Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

An email forensic analyst receives a suspicious email and examines the full headers. Which header field is the MOST reliable for determining the true originating IP address of the sender, assuming no spoofing of the header?

⚠ Common exam trap

EC-Council often tests that candidates confuse the 'From' or 'Return-Path' headers with the actual origin IP, but the trap is that these fields are easily spoofed and contain no IP information, whereas the 'Received' headers provide the true network path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Received

The 'Received' header is the most reliable for determining the true originating IP address because each mail server that handles the email adds a new 'Received' field at the top of the header. The bottommost 'Received' header (the first one added) typically contains the IP address of the sender's MTA or the client's IP, assuming no spoofing. This field is sequentially added by each hop and is the primary source for tracing the email's path back to its origin.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Return-Path

    Why it's wrong here

    The Return-Path header identifies the envelope sender used for bounce messages, but it is set by the sender's mail server and can be arbitrarily forged. It does not record any routing hops or originating IP information. Even when it appears legitimate, an attacker can easily spoof it, so it has no forensic value for tracing the true source of an email.

  • ✓

    Received

    Why this is correct

    Each mail server that processes the email prepends its own Received header, creating a chronological chain from the origin to the destination. The bottommost Received header, added first, typically reveals the originating IP address of the sender's mail server or client, which is why it is the primary evidence for tracing. While the last Received header is added by the receiving server, the chain can be partially forged if the sending server is malicious, so analysts corroborate the first Received header with server logs.

  • ✗

    Message-ID

    Why it's wrong here

    The Message-ID header is a unique identifier generated by the composing mail client, used for message threading and caching; it contains no IP address or routing information. An attacker can craft any arbitrary Message-ID, including one that imitates a legitimate system, so it cannot be used to establish the sender's origin. It may help correlate messages across different logs, but it lacks the transactional data needed for forensic source tracing.

  • ✗

    From

    Why it's wrong here

    The From header contains simply the display name and email address the sender chooses to expose, and SMTP does not authenticate this field. As a result, it is trivially spoofed to impersonate a trusted party, meaning it provides no reliable evidence of the actual sender's IP or identity. Its only forensic utility is as a semantic indicator of intent, which must be verified against authentication records such as SPF, DKIM, or DMARC.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.