Skip to content
Skip to main content
Email Evidence Operational Explainer

How do I preserve and interpret a complete email header?

Preserve the native message and raw header, then identify the first routing record added by recipient infrastructure you trust. Treat every field according to who created it and the narrow question it answers.

Work outward from a known trust boundary

Mail servers normally prepend Received fields, placing newer hops above earlier ones. Start with the recipient's provider and move down until its first trusted server accepted the message from outside. That line can evidence the connecting system, address and handling time. Lower fields may describe genuine earlier routing or values inserted before trusted receipt.

From is a presented author identity; Reply-To a reply destination; Return-Path commonly reflects the envelope return address; Message-ID helps match a message version. Sender Date can be wrong, while trusted handling times usually better evidence receipt stages.

Interpret authentication and structure separately

Trust Authentication-Results only when added by an identified receiver. SPF tests an authorised envelope route, DKIM a domain signature over covered material, and DMARC alignment with the visible From domain. None identifies the human author.

Retain MIME bodies, attachments and embedded objects because the displayed rendering is only one view. Report route findings first, then seek provider account, session and device records for attribution.

The point to remember

A complete header maps message handling; trusted boundaries and field definitions determine what each part can prove.

Sources

Reference: EML-012Email Evidence