CHFI Application, Email and Cloud Forensics Practice Question
Which email header field is MOST reliable for identifying the true origin of an email, assuming no header tampering occurred at the initial MTA?
⚠ Common exam trap
EC-CHFI often tests the misconception that the 'From' header is reliable for origin identification, but the trap is that 'From' is easily spoofed and is not validated by SMTP, whereas 'Received' headers are added by each MTA and provide a verifiable chain of custody.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Received
The 'Received' header is the most reliable for identifying the true origin of an email because each MTA that processes the message adds a new 'Received' header at the top, recording the IP address and timestamp of the previous hop. Assuming no tampering occurred at the initial MTA, the bottommost 'Received' header (the first added) contains the originating IP address of the sender's MTA or client, providing a direct trace back to the source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Received
Why this is correct
Received headers are prepended by every SMTP server that handles the message, so the bottom-most (earliest) Received line is added by the first device that accepts the message. This often reflects the original connecting IP address unless the sender controls a relay server that deliberately strips or alters headers. In forensic analysis, this chain is the most reliable source of the true origin.
- ✗
Message-ID
Why it's wrong here
The Message-ID header is a unique string generated by the client or first mail server to facilitate threading and deduplication. It contains no routing information, no timestamp of actual transmission, and no IP address. An attacker can easily generate a fake Message-ID or modify existing headers, so it offers no trustworthy evidence of the sender's origin.
- ✗
From
Why it's wrong here
The From header is a user-visible display field specifying the author of the email, but it is not cryptographically bound to the actual sending server. SMTP protocol itself performs no address authentication, allowing senders to spoof the From address with a direct or open relay connection. Even with SPF/DKIM alignment checks, the From header alone cannot reveal the IP address of the original sender.
- ✗
DKIM-Signature
Why it's wrong here
DKIM-Signature provides a cryptographic digest of the message body and selected headers, signed with the sending domain's private key. It validates that the message was handled by a server authorized by that domain, and it identifies a domain, not an IP address of the original client. A compromised or legitimate third-party sending service can sign messages on behalf of a domain, so a valid DKIM header does not and cannot pinpoint the originating IP.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.