What is MIME and why does it matter?¶
MIME is the packaging structure that lets an email contain alternative bodies, attachments, inline images and even attached messages. The mail client renders that structure, so the screen is not the complete evidence object.
Multipart structures define relationships¶
multipart/mixed commonly combines body and attachments; multipart/alternative offers versions such as plain text and HTML; multipart/related groups an HTML body with referenced content. Parts can carry Content-Type, disposition, transfer encoding, Content-ID, filename and character set.
Those labels express intended handling, not guaranteed truth. A misleading filename or content type may not match the actual bytes.
The MIME tree exposes evidence hidden by rendering¶
HTML may conceal a destination absent from plain text. An inline image can be a separate Content-ID part. An attached email can retain its own header, and transport encoding must be decoded to recover attachment bytes.
Preserve native source and use a working copy or tool that displays the MIME tree. Keep extracted items tied to their originating part. Forwarding or PDF conversion can flatten these relationships and remove alternative content.
The point to remember
MIME is the message package; preserve and inspect its parts when content, attachments or their relationships matter.