Skip to content
EML-008 Email Evidence

Does the From address identify the sender?


title: Does the From address identify the sender? subtitle: It identifies the author identity presented in the message. It doesn’t automatically identify the account, device or person behind it. slug: does-the-from-address-identify-the-sender series: email-evidence section: sender-and-account-attribution card_type: question_card pathway_order: 7 section_order: 1 status: draft public_safe: true video_ready: true word_count: 535 estimated_read_time_seconds: 221 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - email evidence - From address - sender attribution - spoofing - account sources: - title: 'RFC 5322: Internet Message Format' url: https://www.rfc-editor.org/info/rfc5322/ - title: 'RFC 6376: DomainKeys Identified Mail (DKIM) Signatures' url: https://www.rfc-editor.org/info/rfc6376/ - title: 'RFC 7208: Sender Policy Framework (SPF)' url: https://www.rfc-editor.org/info/rfc7208/ - title: 'RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC)' url: https://www.rfc-editor.org/info/rfc9989/


Does the From address identify the sender?

It identifies the author identity presented in the message. It doesn’t automatically identify the account, device or person behind it.

Script

The From address is the email identity presented to the recipient as the author of the message.

It may be accurate.

It isn’t proof of who actually sent or wrote the email.

Email separates the visible message from the systems used to deliver it. A sender can place an address in the From field, while the message travels through a different server, uses a different envelope return address and directs replies somewhere else.

That happens for legitimate and illegitimate reasons.

A company may send through Microsoft 365, Google Workspace, a customer-management system, a marketing platform or a ticketing service while displaying an employee or brand address in From.

A shared mailbox may be used by several staff members.

An automated system may send a message that looks as though it came from a named team.

A compromised account may send a genuine message from the real mailbox without the account holder’s knowledge.

A hostile sender may also spoof the visible address.

So what does the From field show?

It shows the author identity asserted in the message.

That is useful. It tells you what identity was presented to the recipient and may explain why they trusted, opened or acted on it.

But it doesn’t, by itself, show:

which server submitted the message;

which account authenticated to a provider;

which device created it;

who controlled the account;

or which person typed the words.

Look at the rest of the message.

Compare From with Reply-To and Return-Path. Review the trusted Received chain. Check authentication results such as SPF, DKIM and DMARC. Identify whether the message travelled through infrastructure associated with the claimed organisation or an authorised sending platform.

Then move beyond the header where necessary.

Provider-side message trace may link the email to a customer account, tenant, campaign or authenticated session. Account audit logs may show sign-ins, sending activity, rules or connected applications. Device evidence may show drafts, browser sessions or mail-client artefacts.

Keep authentication in its place.

A DKIM or DMARC pass can support that a domain authorised or authenticated part of the sending arrangement. It doesn’t prove that the individual named in From personally composed the message.

A failure doesn’t automatically prove fraud either. Legitimate forwarding, configuration errors or mailing arrangements can affect authentication results.

The common mistake is to copy the From address into a report as “the sender” without explaining what that means.

Use more precise language.

“The message displayed this address in the From field” states the observation.

“The message was sent through an account controlled by this organisation” needs supporting provider or authentication evidence.

“This person wrote and sent the message” needs a stronger link to the individual.

Also pay attention to the display name.

An email client may show “Finance Director” or “Steve Atkin” prominently while hiding the actual address unless the user expands it. Display-name spoofing can make a message look familiar even when the underlying address belongs to another domain.

Preserve both the display name and the full address.

The From address isn’t worthless.

It is part of the message’s claim about authorship and may be an important lead.

Just don’t confuse the identity presented to the recipient with a proven identity of the person behind the keyboard.

Key takeaway

Treat the From address as a claim that needs support, not as proof of the human sender.

Source notes


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.