Back to overview
Capability explained

E-mail forensics

E-mail forensics reads a saved message, its headers and attachments without silently loading links, images or tracking pixels.

What can be examined?

  • Sender, recipient, date and Message-ID fields
  • Received lines and visible transport relays
  • SPF, DKIM and DMARC results
  • Reply addresses, links, tracking pixels and unsubscribe paths
  • MIME structure, attachments, real file types, hashes and ClamAV findings

What can you find out?

  • Whether the visible sender matches technical delivery traces
  • Which servers handled the message according to its headers
  • Which authentication checks passed or failed
  • Whether remote content could report that the message was opened
  • Which attachments are executable, disguised or match known malware

Example from journalistic work

An alleged bank message fails DMARC, replies to another domain and carries a Windows program named like a PDF. The combined warning signs are preserved with the original and its hash.

What does the result not prove?

  • Some headers can be forged.
  • Passing SPF or DKIM does not make content safe.
  • Signature scanners cannot detect every new or disguised threat.

Evidence and privacy

Only tools actually used and their inputs are recorded. Results, sources, timestamps, hashes and embedded evidence remain attributable. External services are only contacted where the tool expressly states this.

New book, new blog post? Be the first to know!

Sign up and get notified when a new book, blog post or podcast episode is published.

Notify me about

E-mail forensics | Forensics & OSINT