IT Forensics · OSINT

Analysing email headers using OSINT – Conducting a forensic analysis of technical sender information

Email headers contain technical information about the route a message has taken, which can be supplemented with publicly available additional information to provide a comprehensive overview.

Enquire without obligation

As part of investigations into existing phishing or fraud cases, we analyse the available email headers in a structured manner and supplement them with publicly available technical information.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

We carry out a technical analysis of the email headers provided and conduct forensic investigations into publicly available supplementary information relating to the 1TP27 details contained therein.

Typical areas of application

Technical analysis of phishing and fraudulent emails
Supplementing incident response investigations
Assistance with identifying the shipping method
Comparison with known attacker infrastructure
Judicial and non-judicial expert reports
Collaboration with IT security teams

This is how an email header analysis works

The complete email header is analysed technically; any IP addresses and 1TP27 details it contains are researched using Shodan and other publicly available sources, and the results are documented.

Why is the analysis of email headers relevant in a forensic context?

A technical analysis of the email’s route can provide important clues as to the actual origin of a suspicious email.

When combined with investigations into the attacker’s infrastructure, this can help to provide a more comprehensive picture of a phishing or fraud attempt.

Frequently Asked Questions

Is the original email required for the analysis?+
Yes, a reliable analysis of the header requires the complete original email, including the technical headers.
Can the actual sender always be identified?+
No, there may be technical limitations, particularly when it comes to obfuscation techniques; we communicate these transparently.
Is this analysis combined with the phishing campaign analysis?+
Yes, the two methods often complement each other as part of a comprehensive examination.

LanCologne – IT Forensics OSINT Cologne

Do you require a professional OSINT investigation into „analysing email headers using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to support your IT forensic, legal or internal corporate enquiries.

Get in touch now