Email Crime Investigation for Bankers
The 'From' line can be forged; the header and the logs can't easily be. Here is how an email becomes evidence.
Email is still the cheapest way into a bank. A forged sender address, a look-alike domain or a compromised mailbox can move money without any malware at all. Email crime investigation is the work of finding out where a message really came from and preserving it so that it can be used in court.
Branch and operations staff rarely run the technical analysis themselves. What the exam expects is that you recognise the crime, know which parts of an email can be trusted, and avoid the mistakes that destroy evidence in the first hour.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Email Crimes a Bank Meets
- Email spoofing
- Forging the 'From' address so a message appears to come from someone else, such as the bank's own CEO.
- Business email compromise (BEC)
- A fraudster takes over or imitates a supplier's or customer's mailbox and sends genuine-looking instructions, typically 'our bank account has changed, pay the next invoice here'.
- Look-alike domain
- A domain one character away from the real one, such as a zero in place of the letter o, registered to fool a reader at a glance.
- Email bombing
- Flooding an inbox with thousands of messages, sometimes to bury a genuine fraud alert.
- Threat and extortion emails
- Messages demanding money under threat of leaking data or disrupting systems.
Reading an Email Header
Every email carries a header, a block of technical lines most mail apps hide. The 'From', 'Reply-To' and display name are typed by the sender and can be faked. The 'Received' lines are added by each mail server the message passes through, newest at the top, so an investigator reads them from the bottom up. The lowest Received line added by a server the sender does not control is the most reliable pointer to where the message entered the internet.
Mail systems also stamp an authentication result. SPF checks whether the sending server is allowed to send for that domain, DKIM checks a cryptographic signature on the message, and DMARC tells receiving servers what to do when those checks fail. RBI's 2026 directions require banks to implement DMARC on their email domains, take measures against spoofing and look-alike domains, and control which attachment types are allowed.
A classic BEC tell is a 'Reply-To' that differs from the 'From': the reply goes to the fraudster even though the sender looks genuine.
Preserving an Email as Evidence
A corporate customer's accounts team paid ₹18 lakh by RTGS to a 'new' supplier account after an email. What the bank does next, in order:
- 1
Don't forward it as evidence
Forwarding rewrites the header. Ask the customer to keep the original in the mailbox and export it in its native format (.eml or .msg) with full headers.
- 2
Record and hash
Note who collected it, when and from which mailbox, and compute a hash value so any later change is detectable.
- 3
Act on the money first
Report the fraud immediately through the bank's fraud channel and the national cyber crime helpline so the receiving account can be traced and frozen.
- 4
Secure the logs
Mail server and gateway logs show the connection details. CERT-In's 2022 directions require organisations to keep ICT logs for a rolling 180 days within India.
- 5
Certify for court
An electronic record is admitted under section 63 of the Bharatiya Sakshya Adhiniyam, 2023 with a certificate signed by the person in charge of the device or activity and by an expert.
Quick practice on banking operations. No signup.
Section 65B Is Now Section 63
From 1 July 2024 the Bharatiya Sakshya Adhiniyam, 2023 replaced the Indian Evidence Act, 1872. The electronic-evidence certificate that study material calls a 'section 65B certificate' now sits in section 63 of the BSA, which requires it to be signed by the person in charge and by an expert. The IT Act separately lets the Central Government notify an Examiner of Electronic Evidence (section 79A) to give expert opinion to courts.
How the IIBF Exam Tests This
- check_circleWhich header field can be trusted: not 'From', not the display name. The Received chain is the investigator's tool.
- check_circleEvidence handling: forwarding, printing or copying text out of an email are the wrong answers when the question is how to preserve it.
- check_circleOld law versus new: an option citing section 65B of the Evidence Act describes the pre-July 2024 position.
- check_circleCharging sections: impersonating someone to cheat by email fits IT Act s.66D (cheating by personation using a computer resource); misusing another person's password or signature fits s.66C.
FAQs
How do you trace the sender of a fake email?expand_more
Investigators read the 'Received' lines in the full header from the bottom up to find where the message entered the internet, then obtain logs from the mail provider through a lawful request. The 'From' line itself can be forged.
Is an email valid evidence in an Indian court?expand_more
Yes. Under section 63 of the Bharatiya Sakshya Adhiniyam, 2023, an electronic record is admissible when produced with the certificate the section requires, signed by the person in charge of the device or activity and an expert.
What is business email compromise?expand_more
A fraud where a criminal takes over or imitates a trusted mailbox, usually a supplier's, and sends payment instructions to a new account. It needs no malware and often no technical skill.
What is DMARC and do banks have to use it?expand_more
DMARC is an email standard that tells receiving servers how to treat messages failing sender checks, which cuts spoofing of a domain. RBI's 2026 cybersecurity directions require banks to implement it on their email domains.
Next steps
- Phishing, Vishing, Smishingarrow_forward
- Evidence & Custodyarrow_forward
- Investigationarrow_forward
- Database Hackingarrow_forward
120 questions, 2 hours, scored instantly.
