During an investigation, an analyst extracts email headers from a suspicious email. The header includes: Received: from mail.attacker.com (192.168.1.100); DKIM-Signature: v=1; a=rsa-sha256; d=legitbank.com; s=selector1; bh=...; The email claims to be from support@legitbank.com. Which indicator strongly suggests email spoofing?
Trap 1: The email was sent on a weekend
A weekend send time is merely a timestamp in the email's header and does not cryptographically bind to the sender's identity. Spammers and phishers deliberately send at off-peak hours, while legitimate banks often issue automated security alerts on weekends. Thus, the day-of-week alone has no probative value for spoofing.
Trap 2: The DKIM signature uses RSA-SHA256 algorithm
DKIM's RSA-SHA256 is a standard signing algorithm used by the vast majority of legitimate email senders, including banks. A valid DKIM signature that verifies against the d= and s= selectors actually increases confidence in the message's provenance. The algorithm choice is simply a configuration detail and provides no evidence of spoofing.
Trap 3: The X-Originating-IP header is present
X-Originating-IP is a header commonly inserted by webmail clients and local mail user agents to record the TCP peer from which the message was submitted; it is often present on legitimate mail. This header is ad-hoc, not defined in RFC 5322, and can be easily forged or stripped by the mail client, so its mere presence does not correlate with malicious intent.
- A
The email was sent on a weekend
Why it fails: A weekend send time is merely a timestamp in the email's header and does not cryptographically bind to the sender's identity. Spammers and phishers deliberately send at off-peak hours, while legitimate banks often issue automated security alerts on weekends. Thus, the day-of-week alone has no probative value for spoofing.
- B
The DKIM signature uses RSA-SHA256 algorithm
Why it fails: DKIM's RSA-SHA256 is a standard signing algorithm used by the vast majority of legitimate email senders, including banks. A valid DKIM signature that verifies against the d= and s= selectors actually increases confidence in the message's provenance. The algorithm choice is simply a configuration detail and provides no evidence of spoofing.
- C
The X-Originating-IP header is present
Why it fails: X-Originating-IP is a header commonly inserted by webmail clients and local mail user agents to record the TCP peer from which the message was submitted; it is often present on legitimate mail. This header is ad-hoc, not defined in RFC 5322, and can be easily forged or stripped by the mail client, so its mere presence does not correlate with malicious intent.
- D
The Received header shows the email came from a server not owned by legitbank.com
The Received headers form a chronological relay trail, and the first Received line typically reflects the Mail User Agent or initial server that submitted the message. If that server is identified as attacker.com or an IP outside legitbank.com's published mail infrastructure, the message demonstrably did not originate from legitbank.com. A genuine bank email would have a Received chain matching its own mail servers, making this one of the most reliable indicators of spoofing.