Skip to content
Skip to main content
Email Evidence Worked example

Worked example: a genuine account used after compromise

A finance manager receives an email from a colleague asking for an urgent change to payment details.

Nothing about the visible sender immediately looks wrong. The address is the colleague's normal company address and the message has travelled through the organisation's genuine mail service.

The colleague says they did not send it.

That changes the job quite a bit. You are no longer mainly asking whether somebody spoofed the address. You now have a much more useful possibility to test: the real mailbox may have been used by somebody else.

The message is genuinely from the organisation's mail system

The preserved email and message trace show:

Finding Result
From colleague@company.example
Delivery route Organisation's genuine email service
SPF Pass
DKIM Pass
DMARC Pass
Message trace Genuine mailbox submitted the message

Those results are useful. They establish that the message came through the real organisational sending arrangement.

They do not resolve the colleague's denial, because a genuine mailbox can be used by somebody who has compromised the account.

What if the sender's account was compromised? explains that mechanism.

The account history changes the picture

The investigation preserves the relevant sign-in and mailbox records rather than stopping at the email header.

The timeline now looks like this:

Time Account activity
07:48 Successful sign-in from an unfamiliar network and application
08:03 New authentication method registered
08:17 Mailbox rule created to move replies containing “payment” into a little-used folder
08:20 Second rule forwards selected messages externally
09:12 Disputed payment-change message submitted by the genuine mailbox

This is where the sequence becomes useful.

An unfamiliar sign-in on its own may have an innocent explanation such as travel, VPN use or a new device. A newly registered authentication method on its own may also have an authorised explanation.

But the combination of unusual access, security changes, concealed replies and the disputed sending event gives the account-compromise explanation much more substance.

This is where account-access records and login history become more useful than further inspection of the From field.

Preserve the compromise period, not just the one email

Once compromise is suspected, the relevant evidence may include:

  • sign-in and session records;
  • authentication and recovery-method changes;
  • mailbox rules and forwarding;
  • messages sent, deleted or moved during the period;
  • delegate or Send As activity;
  • application or token activity;
  • device or browser identifiers recorded by the provider; and
  • security alerts.

Look at the activity before and after the disputed message. An intruder may have been inside the account for some time before sending anything obvious.

The email preservation checklist gives the wider preservation steps.

Test the account holder's explanation

The colleague's denial is important evidence, but it is not the end of the analysis.

Check whether the unfamiliar sign-in can be explained by normal work activity. Establish whether the new authentication method belongs to them. Identify who or what created the mailbox rules. Look for the same session, application or device identifiers around the sending event.

If the account is shared or delegated, establish whether another authorised user could have caused the activity.

What you really want to know is who or what had control of the mailbox when the message was sent.

Containment may need to happen before the investigation is complete

If the account is still exposed, the organisation may need to revoke sessions or tokens, reset credentials, remove unauthorised authentication methods and disable malicious rules.

Those actions change the account.

Record what was done, by whom and when, so that later examination can distinguish hostile activity from incident-response activity.

What can the investigation now say?

A careful finding might be:

The genuine organisational mailbox submitted the disputed payment-change email during a period in which the account recorded unfamiliar access, a new authentication method and rules designed to hide or forward relevant messages.

That is strong evidence of account compromise.

It still leaves another question: who controlled the hostile session?

The investigation can now move towards device, network, provider and wider contextual evidence instead of arguing about whether the From address was genuine.

The practical lesson is straightforward: a fraudulent email can come from a perfectly genuine mailbox. Once you know that, stop staring at the From address and move into the account history — sign-ins, sessions, security changes, mailbox rules and the activity around the send.

Reference: EML-044Email Evidence