What can a phishing email actually prove?¶
Quite a lot — if you separate what the message itself shows from what still needs other evidence.
A preserved phishing email can tell you what was presented to the recipient, what action was requested, which links or files were supplied, and how the message travelled through the mail system.
What it does not automatically tell you is who authored it or whether the recipient was successfully compromised.
Start with the message as transport evidence¶
Useful material may include:
- visible From, To, Subject and Date fields;
- full headers;
- Message-ID;
- Received fields;
- Return-Path;
- links;
- attachments;
- body content;
- security warnings;
- delivery or quarantine records.
A simplified example might look like:
<88421@mail.example>Link: https://verify-payroll.example/loginDelivered: 2026-09-14 08:41 UTCThat fixes the lure, delivery time and supplied infrastructure.
The content can show the method¶
The message may reveal:
- impersonated organisation or colleague;
- urgency or pressure;
- requested payment;
- request for credentials;
- link or attachment;
- personalisation;
- repeated wording across several messages.
Those details can help connect messages into the same campaign.
Delivery is not interaction¶
A message may be delivered without being opened.
A link may be present without being clicked.
A file may be attached without being executed.
So if the investigation needs to know what happened afterwards, follow the message into:
- browser history;
- proxy/DNS records;
- endpoint activity;
- account-authentication records;
- payment records;
- recipient testimony.
Does clicking a phishing link prove compromise? deals with that next step.
Sender identity needs separate proof¶
The visible sender may be:
- spoofed;
- a lookalike address;
- a compromised genuine mailbox;
- a mailing service;
- another system acting on behalf of an account.
That is why authorship should be built from account, session, provider and device evidence rather than the From field alone.
The practical point is: use the email to establish the lure and delivery mechanics, then prove authorship and victim impact through the records that sit outside the message itself.