Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What can a phishing email actually prove?

Quite a lot — if you separate what the message itself shows from what still needs other evidence.

A preserved phishing email can tell you what was presented to the recipient, what action was requested, which links or files were supplied, and how the message travelled through the mail system.

What it does not automatically tell you is who authored it or whether the recipient was successfully compromised.

Start with the message as transport evidence

Useful material may include:

  • visible From, To, Subject and Date fields;
  • full headers;
  • Message-ID;
  • Received fields;
  • Return-Path;
  • links;
  • attachments;
  • body content;
  • security warnings;
  • delivery or quarantine records.

A simplified example might look like:

Example phishing message
From: payroll@northmere-payments.exampleSubject: Urgent salary verificationMessage-ID: <88421@mail.example>Link: https://verify-payroll.example/loginDelivered: 2026-09-14 08:41 UTC

That fixes the lure, delivery time and supplied infrastructure.

The content can show the method

The message may reveal:

  • impersonated organisation or colleague;
  • urgency or pressure;
  • requested payment;
  • request for credentials;
  • link or attachment;
  • personalisation;
  • repeated wording across several messages.

Those details can help connect messages into the same campaign.

Delivery is not interaction

A message may be delivered without being opened.

A link may be present without being clicked.

A file may be attached without being executed.

So if the investigation needs to know what happened afterwards, follow the message into:

  • browser history;
  • proxy/DNS records;
  • endpoint activity;
  • account-authentication records;
  • payment records;
  • recipient testimony.

Does clicking a phishing link prove compromise? deals with that next step.

Sender identity needs separate proof

The visible sender may be:

  • spoofed;
  • a lookalike address;
  • a compromised genuine mailbox;
  • a mailing service;
  • another system acting on behalf of an account.

That is why authorship should be built from account, session, provider and device evidence rather than the From field alone.

MessageWhat was presented?Words, links, files and claimed identity.
DeliveryHow did it arrive?Headers, trace and mailbox records.
Sender controlWho caused it to be sent?Account/session/provider evidence.
OutcomeWhat happened to the recipient?Browser, endpoint, account and payment evidence.

The practical point is: use the email to establish the lure and delivery mechanics, then prove authorship and victim impact through the records that sit outside the message itself.

Reference: CIM-030Cyber Incidents & Offender Methods