EMAIL HEADER ANALYSIS

Mitaleew
2 min readJun 21, 2021

Phishing attacks are the most common reason for getting trapped in cyber frauds. As cybercrimes are increasing day by day and email messaging being the most common source of phishing and interacting with the victim, there is a huge need for email analysis to find out if the sender of the email is legitimate. So let’s find out what is Email header analysis and how it works.

Fundamentally, an email consists of the envelope, the header, and the body of the message. The envelope specifies how an email is routed which is an internal process. The body of an email contains the actual message being sent. Now, there are several headers that include routing information, the sender’s email address, recipient, date, message ID, subject, etc. which will help us determine the authenticity of the email received.

Analyzing the Email Header

  1. On the right side of an email message, you will find three dots, look for the show original option.

2. You will find all the details of the email there i.e the Message-ID, creation date, time, From, to, the subject, and information about DMARC, DKIM, and SPF.

In the message ID, you can find that the email is actually from emkei.cz, a fake online mailer available for free through which the hacker can spoof the victim.

3. To find out more information about the email just copy the email header by clicking on Copy to Clipboard.

4. Go to any online email header analyzer (G Suite Toolbox Messageheader, MXToolbox, Gaijin, etc.) and paste the header. Here I will use Mxtoolbox.

This information will further help in the email investigation and track the actual sender of the email.

Thanks for reading and kindly leave a bunch of applauses and share if you found this article informative !!

--

--