Treat conversation continuity as evidence that can change
A familiar subject line, quoted history and display name can make a later message feel like part of an established business conversation. The investigation should not rely on that visual continuity. Capture a known earlier message and the message that introduced the sensitive request, then compare the underlying identities that mail systems actually carried: From address, Reply-To, Return-Path, DKIM signing domain, Message-ID domain and receiver-stamped authentication.
Start with the visible From identity and display-name relationship
A display name can remain identical while the address changes to another domain or alias. That pattern deserves review because users often scan the name more quickly than the full address. A changed address is not automatically malicious: suppliers can migrate platforms or route mail through another authorized domain. The useful finding is the discontinuity itself, which tells an investigator where independent confirmation is needed.
Compare reply routing separately from sender presentation
Reply-To can intentionally direct replies somewhere different from the visible From address. Support systems and ticketing platforms use this legitimately, but a newly introduced Reply-To in a financial thread materially changes where the next message will go. Compare it with earlier messages and with the sender organization’s known communication workflow rather than deciding from syntax alone.
Use authentication as one layer, not a safety verdict
A DMARC failure on the later message can strengthen an identity-anomaly finding, but forwarding can alter authentication and a compromised legitimate account can still send fully authenticated mail. Likewise, a message signed by a different DKIM domain can reflect an authorized provider change. Read SPF, DKIM, DMARC and ARC in context with the identity transition instead of collapsing them into a binary safe-or-fraud label.
Payment-change language changes the verification threshold
The FBI advises businesses to verify changes in account numbers or payment procedures using a trusted method rather than relying on the email request itself. An analyzer can flag phrases such as new bank details, wire instructions, beneficiary changes or urgent invoice requests as context, but language detection is not evidence of criminal intent. Its role is to raise the priority of independent verification when identity evidence also changed.
Preserve the pair that explains the transition
For a practical case record, preserve the earlier message, the later message, their raw headers and the exact fields that changed. Avoid replacing the original evidence with screenshots alone. Mailybox’s BEC Conversation Hijack Analyzer compares those two states and its Incident Timeline Builder extends the same method across a larger sequence so the first material identity transition remains visible.
Verify the evidence
Use the live analysis that matches this workflow instead of relying on a generic status check.