An email is more than its message body. Its headers and metadata form a detailed record of where it came from and whether it can be trusted. Email forensics reads that record to prove authenticity, expose forgery, and reconstruct what really happened.
How do you tell if an email is real or spoofed?
- Header path analysis — every server the message traversed, in order
- SPF, DKIM & DMARC results — whether the real sending domain is authorized
- Display-name vs. envelope sender — catching impersonation and lookalike domains
- Timestamps and message IDs — detecting fabricated or back-dated mail
- Embedded links and attachments — phishing payloads and tracking artifacts
Can you investigate a business email compromise?
Yes. In a BEC case an attacker hijacks or impersonates a mailbox to divert wire payments or steal data. We trace the intrusion through mailbox audit logs, sign-in records, and hidden forwarding rules, then correlate them with message headers to establish how the compromise occurred and who was affected. ROHOVOT operates under a licensed California investigator (California BSIS PI License No. 190161) and a court-qualified computer-forensics expert witness. If funds were wired, report the incident promptly to the FBI at ic3.gov.
Will recovered email hold up in court?
Yes — with lawful collection, an unbroken chain of custody, and verified authenticity. We preserve mailboxes and any local mail stores forensically, hash the evidence, and document how each message was authenticated, so the results are defensible when challenged. Deleted mail often survives in backups, server journals, and provider logs, so preserving the account quickly is critical.