Email Forensics
Email Forensics Services | Email Investigation & Digital Evidence Analysis
Email can contain some of the most important evidence in a cybercrime or fraud investigation.
A single email may contain information about who sent it, who received it, when it was sent, what links or attachments were included, and how the message moved through email systems.
Email evidence can be particularly important in investigations involving:
- Phishing
- Business email compromise
- Account takeover
- Identity theft
- Investment fraud
- Online scams
- Malware
- Financial fraud
- Harassment
- Unauthorized access
Email forensics involves the examination and analysis of email messages, technical information, attachments, links, account activity and related evidence to help reconstruct what occurred.
The purpose is not simply to determine whether an email looks suspicious. A forensic investigation examines the available evidence to establish what can and cannot be reliably determined.
What Is Email Forensics?
Email forensics is a branch of digital forensics focused on examining email evidence.
Depending on the circumstances, an investigation may consider:
- Email messages
- Headers
- Attachments
- Links
- Sender information
- Recipient information
- Dates and timestamps
- Mail-server information
- Account activity
- Related devices
- Related websites
Email evidence can be examined individually or together with other digital evidence.
For example, an email may provide the initial evidence of a phishing incident, while a computer or mobile device may provide information about what happened after the recipient opened the message.
When Is An Email Forensic Investigation Needed?
Email forensics may be appropriate when there are concerns about:
- A suspicious email
- Phishing
- Email account compromise
- Business email compromise
- Identity theft
- Fraudulent invoices
- Investment scams
- Malware attachments
- Unauthorized access
- Suspicious account activity
- Harassment or threatening communications
It may also be useful when the authenticity or origin of an email needs to be examined.
Phishing Email Investigation
Phishing messages are designed to persuade recipients to click links, provide information or transfer funds.
A phishing investigation may examine:
- Sender information
- Email headers
- Links
- Attachments
- Website destinations
- Dates and timestamps
- Related account activity
The objective is to understand how the message was delivered and what evidence exists concerning the subsequent activity.
Business Email Compromise Investigation
Business Email Compromise (BEC) can result in significant financial losses.
A typical incident may involve:
Compromised email account
↓
Fraudulent communication
↓
False payment instructions
↓
Financial transfer
Email evidence can be crucial in reconstructing this sequence.
Investigators may examine the communications surrounding the suspected fraud and compare them with available account and financial records.
Email Account Takeover
An email account can be compromised through:
- Stolen credentials
- Phishing
- Malware
- Credential reuse
- Unauthorized access
Evidence may include:
- Login notifications
- Password-change messages
- Recovery activity
- Suspicious sent messages
- Account settings changes
A forensic investigation may examine available account evidence alongside the email itself.
Investment Scam Email Investigation
Fraudulent investment schemes may use email to:
- Introduce investment opportunities
- Send account information
- Provide payment instructions
- Share fraudulent documents
- Communicate with victims
Email evidence can help establish the sequence of communications between the victim and the suspected fraudulent operation.
Cryptocurrency Scam Email Investigation
Cryptocurrency fraud may involve emails containing:
- Wallet addresses
- Payment instructions
- Exchange information
- Transaction requests
- Account details
Where cryptocurrency transactions occurred, the email evidence can be correlated with blockchain records.
Email Spoofing
Email spoofing occurs when email information is manipulated to make a message appear to originate from another sender.
This can be used in:
- Phishing
- Fraud
- Business email compromise
- Impersonation
A message appearing to come from a familiar address does not necessarily mean that the legitimate account owner sent it.
Technical email information can therefore be important.
Can Email Headers Identify The Sender?
Email headers can provide valuable technical information.
Depending on the email system and available records, they may contain information relating to:
- Mail servers
- Routing
- Dates and times
- Authentication results
- Sending infrastructure
However, email headers do not automatically identify the individual who physically sent a message.
An investigation must consider the broader evidence.
What Are Email Headers?
Email headers contain technical information associated with an email message.
They can include fields relating to:
- Sender
- Recipient
- Message ID
- Delivery
- Routing
- Authentication
- Timestamps
Many email applications hide much of this information from the normal message view.
Forensic examination may therefore require access to the original message or complete header information.
Why Original Emails Matter
Forwarding an email can remove or alter information that may be useful to an investigation.
For example, the forwarded message may not contain all of the original technical information.
Where possible, preserve the original email rather than relying solely on a screenshot or forwarded copy.
Email Attachments As Evidence
Attachments can be important evidence in investigations involving:
- Malware
- Fraud
- Phishing
- Identity theft
- Business email compromise
An attachment may contain:
- Documents
- Images
- Spreadsheets
- Scripts
- Links
- Other files
The investigation may examine the attachment together with the email that delivered it.
Malicious Email Attachments
Some phishing campaigns use attachments to deliver malware.
For example:
Fraudulent email
↓
Malicious attachment
↓
User opens attachment
↓
Malware executes
↓
Device or account becomes compromised
This can require both Email Forensics and Malware Investigation.
Email Links As Evidence
Links contained in suspicious emails can provide important evidence.
An investigation may examine:
- The displayed link
- The actual destination
- Associated domains
- Redirects
- Website content
- Timing
A link that appears legitimate may redirect to another website.
Email And Identity Theft
Identity theft investigations may involve emails sent using another person’s name or information.
Relevant evidence may include:
- Sender address
- Display name
- Profile information
- Email content
- Attachments
- Links
- Related accounts
The investigation should distinguish between the identity displayed in the email and the person who actually controlled the account.
Email And Romance Scams
Romance scams can involve prolonged email communication.
Evidence may include:
- Introduction messages
- Relationship communications
- Requests for money
- Investment claims
- Payment instructions
- Identity information
Preserving the complete communication history can help reconstruct how the relationship developed and when financial requests were introduced.
Email And Online Investment Fraud
Investment fraud investigations may involve hundreds of messages.
These can document:
- Initial contact
- Investment representations
- Account information
- Deposit requests
- Withdrawal problems
- Additional payment demands
Email evidence may therefore become an important component of the wider financial investigation.
Email Forensics Investigation Process
1. Initial Assessment
The investigation begins by understanding the incident.
Questions may include:
- What email was received?
- When was it received?
- Who sent it?
- What was requested?
- Were links or attachments opened?
- Did financial activity follow?
2. Evidence Preservation
Relevant email evidence should be preserved before it is deleted or altered where practical.
This may include:
- Original emails
- Attachments
- Headers
- Screenshots
- Related messages
3. Email Examination
The relevant messages are examined.
This can include:
- Sender information
- Recipients
- Dates
- Subject lines
- Attachments
- Links
4. Header Analysis
Where available, complete header information can be examined to understand technical delivery information and authentication results.
5. Link And Attachment Analysis
Relevant links and attachments can be examined in the context of the incident.
Care should be taken when interacting with potentially malicious content.
6. Account Activity Analysis
If an email account was compromised, relevant account records may be examined.
This can include:
- Login activity
- Password changes
- Recovery events
- Account settings
- Suspicious sent messages
7. Timeline Reconstruction
Investigators can organize relevant events chronologically.
For example:
Email received
↓
Link opened
↓
Credentials entered
↓
Account accessed
↓
Unauthorized activity
This can help establish the relationship between communications and subsequent events.
8. Evidence Correlation
Email evidence can be compared with:
- Computer evidence
- Mobile evidence
- Website information
- Financial records
- Cryptocurrency transactions
- Account activity
This can significantly strengthen the investigation.
Can A Deleted Email Be Recovered?
Sometimes.
Depending on the email provider and circumstances, relevant information may remain in:
- Trash folders
- Archived mail
- Backups
- Cloud storage
- Other devices
- Account records
However, recovery cannot be guaranteed.
What If The Scammer Deleted The Emails?
The disappearance of emails does not necessarily eliminate all evidence.
Other sources may include:
- Screenshots
- Forwarded messages
- Recipient records
- Account notifications
- Website evidence
- Financial records
- Cryptocurrency transactions
The investigation can work with the evidence that remains.
What If The Email Address Is Fake?
A fraudulent email address can still provide investigative information.
Investigators may examine:
- Domain information
- Email infrastructure
- Related websites
- Other accounts
- Communications
However, a fake email address does not automatically identify the person behind it.
Can Email Forensics Find A Scammer?
Email evidence may provide clues about:
- Accounts
- Domains
- Infrastructure
- Related online identities
Additional evidence may come from:
- Websites
- Financial transactions
- Cryptocurrency
- Social media
- Device evidence
Attribution requires sufficient supporting evidence.
A professional investigation should avoid treating a technical indicator as definitive proof of an individual’s identity.
What Should You Preserve From A Suspicious Email?
If you receive a suspicious email, preserve:
- The original email
- Complete headers where available
- Attachments
- Links
- Sender address
- Recipient address
- Date and time
- Screenshots
- Related communications
Do not rely solely on a screenshot if the original message is available.
Should You Reply To A Suspicious Email?
Generally, avoid engaging with a suspicious sender simply to obtain additional information.
If evidence is important, preserve what you already have and seek appropriate professional guidance.
Interacting with an attacker can create additional risks.
Email Forensics For Businesses
Businesses may require email forensic investigation following:
- Business email compromise
- Fraudulent invoices
- Employee account compromise
- Data breaches
- Phishing attacks
- Unauthorized communications
A corporate investigation may need to examine multiple accounts and systems.
Email Forensics For Individuals
Individuals may require email forensic assistance following:
- Investment scams
- Cryptocurrency scams
- Identity theft
- Phishing
- Romance scams
- Account takeover
- Financial fraud
The investigation can focus on the communications and accounts relevant to the incident.
Email Evidence And Legal Proceedings
Email evidence may become relevant in:
- Civil disputes
- Fraud investigations
- Employment matters
- Cybercrime investigations
- Regulatory proceedings
The evidentiary requirements vary depending on the circumstances and jurisdiction.
Proper preservation and documentation can therefore be important from the beginning.
What Can Email Forensics Establish?
Depending on the available evidence, email forensics may help establish:
- When a message was sent or received
- Which accounts were involved
- What communications occurred
- What links or attachments were included
- Technical delivery information
- Whether account activity corresponds with the incident
- How email evidence relates to other evidence
The evidence determines the findings.
Why Early Email Evidence Preservation Matters
Email accounts change constantly.
Messages can be deleted.
Accounts can be closed.
Attachments can become unavailable.
Websites can disappear.
Forensic information may also be lost when messages are forwarded or exported incorrectly.
Preserving the original evidence early can therefore make a significant difference to an investigation.
Need An Email Forensic Investigation?
If you have received suspicious emails or believe an email account has been compromised, our investigation team can assess the available communications and explain what evidence may be relevant.
Relevant information may include original emails, headers, attachments, links, account notifications and related financial or online activity.
Discuss Your Case