What can a phishing email actually prove?¶
A phishing email may provide strong evidence about the method used in an incident, but its meaning has limits.
Avoid the dangerous assumption¶
The dangerous assumption is that the apparent sender and the actual sender are the same person.
The email may help show:
- what representation was made
- who was targeted
- what action the recipient was asked to take
- which links, attachments or payment details were supplied
- when the message was sent or received
- which account or infrastructure was used
- whether the message formed part of a wider campaign.
The original message, headers, delivery records and mailbox data may help reconstruct how it travelled and whether it was delivered, opened, forwarded, quarantined or removed.
The content may also show urgency, impersonation, knowledge of the victim or an attempt to exploit an existing relationship.
But the email does not by itself prove who authored it.
The sending account may have been compromised. The display name may be false. The address may have been spoofed. Infrastructure may have been rented, shared or controlled remotely.
The email also does not prove that the recipient believed it, clicked anything or suffered compromise.
Preserve the original message in its native form where possible. A screenshot may omit headers, links, message identifiers and other metadata.
Ask for associated email-security alerts, mailbox audit records, link-protection records, authentication information and any reports made by the recipient.
Keep the propositions separate.
“The message was delivered” is different from “the recipient opened it.”
“The link was clicked” is different from “credentials were captured.”
“The account sent the message” is different from “the account holder sent it.”
Operational takeaway¶
Use a phishing email to evidence the representation, delivery method and associated infrastructure, but do not treat the apparent sender or delivery alone as proof of authorship or compromise.