Keeping email headers for a BEC case
A supplier email looks genuine, and the hidden header can show exactly where it came from.
Updated 2026-09-29 · Independent resource. Legal review pending.
Why the email header matters more than the message
The visible sender name on a fraudulent email can be changed easily, but the header underneath carries technical details that are much harder to fake. It records the actual servers the email passed through before reaching you.
This is often what shows a domain was spoofed or slightly altered, such as one letter changed in the sender’s address. Read what to save after a BEC attack for the wider picture of what your business should keep.
How to find the full header in common email systems
In Gmail, open the email, click the three dots in the top right, and select “Show original” to view the full header as text. In Outlook, open the email, then find “View” or “Message options” to see the internet headers.
Save this as a text file or a screenshot covering the entire header, not just a portion, since the routing information runs across several lines. If your business uses a different email system, your IT team can usually find the same option.
What the header can show even without technical knowledge
The header lists the sending server’s address and the path the email travelled, which can reveal it did not come from where the display name suggests. It also shows the exact date and time the email was sent, down to the second.
You do not need to interpret every line yourself. Save the full header and let your bank, the police, or a lawyer make sense of the technical parts.
Save the header alongside the rest of the case
Keep the header together with the fraudulent email itself, the genuine email it copied or replaced if one exists, and the payment records tied to it. On its own, a header means little without the context of what was paid and when.
Read how to build a transaction chronology so the header, the payment, and the internal approval trail all sit in one clear timeline.
What to do next
Provide the full header to your bank when disputing the payment, and include it in your police report so investigators can trace the sending source. Ask your IT team to check whether any other inbox was affected in the same way.
Once this is saved, read how to organise evidence for a lawyer to bring it together with your other business records.
If your business has the fraudulent email but you are not sure how to extract the header properly, tell us what happened and we will help you see the next step.
Common questions
What if our email system does not have a clear 'view header' option?
Most systems have one, even if it is labelled differently, such as 'show original' or 'internet headers'. Search your email provider's help pages for the exact steps, or ask your IT provider to export it for you.
Is a screenshot of the header good enough, or do we need the raw text?
The raw text version is more useful, since it can be copied, searched, and analysed properly, while a screenshot can miss lines if the header is long. Save both if you can, with the text version as the priority.
Should every staff member's inbox be checked, or just the one that received the fraudulent email?
Ask IT to check other inboxes with similar access or the same supplier relationship, since the same method is sometimes used against more than one person. This helps confirm whether the compromise was limited to one account.
Read next
How to organise evidence for a lawyer
Here is how to organise your screenshots, records, and messages into a clear file before you speak to a lawyer about your case.
Read thisWhat to save after a BEC attack
If your business paid a fraudulent invoice through business email compromise, here is exactly what to preserve for the bank, police, and any claim.
Read thisHow to build a transaction chronology
If your scam involved more than one payment, here is how to build a clear transaction chronology that a bank, the police, or a lawyer can follow.
Read thisFiling a police report for a scam
A police report matters even for a small loss. Here is where to file one, what to bring, and why it supports later steps.
Read thisIf your business has the fraudulent email but you are not sure how to extract the header properly, tell us what happened and we will help you see the next step.