email headers – expert forensic analysis

23
Technical Awareness on Analysis of Email Headers

Upload: forensicemailanalysis

Post on 21-Jul-2015

515 views

Category:

Technology


4 download

TRANSCRIPT

Page 1: Email Headers – Expert Forensic Analysis

Technical Awareness on

Analysis of Email Headers

Page 2: Email Headers – Expert Forensic Analysis

Agenda Email Headers – A Basic Introduction Viewing Email Headers in Web – Based Email

Services Viewing Email Headers in Desktop – Based Email

Client Applications Common Fields Available in Email Headers – A

Brief Overview How Mail Works on the Internet Investigating an Email Header – Expert Analysis

Page 3: Email Headers – Expert Forensic Analysis

What is Email Header?

Email Headers are lines of metadata (data about data) attached to each email that contain lots of useful information for a forensic investigators.

Page 4: Email Headers – Expert Forensic Analysis
Page 5: Email Headers – Expert Forensic Analysis

Web-Based Email ServicesWeb-based email allows user to manage email via a web browser and sent or receive e-mail from anywhere. E-mail is not downloaded to a computer, but instead is left on the mail server until the user delete it.Examples of Web Based Email Client Applications are: -GmailYahoo! Mail

Page 6: Email Headers – Expert Forensic Analysis

Hotmail Google Apps Google Apps Admin Live Exchange Office 365 IMAP

Page 7: Email Headers – Expert Forensic Analysis

Gmail

• Log in to your Gmail account.• Open the message you want to view headers for.• Click the Down arrow next to the Reply button, located at the top right of the message pane.• Select Show Original.

Page 8: Email Headers – Expert Forensic Analysis
Page 9: Email Headers – Expert Forensic Analysis

Desktop Based Email Services

Desktop based email clients are mailing applications that enable the users to easily manage their email accounts and perform operations such as sending and receiving of emails, managing tasks & calendar items, and many more.Examples of Desktop Based Email Client Applications are: -

Page 10: Email Headers – Expert Forensic Analysis

Microsoft Outlook Outlook Express Mozilla Thunderbird The Bat Pocomail Lotus Notes Mailbird Postbox

Page 11: Email Headers – Expert Forensic Analysis

Microsoft Outlook• Open Outlook.• Open a message.• On the Message tab, located in the Tag group, click the Dialog Box Launcher icon.• In the Message Options dialog box, the headers will appear in the Internet Headers box.

Page 12: Email Headers – Expert Forensic Analysis
Page 13: Email Headers – Expert Forensic Analysis

Investigating an Email Header Expert Analysis

Page 14: Email Headers – Expert Forensic Analysis
Page 15: Email Headers – Expert Forensic Analysis

Delivery-To filed of email header shows the address of automailer.

Return-Path of email header used for bounces. The mail server will send a message to the specified email address if the message cannot be delivered.

Received-SPF: Sender Policy Framework is used to describe what mail server is allowed to send messages for a domain.

Page 16: Email Headers – Expert Forensic Analysis

From: Displays the name of sender. However, this information can be easily forged and hence, is least reliable.

To: Displays the name of receiver. Subject: Represent the subject of the

email message. Date: Shows the date and time, when the

email message was composed.

Page 17: Email Headers – Expert Forensic Analysis

Message-ID: Every email should have a message id field that: "provides a unique message identifier that refers to a particular version of a particular message.

MIME-Version: Multipurpose Internet Mail Extensions is an Internet Standard that extends the format of email message. 

Content-Type: Shows the format of the message, such as html, plain text, xml.

Page 18: Email Headers – Expert Forensic Analysis

X-Mailer: The email client used to send the message.

Content-Language: Specify language used for content of page.

X-Antivirus: This states that what the sender’s antivirus program is such as Norton, AVG, etc.

X-Antivirus-Status: It shows that email was free or not from any viruses.

Page 19: Email Headers – Expert Forensic Analysis

Received

Page 20: Email Headers – Expert Forensic Analysis

Received is the most essential field of the email header. It creates a list of all the mail server through which the message traveled in order to reach the receiver. The best way to read the received fields are from bottom to top. The bottom “Received” shows the IP address of the sender’s mail server.

Page 21: Email Headers – Expert Forensic Analysis

The top “Received” shows the IP address of receiver mail server.

The middle “Received” shows the IP address of the mail server through which email passes from sender to receiver.

Page 22: Email Headers – Expert Forensic Analysis

Message Header View using MailXaminer

(http://www.mailxaminer.com/product)

Page 23: Email Headers – Expert Forensic Analysis