We are launching this blog with a series of articles dedicated to precisely defining how an email is structured, what parts compose it, and which elements need to be reviewed to determine the potential threats that may exist.

An email is not just what you see on screen. Behind the sender name and message text there is a complete technical structure: authentication headers, transport routes, DKIM signature and more. Understanding these parts is what allows you to tell a legitimate email from a fake one. Before analyzing fraud, spoofing, or social engineering techniques, it is essential to understand the complete anatomy of an email. A rigorous analysis is only possible through structural knowledge.

To better visualize this structure, here is a general diagram of the parts of an email:
Article image

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

1. Main Headers (Visible Headers)

2. Authentication Headers

3. Transport Routes (Traceability)

4. MIME Structure

5. Message Body

6. Potentially Manipulable Elements

Continuation

In the next article, we will begin to detail each of these components, explaining their actual function, how they can be manipulated, and which indicators allow for the identification of potential fraud or spoofing attempts.

Understanding the structure is the first step. The technical analysis begins next.