IP Address Leakage When Using Gmail with Third‑Party Email Clients

I just realized that when sending Gmail messages through third‑party email clients (e.g., Thunderbird, Apple Mail), Gmail adds a Received: header which includes the sender’s public IP address. After checking my own message headers, my IP was indeed exposed.

This behavior isn’t new. There’s an older write‑up explaining how Apple Mail leaks both public and private IPs when using Gmail’s SMTP:

To compare, I tested Outlook and iCloud Mail as well. In both cases, IP address was not exposed. Instead, the mail appears to be relayed through Microsoft’s or Apple’s infrastructure, so the Received: headers only show the server IPs.

It seems worth adding a warning about this in PG email client guide, since it affects anyone using Gmail with non‑Google clients and isn’t immediately obvious. In this specific case, sticking to Gmail’s webmail/apps may actually be the more privacy‑preserving option.


As far as I can trace back from googling, this has been around for well over a decade:

3 Likes

Strange. Some messages have Received: header, some not.
Anyway they have vpn address when from mobile. I’m not by computer to check if those 2 addresses are to from my vpn (since at home i have 1 vpn on a e-mail VM, one address might be internal inter VM ip, but can’t check it now).