How to Identify the Author of an Anonymous Email
By Juan Jesús Merino Carretero, chartered computer engineer no. 89 (CPIIEX) email · anonymous · computer forensics
Receiving a threatening or defamatory anonymous email is more common than it seems. Companies that receive extortion emails, individuals being harassed, law firms that receive emails with leaked confidential information… The question is always the same: how do you identify who is behind it? The answer combines computer forensics techniques with legal procedures: technical analysis provides indicators; court proceedings provide definitive authorship.
What an anonymous email always carries
Even if the sender tries to hide behind an alias, a disposable account or an “anonymous” email service, every email carries metadata that can be analyzed. The most relevant are:
1. Technical headers
Each email travels with a set of headers that record its path from the originating server to the destination one. The key headers are:
Received: each hop the email has made, with the IP of the sender or the server.Return-Path: address to which bounces would be returned.Message-ID: unique identifier assigned by the originating server.X-Originating-IP: on some services, the sender’s IP.Authentication-Results: SPF, DKIM and DMARC, which indicate whether the email is authentic or spoofed.User-AgentorX-Mailer: the client from which it was sent.
2. Client metadata
If the email was sent from a desktop client (Outlook, Thunderbird, Apple Mail), the headers can reveal the software version, operating system and regional settings.
3. Language patterns and timing
Analysis of the writing (stylometry) and the sending times are complementary indicators that help narrow the circle of suspects in internal investigations.
Steps of the investigation
Step 1: Obtaining the email in its original format
The first mistake many people make is forwarding the email to the expert or the lawyer. That destroys the original headers of the first sending. The correct approach is:
- In Gmail: “Show original” (or “View original message”).
- In Outlook: the original
.emlor.msgfile. - In Apple Mail: dragging the email to a Finder folder generates an
.eml. - On the server (when possible): the email exactly as it arrived, without any client modifications.
Step 2: Header analysis
The expert examines the Received headers from bottom to top (the chronological order of the email):
Received: from mail.proveedor.com ([X.X.X.X])
by smtp.destino.com with ESMTPS
for <[email protected]>; Tue, 30 Apr 2026 09:14:22 +0200
The IP in the first Received (the oldest) is usually that of the sender’s server, and sometimes that of the client itself.
Step 3: IP geolocation and attribution
Once the IP has been identified, the expert consults:
- WHOIS databases (RIPE, LACNIC, ARIN): holder of the IP range.
- Geolocation: geographic approximation.
- Proxy / Tor / VPN lists: whether the IP belongs to an anonymization service.
If the IP belongs to an ISP (Movistar, Vodafone, Orange, etc.), the ISP knows which customer was assigned that IP at that moment. But that information is only obtained with court authorization.
Step 4: Court request to the ISP or provider
If the investigation is serious, the next step is a court order asking the ISP for the IP holder’s details at the exact date and time. Under the Ley de Conservación de Datos (Ley 25/2007, the Spanish Data Retention Act), Spanish ISPs must keep these records for 12 months. After that period, the data is lost.
To do so the lawyer:
- Files a criminal complaint or lawsuit with the expert report.
- Requests an interim measure of preliminary proceedings or identification of the IP user.
- The court, if it sees fit, issues an order to the ISP.
- The ISP responds with the contract holder.
Step 5: Complementary investigation
With the holder identified, the expert and the lawyer supplement the investigation with:
- Analysis of the suspect’s device (with court authorization).
- Cross-referencing of times and location.
- Review of parallel accounts on social media or forums.
- Stylometric analysis of the email’s language compared with other texts by the suspect.
Technical limitations
Not all emails are 100% traceable. The main obstacles:
- Email sent through anonymizing services (Tor, ProtonMail with strict policies, Tutanota): the originating IP is hidden or not retained.
- Commercial VPNs that keep no logs.
- Accounts created with false data and from public networks (WiFi in cafes, libraries).
- Emails more than 12 months old: the ISP no longer keeps the IP assignment records.
- Disposable email services (Mailinator, 10minutemail).
Despite these limitations, most anonymous emails in real cases are not sent with so many precautions and can be traced successfully.
Typical case: extortion email to a company
- The company receives an anonymous email threatening to publish confidential information unless a sum is paid.
- The expert receives the email as the original
.eml. - Analyzes the headers → identifies a Spanish IP belonging to an ISP.
- The company files a criminal complaint with the expert report.
- The court issues an order to the ISP.
- The ISP returns the IP holder at that date and time.
- The author is identified: in many cases, a former employee or a competitor.
Forenlab has been involved in cases of this profile in a wide variety of sectors.
Identifying authors on social media and forums
The methodology is similar but with nuances:
- The platforms (Twitter/X, Facebook, Instagram, LinkedIn, Telegram) respond to court orders.
- There are international cooperation treaties (especially with the US via MLAT).
- For small forums and messaging services with no seat in Europe, identification is harder.
Frequently asked questions
Can I identify the author without going through the court?
What does not require a court is the technical analysis (headers, IP). What does require a court is obtaining the IP holder from the ISP. Without that step, definitive attribution is normally not possible.
How long does the investigation take?
Technical analysis: 5-10 days. Court proceedings: variable depending on the court (weeks or months).
What happens if the email comes from outside Spain?
International judicial cooperation applies. For the US it is reasonably effective; for some Asian or offshore countries it is very slow or impossible.
Is it worth trying if 12 months have passed?
You lose the ISP data, but other avenues may remain (stylometric analysis, associated accounts, the suspect’s devices) if there are concrete indications.
Do the police investigate for free?
State security forces investigate in criminal cases (serious threats, extortion, harassment). For civil cases or private disputes, the party-appointed expert provides the technical report that supports the criminal complaint.
Conclusion
Identifying the author of an anonymous email is feasible in most cases if you act quickly (within 12 months) and with forensic methodology. Header analysis and IP traceability are the backbone of the work, complemented by court proceedings to obtain the holder’s identity. At Forenlab we analyze anonymous emails with documented chain of custody and prepare the expert report for a criminal complaint or lawsuit. Contact us and we will reply within 24 business hours.