What this analysis does
Paste raw .eml content or a complete header to create a SHA-256 evidence fingerprint, message and header hashes, identity snapshot, receiver-stamped authentication summary, transit metadata, content-type inventory, attachment filenames and visible URL hosts. The downloadable manifest documents the supplied evidence without claiming formal chain of custody.
When an email may support a dispute, an insurance claim or a report to law enforcement, the technical facts need to be recorded in a form that survives being passed between people. A manifest captures the cryptographic hash and the observable evidence together, at a known point in time.
Hash first, analyze afterwards
A cryptographic hash of the original file is what allows the message examined later to be shown to be the message collected. Compute it before any analysis, note when it was computed, and store it separately from the file itself.
The order matters because analysis workflows frequently modify files without anyone intending to. Opening a message in some clients rewrites headers or flags, and a hash taken afterwards no longer describes what arrived.
- Compute the hash before opening or analyzing the file.
- Record the time the hash was computed.
- Store the hash separately from the file it describes.
Record observations, not conclusions
A manifest documents what is present: the identities the message asserted, the authentication results receiving systems recorded, the transit chain, the MIME structure and the visible link surface. Each is an observation that another examiner can independently verify against the same file.
Interpretation belongs elsewhere. Recording that a DMARC failure was present is an observation; asserting that the message was fraudulent is a conclusion, and mixing the two weakens a document whose value depends on being neutral.
Keep the original unmodified
Work from a copy and preserve the original exactly as collected. Save the message using a client function that produces the original file rather than forwarding it, since forwarding discards the headers the manifest depends on.
Record where the file came from and who collected it. A manifest for a message someone forwarded from an unspecified source is materially weaker than one for a file saved directly from the recipient mailbox by an identified person.
Read the evidence and hashing guideBuild a timeline across several messages
Example: documenting a disputed message
Evidence supplied
A complete message file saved from the recipient mailbox.
How to read the result
The manifest records the file hash, the asserted identities, the authentication results present in the header, the transit chain and the extracted link surface, in a portable format that another examiner can verify against the same file.
Known limits
- A manifest documents technical observations and is not a legal determination.
- Evidentiary requirements differ by jurisdiction and proceeding.
- The manifest describes the file supplied and cannot establish how that file was obtained.
Common questions
Is a manifest admissible as evidence?
That is a question for the relevant jurisdiction and proceeding. The manifest records technical observations in a verifiable form; admissibility is decided elsewhere.
Why hash before analyzing?
Some clients modify files when opening them. A hash computed first describes the message as collected rather than as altered by handling.
Can a forwarded message be used?
It is much weaker. Forwarding replaces the original headers, which are the substance of the manifest. Use a saved original.