A payment instruction arrives from a director’s apparent email address. It uses the right signature, refers to a live transaction and asks the finance team to act quickly. The payment is made. Days later, the director denies sending it. This spoofed email litigation example illustrates why an apparently straightforward message can become a contested issue of attribution, loss and evidential reliability.
For solicitors and organisations, the central question is rarely whether the email looked convincing. The question is what the available digital evidence can prove: who controlled the sending infrastructure, whether the message originated from the claimed account, whether any mailbox was compromised, and whether the evidence has been preserved in a manner that can withstand challenge.
The spoofed email litigation example
Consider a hypothetical UK commercial dispute. A construction company is negotiating a substantial equipment purchase. Its accounts department receives an email appearing to come from the supplier’s finance director, requesting that payment be redirected to a new bank account. The email address displayed in the sender field is correct. The wording matches previous correspondence, and the message is sent shortly after genuine discussions about invoicing.
The company pays £180,000. The supplier then says it never changed its bank details and brings a claim for the outstanding invoice. The purchaser alleges that the supplier’s email account was insecure, while the supplier contends that the purchaser failed to follow its own verification procedures. A separate issue arises when an employee has forwarded the disputed email, potentially altering the available message data.
At this stage, assumptions are dangerous. A visible sender address is not proof of origin. An email can be forged at the display level, sent through a compromised genuine mailbox, relayed through an unauthorised server, or created from a deceptively similar domain. Each scenario has different implications for liability, disclosure and the weight a court may give the evidence.
What the forensic examination should establish
A proper examination begins with preservation, not interpretation. The original message should be collected in its native form wherever possible, rather than relying on screenshots, printed copies or a forwarded version. The original may contain routing information, authentication results, message identifiers, timestamps and encoded content that are unavailable or unreliable in a visual copy.
The examiner would review the full email headers. These can reveal the route taken between mail servers, the server that introduced the message into the delivery chain, and whether authentication checks such as SPF, DKIM and DMARC passed, failed or were absent. Authentication is not a verdict by itself. A passing result may show that a message was authorised by a particular domain’s infrastructure, but it does not necessarily identify the individual who drafted it. A failing result may support spoofing, yet configuration errors and forwarding arrangements can also produce failures.
The investigation should also examine message IDs, return-path fields, reply-to addresses, domain registration details, IP address evidence where available, and the relationship between the disputed message and genuine messages in the correspondence chain. If the email was sent from a compromised account, mailbox audit logs, sign-in records, forwarding rules, deleted items and sent items may be more revealing than the headers alone.
In the example, the headers show that the email did not originate from the supplier’s usual Microsoft 365 tenancy. It was injected through an unrelated overseas server. The display name and visible address had been forged, while the reply-to field directed responses to a lookalike domain. A forensic comparison also identifies subtle differences in the HTML structure and writing pattern when set against known genuine communications.
That evidence may substantially weaken any assertion that the supplier’s finance director personally sent the instruction. It does not, however, automatically determine whether the purchaser was entitled to rely on it. The surrounding facts still matter: prior warnings, internal controls, telephone verification procedures, contractual terms, the timing of the request and the actions taken by both parties after discovery.
Why email evidence often fails under scrutiny
Disputed emails are frequently presented too late and in the wrong form. A party may provide a PDF printout, a screenshot from a mobile phone or text copied into a witness statement. These materials can assist with context, but they are not a substitute for forensic preservation of the source evidence.
Screenshots do not ordinarily disclose the full header chain, account metadata or whether a conversation has been selectively presented. They may omit the address actually used for replies, conceal a malicious attachment, or reflect a message that has been rendered differently by a particular device. A witness can honestly say they saw an email, but that does not establish the technical origin of the email.
There is also a distinction between spoofing and account compromise. In a spoofing event, a criminal may impersonate an address without access to the genuine mailbox. In an account compromise, the attacker may use a legitimate account and have access to historic threads, contacts and documents. The latter can produce a far more credible fraud and may require examination of cloud audit data, endpoints and mobile devices. Treating both events as simple ‘fake emails’ risks missing the evidence needed to identify the mechanism and scope of the incident.
Preservation and chain of custody matter
Once a disputed email is identified, routine IT activity can destroy or overwrite material. Retention rules may purge logs. Users may delete messages, change passwords or remove suspicious forwarding rules. Well-meaning staff may circulate copies widely, creating confusion about which version is original.
A defensible approach records what was collected, from where, by whom, when and using what method. Original files should be retained alongside forensic working copies, with integrity checks used to demonstrate that the material has not changed. Relevant cloud data should be preserved promptly, subject to the organisation’s legal obligations and the practical limits of the provider’s available retention and audit records.
The scope must be proportionate. It may be unnecessary to image every device in a large business where the issue is confined to a single spoofed message. Conversely, a narrow collection may be inadequate if there is evidence of sustained compromise, internal involvement or deleted communications. The appropriate scope depends on the pleaded issues, the value and seriousness of the claim, the likely sources of evidence and the need to control cost.
For legal teams, early expert input can help frame preservation requests, identify material suitable for disclosure and distinguish technically meaningful evidence from material that merely appears persuasive. It can also prevent a party from making an allegation of hacking or fabrication without a sound evidential basis.
Turning technical findings into usable litigation evidence
A court does not need a lesson in every email protocol. It needs a clear, transparent explanation of what the evidence shows, what it cannot show and how the examiner reached each opinion. The report should identify the source materials reviewed, collection methods, tools and validation steps, relevant findings and limitations.
In the hypothetical dispute, a useful expert opinion would not simply state that the email was spoofed. It would explain the significance of the server path, the failed alignment between the claimed sender and the sending system, the lookalike reply domain, and the absence of corresponding activity in the supplier’s account records. It would separate factual findings from opinion and avoid straying into legal conclusions on negligence or contractual liability.
That discipline is particularly important where parties advance competing narratives. One side may argue that the email proves authority to redirect payment. The other may argue that it is obvious fraud. The forensic evidence may support neither extreme. It may show an impersonation with high confidence while leaving open questions about whether the recipient’s controls were reasonable. Clear boundaries make expert evidence more credible, not less.
Computer Forensics Lab can assist by preserving relevant material, examining email and cloud evidence, and producing an independent report designed for scrutiny in civil, criminal and internal-investigation contexts. Where the facts demand it, findings can also be explained in conference or through expert witness evidence.
A disputed email should be treated as a potential evidence source from the moment it is discovered, not as an image to be attached to a claim form. Preserving the original, securing the relevant accounts and obtaining an impartial forensic assessment early can turn an allegation of spoofing into evidence that meaningfully assists the court.
