What a forensic report can and cannot establish
An Email Forensic Report is built from hard evidence in the headers and metadata, and it is honest about the limits of that evidence.
What it reliably establishes:
- The routing the message genuinely took and the true originating IP.
- The geographic location and network of the sending machine.
- Which authentication checks passed or failed, and which spoofing techniques were used.
- Whether the visible sender is consistent with the underlying evidence.
What headers alone cannot always prove:
- The named individual behind an account — the evidence points to a machine and network, and identifying the person often needs a provider or the authorities to act on it.
- A location hidden behind a VPN, relay or anonymising service will resolve to that intermediary, though the report identifies when such a service is in play.
Being clear about both is part of producing a report that stands up as evidence rather than overstating what the data shows.

0 comments
Sign in with your TDesk account to comment.