Automatic (machine) translation. This text was translated automatically from the Polish original and may contain inaccuracies. In case of any doubt, the Polish version is the authoritative one.
← Back to Knowledge
Knowledge

A methodology for analysing e-mail headers in cyber-fraud cases — an evidentiary guide

A methodology for analysing e-mail headers in cyber-fraud cases — an evidentiary guide

An e-mail header is a digital fingerprint. How to read it to unmask a fraudster?

A fake e-mail from the bank looks genuine — until you look into its hidden metadata. Here is how, in a few minutes, to establish where a message really came from and whether it can serve as evidence in a case.

In cases involving cybercrime — including phishing, spoofing and impersonating financial institutions — e-mail message headers are a valuable source of evidentiary information. Their analysis can help identify the sender's IP address, the mail server from which the message was sent, any impersonation attempts (spoofing), and unusual message-routing paths.

Below we present a methodology for obtaining and analysing e-mail headers that can be used in civil and criminal proceedings.

1. What are e-mail message headers?

Headers are technical metadata attached to every e-mail message, which in the standard view remain invisible to the user. They include, among other things:

  • the message's routing path (intermediary servers),
  • the exact date and time of sending,
  • the IP addresses of the servers involved in the transmission (including the sender's host),
  • information about the SMTP server and the TLS protocol,
  • authentication data (SPF, DKIM, DMARC).

2. How to obtain the full e-mail headers?

Instructions for the most popular e-mail clients.

Gmail (browser)

  1. Open the message.
  2. Click the three dots in the top right corner ("More").
  3. Select "Show original".
  4. Copy the entire content.

Outlook (desktop)

  1. Open the message.
  2. Click "File" > "Properties".
  3. You will find the content to analyse in the "Internet headers" field.

Thunderbird

  1. Select the message.
  2. Press Ctrl+U (or, from the menu: "View message source").

3. What information can be read from the headers?

The infographic below shows the anatomy of a sample (suspicious) header and explains what each of the key lines means.

Anatomy of a suspicious e-mail header: Received, From, SPF/DKIM/DMARC and Reply-To fields
Infographic: the anatomy of a suspicious e-mail header and four phishing signals.

4. What to look out for in the case of phishing?

  • A mismatch between the sender's domain (From:) and the domain authorised in SPF/DKIM — e.g. the e-mail appears to be sent from olx.pl, but the header shows bskx7.com.
  • No positive SPF/DKIM/DMARC verificationfail, none or neutral results indicate that the message may be forged.
  • An unknown or suspicious IP in the Received: field — e.g. addresses linked to botnets in Russia, India or Vietnam.
  • A strange Reply-To: differing from From: — a common trick in scams; the user replies to the fraudster, not to the institution.

5. How to use headers as evidence?

  1. Attach the headers as an attachment (in .eml, .msg or .txt format) to: a crime report (police, prosecutor), a report to CERT Polska, and a complaint to the bank.
  2. Keep the original message on the server — preferably in an unedited form.
  3. Request analysis by an IT expert — e.g. as part of civil or criminal proceedings.

6. Tools for header analysis

  • Google Admin Toolbox — Messageheader Analyzer
  • MxToolbox — Email Header Analyzer
  • IPVoid / AbuseIPDB — checking the reputation of IP addresses
  • MailTester / DKIMCore — testing the correctness of SPF/DKIM

7. Summary: the header is a digital fingerprint

In an age when cyber-fraudsters operate remotely and professionally, the e-mail header becomes a key technical trace. Its analysis makes it possible to identify the source of the attack, to confirm or rule out the authenticity of the message, and to support allegations in legal proceedings.

In any case involving phishing, spoofing or cybercrime, preserving the full headers and analysing them early can decide the outcome of the case.

Prepared by: Waldemar Chodasiewicz Date prepared: 19 August 2024