What we examine in your email
Every Email Forensic Report is built from a detailed examination of the message's technical data. We look at:
- Full header trace — every routing hop the message passed through, in order.
- True originating IP address and the geographic location of the genuine sender.
- Spoofing and forgery techniques used to disguise the real source.
- Sender authentication results — SPF, DKIM and DMARC checks.
- From / Reply-To / Return-Path consistency and any mismatches between them.
- Indicators of phishing, impersonation or automated/bulk origin.
Together these reveal not just what the message claims about itself, but what actually happened when it was sent.

0 comments
Sign in with your TDesk account to comment.