Email Forensics & Admin Support
Budget: $15 – $25 USD
An employee’s mailbox was accessed by our current email administrator, who then sent a message under that person’s name. I need clear, defensible proof that the email originated from the administrator’s computer—not the employee’s.
Your first task is a small-scale forensic investigation. Please extract and interpret the full header, trace the sending IP address, and correlate it with server or workstation logs so I can demonstrate that the message did not leave the employee’s PC. Accuracy and chain-of-custody notes are important because this material may be presented internally (and potentially to legal counsel).
Once that is complete, I’d like to transition ongoing email and website management to someone trustworthy. Our stack is fairly typical—domain and DNS on GoDaddy, email on Microsoft 365, and a cPanel-based website—so routine administration, security hardening, and user support will follow the initial forensic job.
Deliverables
• Forensic report showing originating IP and evidence the message was sent from the administrator’s machine, not the employee’s.
• Step-by-step notes of the methods and tools you used (e.g., header analysis, log review) so I can reproduce or defend the findings.
• After acceptance of the report, a brief plan outlining how you would take over email and website administration, including a security checklist for preventing similar incidents.
I’m ready to provide access to the raw email file, server logs, and any additional information you request.
Your first task is a small-scale forensic investigation. Please extract and interpret the full header, trace the sending IP address, and correlate it with server or workstation logs so I can demonstrate that the message did not leave the employee’s PC. Accuracy and chain-of-custody notes are important because this material may be presented internally (and potentially to legal counsel).
Once that is complete, I’d like to transition ongoing email and website management to someone trustworthy. Our stack is fairly typical—domain and DNS on GoDaddy, email on Microsoft 365, and a cPanel-based website—so routine administration, security hardening, and user support will follow the initial forensic job.
Deliverables
• Forensic report showing originating IP and evidence the message was sent from the administrator’s machine, not the employee’s.
• Step-by-step notes of the methods and tools you used (e.g., header analysis, log review) so I can reproduce or defend the findings.
• After acceptance of the report, a brief plan outlining how you would take over email and website administration, including a security checklist for preventing similar incidents.
I’m ready to provide access to the raw email file, server logs, and any additional information you request.
Related categories:
Linux
Web Security
DNS
Internet Security
Data Analysis
Technical Documentation
cPanel
Microsoft 365