Skip to content
Skip to main content
Email Evidence Technical Explainer

What can embedded images reveal?

An image may be carried inside the message, referenced as a related MIME part or fetched from a remote server. That location determines what can be preserved from the email and whether display could generate network evidence.

MIME and HTML reveal how the image was supplied

An inline image can have a Content-ID, filename, content type, encoding and hash inside the message. HTML may refer to it with a cid: URL. A remote image instead appears as an HTTP or HTTPS address and is retrieved only when a client or intermediary loads it.

Privacy relays, provider caches, scanners and blocked content mean a server request neither proves human reading nor is required for display. Tiny images can support tracking; larger images may contain message text or QR codes that evade ordinary link analysis.

Preserve rendering context without causing new requests

Review raw MIME and HTML on a working copy with remote content controlled. Record Content-ID relationships, URLs, client settings and whether content was embedded, cached, proxied, blocked or unavailable. Extract contained images from the working copy and retain metadata and hash without losing their message relationship.

State whether the preserved email contains the image bytes or only a reference. Viewing the original with remote loading enabled can create fresh activity.

The point to remember

Establish whether an image travelled inside the message or was fetched later before interpreting content, tracking or network records.

Sources

Reference: EML-019Email Evidence