The extended email header is a hidden part of an email which isn’t routinely displayed. Every email has an extended header and careful analysis of the extended header can provide valuable information for an investigator.
No two email headers will be identical. However, typical information contained within the extended header would include:
It is important to note that the information contained within the extended header information be have been manipulated by the sender.
The video below shows how to locate the extended email headers when using any Microsoft Outlook email client.
In this trainer led exercise we will go through the process of examining an extended email header.
What additional information is hidden in the header?
How much information can you find contained within this header when under time pressure?
What additional lines of enquiry can be carried out as a result of your research?
Continuing from the previous exercise, the incident has progressed when another email is received.
What fast track actions would you undertake after examining this extended email header?
When directed, use what you have learned and analyse the extended email header which you've been sent.
Don't forget to update your report with your findings.
The number one rule that we following when analysing an extended email header is that we start from the bottom and work our way to the top.
We do this as the bottom of the email will contain the details of the sender - as you move up towards the top, you are following the email on its journey through the internet, passing through the routers and switches, until it arrives at its destination - at the top.
The key to making sense of the extended header is to break the information down into sections:
Once you have highlighted the above information, review what you have highlighted and resolve any IP Adresses and determine if this leads to any additional lines of enquiry.
In additional to manually going through this process, you may also wish to consider using this extended email header analysis tool developed by Google.
West Yorkshire Police - Digital Policing Team
Carr Gate Training Complex, Bradford Road
Carr Gate, Wakefield, WF2 0QD
Phone: x21764
© Copyright West Yorkshire Police 2025 - Crime Training Department. All right reserved.