Forensic analysis of forwarded emails: what is preserved, what is lost and how not to destroy the evidence
Forensic analysis of a forwarded email is one of the most delicate scenarios in cybersecurity and digital forensics. When a victim forwards a suspicious message for someone to review, the gesture seems harmless — but technically the original message undergoes a radical transformation that can destroy the most valuable evidence without the user realising. If you don't understand what changes in the process, the analyst may end up examining data that is completely useless, or worse, data that points to the person who forwarded it rather than the attacker.
This article explains what happens technically when an email is forwarded, which metadata survives depending on the method used, how to preserve evidence correctly, and what legal validity a forwarded email has in judicial or insurance proceedings.
🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
What happens to an email when you forward it?
When you hit "Forward", your email client is not sending the same package — it is creating a new one. This has three critical implications for forensic analysis:
New identity: The sender is no longer the attacker, it is you. The From, To and Date fields now reflect the moment of forwarding. The original message is buried inside the body of the new email.
Encapsulation: Depending on how your email client is configured (Outlook, Gmail, Thunderbird), the suspicious email may end up as a quoted text block, an attachment or an .eml file. If it becomes plain text, almost all forensically valuable metadata is lost.
False security positives: Your server will sign the forwarded message with its own SPF, DKIM and DMARC records. If an analyst looks at this data, they will see that the email appears "safe" because your domain is legitimate — completely ignoring the original attacker's authentication.
Which metadata survives depending on the forwarding method
The following table summarises which forensic information is preserved or lost depending on the method used:
| Metadata | Standard forward | Forward as .eml |
|---|---|---|
| Original Received headers | ✗ Lost | ✓ Preserved |
| Attacker's server IP | ✗ Lost | ✓ Preserved |
| Original DKIM signature | ✗ Invalidated | ✓ Verifiable |
| Attacker's SPF/DMARC | ✗ Replaced | ✓ Preserved |
| Original URLs and links | ⚠ Partial | ✓ Complete |
| Malicious attachments | ⚠ May vary | ✓ Intact |
Layers of analysis: where to focus
To detect a threat in a forwarded email you need to separate two layers of information:
The transport layer (the forward): This will not help identify the fraudster, but it can reveal whether the message was tampered with during forwarding or whether the email client stripped important parts such as scripts or unusual formatting.
The original message (the threat): This is where the action is. If the email was forwarded as an .eml attachment, it is possible to recover the Received headers with the attacker's real trail, the X-headers with technical information from the originating server, and the complete body with phishing URLs, Unicode-spoofed domains and malicious attachments.
How not to destroy the evidence
If you need a forensic analyst or digital expert to examine a suspicious email, the forwarding method determines whether the analysis will be complete or useless:
Always forward as an attachment (.eml): This is the only way to ensure that the original headers and signatures arrive intact.
Avoid mobile: Mobile email apps simplify code to save space, stripping crucial metadata in the process.
Do not copy and paste the content: Copy-pasting destroys the technical structure. It is like trying to analyse a fingerprint after wiping the surface with bleach.
Report what you did: Did you click a link? Did you download the attachment? That information is vital for the analyst.
How to forward an email as an .eml attachment by platform
Microsoft Outlook (desktop)
Quick method: Select the suspicious email in your inbox and press Ctrl + Alt + F. A new message will open with the original already attached as a file.
Visual method: On the "Home" tab, in the "Respond" group, click More and select Forward as Attachment.
Gmail (web)
Open the email, click the three vertical dots (⋮) in the toolbar and select "Forward as attachment". A draft will be created with the .eml file already loaded.
Apple Mail (macOS)
Right-click on the message in the email list and select Forward as Attachment. You can also drag the email directly from the list into the body of a new message you are composing.
Outlook.com / Microsoft 365 (web)
Click New message and drag the suspicious email from the message list directly into the body of the new email. It will automatically become an attachment named "Message.eml".
Legal validity of a forwarded email in judicial proceedings
This is the question that matters most when the goal is not only to detect fraud but to prove it before a court, an insurer or a regulatory authority.
A standard forward rarely has probative value in legal proceedings. The technical reasons are clear: the original headers have been replaced, the DKIM signature has been invalidated and the attacker's server IP has disappeared. What remains is an email that technically appears to have been sent by the victim, not the attacker. An opposing expert can challenge that evidence with ease.
For an email to carry evidential weight in a formal proceeding, three conditions must be met:
- Preserve the original .eml file with all headers intact, unmodified from the moment of receipt.
- Establish chain of custody — demonstrate that the file has not been tampered with from the moment it was received to the moment it is submitted as evidence.
- Obtain a forensic expert report signed by a certified judicial IT expert who technically analyses the message and certifies its authenticity and origin.
Without these conditions, the email may be admitted as circumstantial evidence but rarely as full proof. In cases of business email compromise, supplier impersonation fraud or phishing with financial loss, the difference between a standard forward and an .eml with a certified expert report can be decisive for the outcome of the proceedings.
ORTSLAB and the analysis of forwarded emails
The ORTSLAB engine automatically detects when an email has been forwarded and adapts the analysis to extract information from the original message even when it is encapsulated. The system separates the forwarding transport layer from the original content, avoiding the false negatives generated by the forwarder's authentication records.
If you attach the .eml file directly, the analysis will be complete: Received headers, originating server IP, attacker's DKIM/SPF validation, and the original message's URLs and attachments.
Frequently asked questions about forensic analysis of forwarded emails
Can I analyse a normally forwarded email without the .eml file?
Yes, but the analysis will be partial. Without the original .eml, the Received headers, the attacker's server IP and the DKIM signature are lost — the most valuable evidence for identifying the real origin of the fraud.
What if I already forwarded the email normally and lost the headers?
If you still have the original email in your inbox, you can analyse it directly in ORTSLAB by pasting its full content or uploading the .eml file. If you have already deleted it, the analysis will be limited to whatever data survived the forwarding process.
Does a forwarded email have legal validity for filing a complaint?
It depends on the method and how it is documented. For a police report it may be sufficient as a starting point. For civil or criminal proceedings where the email is the primary evidence, the original .eml and a forensic report signed by a certified judicial IT expert are essential.
Do I need a digital forensics expert to document email fraud?
If there is financial loss, identity theft or the case is heading to court, yes. A forensic expert report technically establishes the origin of the message, the identity of the attacker and the damages caused, and carries full evidential weight in legal proceedings.
If you need to document email fraud for a formal complaint, legal proceedings or an insurance claim, Oscar Orts — a certified judicial computer expert — issues forensic reports on digital fraud and identity impersonation.