Skip to content
EML-019 Email Evidence

What can embedded images reveal?


title: What can embedded images reveal? subtitle: An image may be stored inside the message, loaded remotely, or linked to another MIME part. Those arrangements produce different evidence. slug: what-can-embedded-images-reveal series: email-evidence section: content-and-attachments card_type: question_card pathway_order: 26 section_order: 4 status: draft public_safe: true video_ready: true word_count: 662 estimated_read_time_seconds: 274 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - email evidence - embedded image - Content-ID - remote image - MIME sources: - title: 'RFC 2387: The MIME Multipart/Related Content-Type' url: https://www.rfc-editor.org/info/rfc2387/ - title: 'RFC 2392: Content-ID and Message-ID Uniform Resource Locators' url: https://www.rfc-editor.org/info/rfc2392/ - title: 'RFC 2045: Multipurpose Internet Mail Extensions (MIME) Part One' url: https://www.rfc-editor.org/info/rfc2045/ - title: 'RFC 2046: Multipurpose Internet Mail Extensions (MIME) Part Two' url: https://www.rfc-editor.org/info/rfc2046/ - title: 'Gmail Help: Turn images on or off' url: https://support.google.com/mail/answer/145919?hl=en-GB - title: 'Apple Support: Protect email privacy in Mail' url: https://support.apple.com/en-gb/guide/mail/mlhlp1205/mac


What can embedded images reveal?

An image may be stored inside the message, loaded remotely, or linked to another MIME part. Those arrangements produce different evidence.

Script

An image displayed inside an email may have arrived in several different ways.

It may be stored inside the message as a MIME body part.

It may be attached and referenced from the HTML using a Content-ID.

It may be loaded from a remote website when the message is displayed.

Or the email client may have replaced, cached, proxied or blocked it.

Those differences matter.

An image contained inside the message can be preserved with the original email. It may have its own filename, content type, transfer encoding, Content-ID and hash.

The HTML body may refer to it using a CID address, allowing the mail client to display it in the body even though it exists as a separate MIME part.

That is common with logos, signature images and pictures pasted into a message.

A remote image is different.

The email contains a URL, and the mail client requests the image from a server when it decides to display it.

That request may reveal timing, network and identifier information to the server. It can also act as open tracking.

But the request may come from an email provider, privacy relay or security system rather than directly from the recipient’s device.

First establish which kind of image you have.

Preserve the complete raw message.

Review the MIME structure and HTML.

Does the image use a CID reference?

Is there a matching Content-ID body part?

Is it marked inline or attachment?

Does it refer to an HTTP or HTTPS URL?

Was the content replaced by a placeholder or warning?

Did the recipient’s application load it automatically?

If the image is inside the message, extract it only from a working copy.

Keep the original relationship between the HTML and the image body part. Record the original filename, content type, Content-ID, encoding and hash.

The displayed filename may be missing or misleading. File content and metadata should be assessed separately.

Images may contain useful visible evidence:

screenshots;

documents photographed by a phone;

QR codes;

logos;

signatures;

account details;

location clues;

or content intended to influence the recipient.

They may also contain file metadata, thumbnails, colour profiles or other technical information.

The presence and meaning of metadata depends on how the image was created and processed. Email clients and platforms may strip or alter it. Don’t assume that a missing item was never present, or that every metadata value is accurate.

An image can also conceal content in less obvious ways.

A transparent or tiny image may be used for tracking.

A large image may contain the entire message text so that ordinary text filtering sees very little.

A QR code may direct the recipient to a website without displaying a clickable text link.

An image map or surrounding HTML may make different areas clickable.

That doesn’t mean every image requires specialist forensic examination.

Start with the operational question.

Are you trying to preserve what the recipient saw?

Identify a remote service?

Recover an attached photograph?

Understand whether the message generated a network request?

Or assess whether the image carried active or concealed content?

The level of examination should follow the question and risk.

Avoid repeatedly opening the original message with remote content enabled. Your own viewing may create requests and change provider tracking records.

Use a controlled copy and record the client settings.

The common mistake is to treat every image shown in the email as an attachment that travelled with it.

Another is to assume a broken image means there was no image. The remote content may have been blocked, removed or no longer available.

A careful conclusion could say:

“The HTML body referenced this image by Content-ID, and the matching image file was contained within the preserved message.”

Or:

“The HTML body referenced a remote image at this URL. The image itself wasn’t contained in the message.”

Those are different evidential situations.

Work out where the image lived, how the email referred to it and whether displaying it caused another system to be contacted.

Key takeaway

Establish whether the image travelled with the email or was fetched later. That determines what the message and the network records may show.

Source notes


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.