Analyzing Email Headers: SPF, DKIM, DMARC, and Received

Email header analysis is a controlled process that balances damage containment with evidence preservation. Document source, time, and tools, save Hash, build a Timeline, and separate fact, interpretation, and decision.
Incident Response and DFIR require a balance between speed, evidence preservation, business continuity, and documentation. A correct action is one that can be explained, reproduced, and reviewed after the incident. This article focuses on Email Header Analysis and is intended for SOC analysts and mail administrators. The goal is to provide a working methodology that can be applied in practice, in professional interviews, and in a work environment, without settling for a dictionary definition.
The main challenge is that data is almost always partial. Received chain, Return-Path, and SPF can indicate a direction, but their meaning depends on time, asset, user, and expected activity. Therefore, we will build the examination around an investigative question, required evidence, and a clear criterion for completion.
The practical scenario in the article is: decoding a simulated Header and marking anomalous points. All examples are laboratory data or process descriptions. When dealing with Penetration Testing, Web, or Cloud, work only with explicit authorization, a defined Scope, and the ability to stop the examination.




