Search
  • For Individuals
      « Back
    • Windows Data Recovery

      Recovers lost or deleted Office documents, emails, presentations & multimedia files.

      Free Standard Professional Premium

    • Mac Data Recovery

      Recovers deleted files, photos, videos etc. on Mac.

      Free Standard Professional Premium

    • Photo Recovery

      Recover photos, videos, & audio files from all cameras and storage on Windows or Mac.

      Free Standard Professional Premium

    • Video Repair
    • Photo Repair
    • iPhone Data Recovery
  • For Business
      « Back
    • Email Repair & Converter

      Repair for Exchange Converter for EDB Converter for OST Converter for NSF Converter for OST MBOX Repair for Outlook

    • Database & File Repair

      Repair for MS SQL Repair for Access Repair for QuickBooks Software Repair for Excel Extractor for Windows Backup Repair for MySQL

    • Data Recovery & Erasure

      Data Recovery Professional Data Recovery Technician Mac Recovery for Technician Virtual Machine Recovery File Erasure Software Mobile Erasure Drive Erasure File Eraser Software File Eraser Software for Mac

    • Toolkit

      Exchange Toolkit Outlook Toolkit File Repair Toolkit MS SQL Toolkit Data Recovery Toolkit

    • Forensic

      Email Forensic Exchange Auditor Log Analyzer for MySQL Log Analyzer for MS SQL

  • Store
  • Partners
  • Services
  • Offers
  • Support

 

  • For Individuals
    DIY software for anyone who works with data.

    Windows Data Recovery Recovers lost or deleted Office documents, emails, presentations & multimedia files

    Free Standard Professional Premium

    Mac Data Recovery Especially for Mac users to recover deleted documents and multimedia files from macOS

    Free Standard Professional Premium

    Video Repair Windows Mac Repair multiple corrupt videos in one go. Supports MP4, MOV & other formats.

    StandardPremium

    Photo Recovery Windows Mac Recover photos, videos, & audio files from all cameras and storage on Windows or Mac.

    Standard Professional Premium

    iPhone Data Recovery Windows Mac Recover deleted photos, videos, contacts, messages etc. directly from iPhone & iPad

    Recover Erase Toolkit

    Photo Repair Windows Mac Repair multiple corrupt photos in one go. Supports JPEG & other formats.

    Standard Professional Premium


  • For Business
    • Email Repair
    • Email Converter
    • File Repair
    • Data Recovery & Erasure
    • Toolkit
    • Forensic

    Exchange Repair Repair corrupt EDB file & export mailboxes to Live Exchange or Office 365

    Outlook PST Repair Repair corrupt PST & recover all mailbox items including deleted emails & contacts

    OLM Repair Repair Outlook for Mac (OLM) 2011 & 2016 backup files & recover all mailbox items

    Exchange Toolkit Repair EDB & Exchange backup file to restore mailboxes, convert OST to PST, & convert EDB to PST

    Active Directory Repair Repair corrupt Active Directory database (Ntds.dit file) & extract all objects in original form

    EDB to PST Convert online & offline EDB file & extract all mailbox items including Public Folders in PST

    OST to PST Convert inaccessible OST file & extract all mailbox items including deleted emails in PST

    NSF to PST Convert IBM Notes NSF file & export all mailbox items including emails & attachments to PST

    MBOX to PST Convert MBOX file of Thunderbird, Entourage & other clients, & export mailbox data to PST

    OLM to PST Convert Outlook for Mac Data File (OLM) & export all mailbox data to PST in original form

    GroupWise to PST Convert GroupWise mail & export all mailbox items - emails, attachments, etc. - to PST

    EML to PST Convert Windows Live Mail (EML) file & export mailbox data - emails, attachments, etc. - to PST

    Office 365 to PST Connect to Office 365 account & export mailbox data to PST and various other formats

    DBX to PST Convert Outlook Express (DBX) file & export all mailbox data - emails, attachments, etc. - to PST

    SQL Repair Repair corrupt .mdf & .ndf files and recover all database components in original form

    Access Repair Repair corrupt .ACCDB and .MDB files & recover all records & objects in a new database

    QuickBooks Repair Repair corrupt QuickBooks® data file & recover all file components in original form

    MySQL Repair Repair MyISAM & InnoDB tables and recover all objects - keys, views, tables, triggers, etc.

    Excel Repair Repair corrupt Excel (.XLS & .XLSX) files and recover tables, charts, chart sheet, etc.

    BKF Repair Repair corrupt backup (BKF, ZIP, VHDX and .FD) files and restore complete data

    Database Converter Interconvert MS SQL, MySQL, SQLite, and SQL Anywhere database files

    PowerPoint Repair Repair corrupt PPT files and restore tables, header, footer, & charts, etc. like new

    File Repair Toolkit Repair corrupt Excel, PowerPoint, Word & PDF files & restore data to original form

    Data Recovery Windows Mac Recover lost or deleted data from HDD, SSD, external USB drive, RAID & more.

    Technician Toolkit

    Tape Data Recovery Retrives data from all types and capacities of tape drives including LTO 1, LTO 2, LTO 3, & others.

    Virtual Machine Recovery Recover documents, multimedia files, and database files from any virtual machine

    File Erasure Permanently wipe files and folders, and erase traces of apps and Internet activity.

    Standard Corporate

    Mobile Erasure Certified and permanent data erasure software for iPhones, iPads, & Android devices

    Drive Erasure Certified and permanent data erasure software for HDD, SSD, & other storage media Windows Mac

    Exchange Toolkit 5-in-1 software toolkit to recover Exchange database, convert EDB to PST, convert OST to PST, restore Exchange backup, and reset Windows Server password.

    Outlook Toolkit Comprehensive software suite to repair PST files, merge PST files, eliminate duplicate emails, compact PST files, and recover lost or forgotten Outlook passwords.

    File Repair Toolkit Powerful file repair utility to fix corrupt Word, PowerPoint, and Excel documents created in Microsoft Office. It also repairs corrupt PDF files and recovers all objects.

    MS SQL Toolkit 5-in-1 software toolkit to repair corrupt SQL database, restore database from corrupt backup, reset database password, analyze SQL logs, & interconvert databases.

    Data Recovery Toolkit Software helps to recovers deleted data from Windows, Mac and Linux storage devices. Also supports recovery from RAIDs & Virtual Drives.

    Email Forensic Advanced email forensic solution for cyber experts to audit, analyze, or investigate emails & gather evidences.

    Exchange Auditor Exchange Server monitoring solution to automate audits, scans and generate reports ìn real-time.

    Log Analyzer for MySQL Analyze forensic details of MySQL server database log files such as Redo, General Query, and Binary Log.

    Log Analyzer for MS SQL Track & analyze MS SQL Server database transactions log files.

    STELLAR EMAIL FORENSIC

    Advanced email forensic tool to analyze and collect the mailbox data of email clients

    Learn More arrow


    All Products

    All Products

    All Products

    All Products

  • Our Partners
  • Lab Services
  • Trending Searches

    Data Recovery

    Photo Recovery

    Video Repair

    iPhone Data Recovery

    File Erasure Software

    Exchange Repair

    OST to PST

    PST Repair

    Raid Recovery

    MS SQL Repair

  • English Deutsch Français Nederlands Italiano Español 日本語 简体中文
  • Support
Email Forensics 5 minute read

Importance of Message-ID in Forensic Examination of Emails

Updated on May 27th, 2022
Abhinav Sethi
Written By
Abhinav Sethi
Kuljeet Singh
Approved By
Kuljeet Singh

When digital forensics investigators study emails to find the source of spoofed messages, they have to analyze every field of email architecture. Email header is one of the vital resources that contains many important fields, one of which is Message-ID. So, it is important to understand what Message-IDs are, how they are created and extracted, and how they can help investigators in extracting useful information.

Taking a Closer Look at Message-ID

According to RFC 2822, standard for the format of Advanced Research Projects Agency (ARPA) Internet text messages or emails, each email should have a globally-unique identifier to distinguish it from other emails. This identifier is called Message-ID, an important field in the email header. It comprises a long string of characters that end with the Fully Qualified Domain Name (FQDN).

Message-IDs are generated by client programs that send emails such as Mail User Agents (MUAs) or Mail Transfer Agents (MTAs). The following figures consist of a sample Message header:

Figure 1: Part 1 of Sample Message header
Figure 2: Part 2 of Sample Message header

After analyzing the message header, the following information can be retrieved:

Figure 3: Information retrieved from Sample Message header

In the above-mentioned figure, the Message-ID is 20200612190818.3E16E1FBE8@serverxx.xxxxx.xxx,
There are two parts of a Message-ID. One part is before @ and another part is after @.

Most of the mail services incorporate the date and time, at which an email is sent, into the Message-ID, along with other random string of characters to distinguish it from other emails. In the sample Message-ID above, the mail system has used timestamp information of the message at the time when it was sent. The date and time format are in the form of YYYY-MM-DD-HH-MM-SS. Extracting the details from the timestamp (the numerical value in the first part till the first dot: 20200612190818), we can know the following details:

  • Year: 2020
  • Month: June (06)
  • Day: 12
  • Time: 19:08:18 (Hours:Minutes:Seconds)

The second part of the Message-ID contains the details of the FQDN. It shares important details such as the local hostname which is serverxx and the local domain name which is xxxxx.xxx.

You can find the Message-ID of an email in its message header. The following are the steps to extract the message header of an email in Gmail and Outlook:

How to Obtain Message-ID in Gmail?

To obtain the Message-ID of a Gmail message, follow the given steps:

Step 1: Open the email message.

Step 2: Click the icon with three dots on the top-right of the message box and select Show original from the options. [See Figure 4]

Figure 4: Extracting email header in Gmail

Step 3: It will open a new tab that contains all the fields of the email header. You can find the Message-ID in it. [See Figure 5]

Figure 5: Message-ID in Gmail

You can also instantly locate it by using the search function of your web browser (usually activated by CTRL+F key combination) and searching with the keyword “Message-ID”.

How to Obtain Message-ID in Outlook?

The steps to obtain Message-ID of an email in Microsoft Outlook are given below:
Step 1: Open the email message and click on more actions (v) menu to expand it. [See Figure 6]

Figure 6: Process for extracting email header in Outlook

Step 2: Click View message details. [See Figure 7]

Figure 7: Extracting email header in Outlook

Step 3: It will open a new window that contains the email header. You can find the Message-ID. [See Figure 8]

Figure 8: Message-ID in Outlook

Challenges with Message-ID in Email Forensics

Message-ID is a unique identifier that helps to distinguish emails across the globe. An email forensic expert can break it down to discover important details about an email and its MTA. However, there are a few challenges:

  • The majority of mail systems add the Message-ID field in their emails. However, it’s an optional detail and you may come across an email that doesn’t contain Message-ID.
  • No standard algorithm is used for Message-IDs generation and each mail service uses its own algorithm to generate unique identifiers. You must have a sound understanding of multiple email platforms and their Message-ID formats to decode these identifiers for a comprehensive investigation.
  • You can understand the construction of a Message-ID of open source email MTAs as documentation is easy to obtain. However, proprietary programs can make acquiring information a challenge.

Looking Beyond Message-IDs for Comprehensive Email Examination

Message-ID is an important email header field and can be of huge help in the investigation. However, forensic experts need all kinds of additional details to conduct investigations. For instance, useful information can be readily found in other email header fields, like Received: where the details of each server that’s relayed an SMTP message is cumulated, or X-headers where details of security devices like email anti-virus are found. Similarly, for closer inspection of attachments, their Hex values may be required.

Forensic experts correlate multiple pieces of information in an email message to trace its origin. This can only be done efficiently and timely with the help of a reliable and feature-rich tool, such as Stellar Email Forensic. This software is engineered for accuracy, speed, and versatility, and supports 25+ email file formats. It allows you to perform granular search for emails and offers case management facility.

Download a free trial version of Stellar Email Forensic software to start your email investigation now. The software is available for a free 60-day trial.

About The Author

Abhinav Sethi

Abhinav Sethi is a Senior Writer at Stellar. He writes articles, blog posts, knowledge-bases, case studies, etc. for different technologies. He also has a keen interest in digital forensics and helps forward-thinking companies fight different threats with apt solutions.

Best Selling Products

Stellar Reporter & Auditor for Exchange Server

Exchange reporter & auditor is an automa

Read More

Stellar Repair for Active Directory

It is a professional Active Directory re

Read More

Stellar Toolkit for Exchange

5-in-1 suite of specialized tools, highl

Read More

Stellar Toolkit for Outlook

It is 8-in-1 software kit to automate ad

Read More

Leave a comment Cancel reply

Your email address will not be published. Required fields are marked *

21  −    =  17

Table of Contents    

Categories

Related Posts

Email Forensics

Challenges while Recovering Deleted Emails from Email Clients and Services

Stellar Author Abhinav Sethi August 26, 2020 Read More
Email Forensics

Approaches to Filter Emails for Forensic Investigation

Stellar Author Abhinav Sethi August 25, 2020 Read More
Email Forensics

Importance of MX Records in Email Forensic Investigation

Stellar Author Abhinav Sethi July 9, 2020 Read More

Stellar Official Website

Stellar Data Recovery Inc.
48 Bridge Street Metuchen,
New Jersey 08840,
United States

ALSO AVAILABLE AT

About

  • About us
  • Career
  • ISMS Policy
  • Privacy Policy
  • Terms of Use
  • License Policy
  • Refund Policy
  • End User License Agreement

RESOURCES

  • Blog
  • Articles
  • Product Videos
  • Knowledge Base
  • Case Studies
  • Whitepapers
  • Software Catalog

NEWS & EVENTS

  • News
  • Events

PARTNERS

  • Affiliates
  • Resellers
  • Distributors

Useful Links

  • Contact Us
  • Support
  • Special Offers
  • Student Discounts
  • Awards & Reviews
  • Downloads
  • Store
  • Sitemap
Follow Us

Stellar & Stellar Data Recovery are Registered Trademarks of Stellar Information Technology Pvt. Ltd. © Copyright 2022 Stellar Information Technology Pvt. Ltd. All Trademarks Acknowledged.

DMCA.com Protection Status
We use cookies on this website. By using this site, you agree that we may store and access cookies on your device Read More Got it!