Summary
In this chapter, we covered the email message flow and the hops that the email traverses until it’s delivered to the recipient. We also learned about email authentication records and protocols, how they work, and how to investigate the authentication results using the email header. Finally, we learned how to analyze the email message header before investigating the email header of a spoofed email message.
In the next chapter, we will enter a new section of this book and introduce various Windows event log types.