I think if you index the headers of the email, then you will be able to search on that data as well.
in imap.conf add "fullHeaders = True" or use "1" either way should work.
Restart splunk and you should start importing the full email header fields.