I have been given a suspicious email
Preserve the original message, attachments, headers and mailbox context before forwarding, downloading or changing it. The visible From address may identify a displayed claim without identifying the sender.
Start with the practical pathway
Use the short guided route for the first decisions, then go deeper only when needed.
Start with what needs doing now
Use the guided route for immediate preservation and triage, then use the walkthrough or checklist when the email involves payment, compromise or records that may disappear.
Work through preservation, mailbox evidence, payment action, compromise testing and careful attribution.
Reference EML-046Preserve firstEmail preservation checklistRetain the original message, headers, attachments, identifiers, mailbox context and relevant times.
Reference EML-043Understand the evidence and the offender method
Use this route to understand header evidence and see how a separate offender method creates records across email, web and payment services.
Understand the routing and authentication records behind the visible message.
Reference EML-048Separate offender exampleDodgy Dave spoofs a parcel company to steal card detailsFollow a separate offender method across a spoofed message, landing page, hosting and payment collection.
Reference EML-049Go directly to the issue you need to resolve
Distinguish a screenshot, forwarded copy, exported message and original mailbox item.
Reference EML-014CorroborationWhat evidence should support the email?Combine message, mailbox, provider, device, payment and contextual records.
Reference EML-024AuthenticationWhat do SPF, DKIM and DMARC tell me?Use authentication results without treating them as proof of human authorship.
Reference EML-025CompromiseCould the genuine sender account have been taken over?Test spoofing against account compromise, forwarding rules and session evidence.
Reference EML-028Browse every Email evidence guidance page
The complete reference library remains available when you need a narrower question.- Can a deleted email be recovered?
- Can an email identify the person who wrote it?
- Can I tell whether the recipient opened or read the email?
- Could an automated system have generated the message?
- Could the email content have been altered after delivery?
- Does a failed SPF check prove the email is fraudulent?
- Does an IP address in the header identify the sender’s location?
- Does successful DKIM prove the named sender wrote it?
- Does the From address identify the sender?
- How do I establish whether messages really belong to the same email thread?
- How do I preserve an email properly?
- How do I preserve and examine an attachment?
- How do I preserve and interpret a complete email header?
- Is a screenshot or forwarded copy enough?
- I’ve been given an email that may be relevant to an investigation. What can I do with it?
- Should I preserve the mailbox as well as the individual message?
- What account-access records may exist?
- What can a Message-ID tell me?
- What can BCC information show, and who may hold it?
- What can embedded images reveal?
- What can I do with an IP address found in an email header?
- What can login history show?
- What can timestamps in an email header tell me?
- What changes when a shared mailbox, Send As or Send on Behalf access is used?
- What corroboration should I look for?
- What do SPF, DKIM and DMARC actually prove?
- What if the email address was spoofed?
- What if the message came through a mailing platform or customer-management system?
- What if the sender’s account was compromised?
- What information may disappear if the message is forwarded or exported incorrectly?
- What is a tracking pixel?
- What is MIME and why does it matter?
- What is the difference between From, Reply-To and Return-Path?
- What records may link an email account to a device or recovery account?
- What should a supervisor ask before relying on email evidence?
- What should I ask an email provider to preserve?
- What should I ask the recipient not to do?
- What should I do with links in a suspicious email?
- Which Received line can I trust?
- Who may hold relevant email records?
- Why might the original sender’s IP address not appear?
- Why might the plain-text and HTML versions differ?
- Email evidence triage checklist
- Email preservation checklist
- Worked example: a genuine account used after compromise
- Worked example: a message generated by a CRM or mailing platform
- Worked example: a spoofed supplier payment request
- Worked example: a suspicious attachment opened by the recipient
- What is an email header?
- Dodgy Dave spoofs a parcel company to steal card details