Forensics Email Forensic Report Product information New

How we read the Received hops to trace a message's real path

Transcom 13 Feb 2026, 12:25

The Received: lines are the backbone of a forensic trace. Each mail server that handles a message adds its own Received line at the very top, so reading them from the bottom up replays the journey in order — from the machine that first injected the message, through every relay, to your inbox.

For each hop we look at:

The lowest genuine Received line usually reveals the true originating IP — the machine the message actually came from, before it was dressed up to look like something else. Forgers can add fake Received lines to the bottom to mislead, but they cannot rewrite the lines added by servers further up the chain. Reconstructing which hops are trustworthy is a core part of the report.

0 comments

Sign in with your TDesk account to comment.

← Back to all posts