1
How to Extract Hidden
Information from an Email By: Samuel Steers
Note: This document is not created by a professional content writer so any mistake and
error is a part of great design
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com
2
Disclaimer
This document is generated by VIEH Group and if there is any contribution or or
credit, it’s mentioned on the first page. The information provided herein is for
educational purposes only and does not constitute legal or professional advice. While
we have made every effort to ensure the accuracy and reliability of the information
presented, VIEH Group disclaims any warranties or representations, express or
implied, regarding the completeness, accuracy, or usefulness of this document. Any
reliance you place on the information contained in this document is strictly at your
own risk. VIEH Group shall not be liable for any damages arising from the use of or
reliance on this document. also we highly appreciate the source person for this
document.
Happy reading !
Content Credit: Samuel Steers
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com
3
Introduction
In this article I will show you some verification processes you can take on emails you
receive from senders who you are not certain about. The first part of this article will
look into email address verification, the second part we will look into email
header analysis.
Emails like IP addresses (see my previous article here) contain a lot of interesting
information. On the surface you’ll just have the basics, such as an email address,
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com
4
potentially a name, and sometimes more details in the sender’s email signature.
We’ll have to dig a little below the surface to extract some additional information.
From an email we can extract the following:
• Does this email exist
• IP address
• ISP
• Get physical address (if possible)
• Look up search engines
Part 1 Email Address Verification
So you’ve received an email, firstly, we can check if this email really exists.Many cyber
criminals and scummy salespeople can spoof an email address.Here’s a dodgy email
I’ve received into my Spam folder on my Gmail account.Google’s Spam filters are
pretty good, so you probably won’t see emails like the one below in your inbox.
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com
5
Copying the strange email address we can go to EmailHippo and use their free email
verification tool
The email address brings back a bad result.
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com
6
Clicking on “MORE INFORMATION” we can get, you guessed it, more information on
the senders of the email. Now this specific email address didn’t bring back any
results, however just the result flag alone can give you enough information to ignore
that email you received. To show you some results EmailHippo gives, I used an
address from a list of spammers addresses:
For this example we used: zibhntffmq@excite.com His results from HippoEmail are
below
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com
7
Part 2 Email Header Analysis
On the next step, go back to the email in question and go to the ellipses and click
“Show original”.
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com
8
This will bring up the email header, which is the section of your mail that includes
information like the sender details, receiver details, subject, and date. Other technical
details like the Return Path, Reply-To Field, and Message ID are also included in
an email header. I’ve redacted my email address information.
You will then “copy to clipboard” and go to another site
called www.whatismyip.com and use their Email Header Analyser tool:
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com
9
Copying in the header info gives us the following:
• The source IP address the email was sent from
• The Hostname
• The Advanced Shipment Notice (ASN)
• The city, State/Region/country
• The ISP
We can use this information to further our search. With the IP address you can refer
to my previous article about tracing IP addresses:
https://medium.com/@samuel.i.steers/how-to-trace-and-ip-address-using-osint-
e9e0e8887bc0
Remember, like humans these tools can sometimes be wrong, so it is best to double
or even triple check the results. Using another email header analyzing tool we can
double check that the results initially found are correct. See below
using IP2Location’s free Email Header Tracer tool we garner the same results:
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com
10
Further
I would recommend that you use your own email address on these tools. You might
be surprised how much information people can find out about you on the internet.
Tools Used in this article
tools.emailhippo.com
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com
11
Thanks for reading
Social media:@viehgroup vww.viehgroup.com support@viehgroup.com