CHFI Application, Email and Cloud Forensics Practice Question
An email forensic investigator examines a suspicious email and notices the following header: Received: from mail.evil.com (192.168.1.100) by mail.company.com. The DKIM-Signature header fails verification. What does this indicate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The email may be spoofed or its content altered
A failing DKIM-Signature indicates the email may have been tampered with during transit or was not signed by the claimed domain. This is a strong indicator of email spoofing or alteration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The receiving server rejected the email
Why it's wrong here
DKIM signature verification failure does not automatically imply that the receiving server rejected the email. SMTP rejection based on DKIM only occurs if a domain's DMARC policy is set to 'p=reject' and the message fails DKIM and SPF alignment; otherwise, the server may accept and quarantine it. The presence of a DKIM failure in headers indicates the message was still delivered, making this option factually incorrect.
- ✗
The email is legitimate and was forwarded through a relay
Why it's wrong here
While legitimate forwarding through a relay or mailing list can break DKIM signatures due to header or body modification, the mere fact that a relay was involved does not establish the email as legitimate. A DKIM failure actually indicates that the signature cannot be cryptographically validated against the sender domain's public key, which is a hallmark of potential tampering, not authenticity. Therefore, this option misreads the evidence and incorrectly concludes legitimacy from a signature mismatch.
- ✗
The email was sent from a compromised mail server
Why it's wrong here
A compromised mail server scenario would involve an attacker gaining access to the private signing key, allowing them to produce valid DKIM signatures that pass verification. In this case, DKIM is failing, meaning the signature is invalid or the domain does not match, which points to spoofing or alteration rather than a server compromise. The indicator is about signature misalignment, not about the internal state of the sending infrastructure, making this an unsupported inference.
- ✓
The email may be spoofed or its content altered
Why this is correct
A DKIM failure means the message's signature does not verify against the public key published in the claimed sending domain's DNS records. This can occur when an attacker spoofs the domain and sends unsigned or incorrectly signed mail, or when the message body or selected headers were changed after the original signature was applied. Either way, the email is unreliable and may have been tampered with, directly supporting the conclusion that it is potentially spoofed or altered.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.