Email Evidence¶
48 investigator questions.
Use the list below or search the complete library.
- Can a deleted email be recovered?
- Can an email identify the person who wrote it?
- Can I tell whether the recipient opened or read the email?
- Could an automated system have generated the message?
- Could the email content have been altered after delivery?
- Does a failed SPF check prove the email is fraudulent?
- Does an IP address in the header identify the sender’s location?
- Does successful DKIM prove the named sender wrote it?
- Does the From address identify the sender?
- How do I establish whether messages really belong to the same email thread?
- How do I preserve an email properly?
- How do I preserve and examine an attachment?
- How do I preserve and interpret a complete email header?
- Is a screenshot or forwarded copy enough?
- I’ve been given an email that may be relevant to an investigation. What can I do with it?
- Should I preserve the mailbox as well as the individual message?
- What account-access records may exist?
- What can a Message-ID tell me?
- What can BCC information show, and who may hold it?
- What can embedded images reveal?
- What can I do with an IP address found in an email header?
- What can login history show?
- What can timestamps in an email header tell me?
- What changes when a shared mailbox, Send As or Send on Behalf access is used?
- What corroboration should I look for?
- What do SPF, DKIM and DMARC actually prove?
- What if the email address was spoofed?
- What if the message came through a mailing platform or customer-management system?
- What if the sender’s account was compromised?
- What information may disappear if the message is forwarded or exported incorrectly?
- What is a tracking pixel?
- What is MIME and why does it matter?
- What is the difference between From, Reply-To and Return-Path?
- What records may link an email account to a device or recovery account?
- What should a supervisor ask before relying on email evidence?
- What should I ask an email provider to preserve?
- What should I ask the recipient not to do?
- What should I do with links in a suspicious email?
- Which Received line can I trust?
- Who may hold relevant email records?
- Why might the original sender’s IP address not appear?
- Why might the plain-text and HTML versions differ?
- Email evidence triage checklist
- Email preservation checklist
- Worked example: a genuine account used after compromise
- Worked example: a message generated by a CRM or mailing platform
- Worked example: a spoofed supplier payment request
- Worked example: a suspicious attachment opened by the recipient