filesaudit.com

9/24/2026

How to Verify an Email Attachment Hasn't Been Tampered With

Receiving an email attachment that should be a signed contract, an invoice, a photo from a witness, or a software build can feel routine until the stakes rise. A single altered number in a PDF, a cropped frame in a video, a replaced page in a document, or a renamed archive can change meaning, create liability, or enable fraud. Email itself does not guarantee that the bytes you open are the bytes the sender attached. Mail servers, intermediate gateways, anti-virus scanners, and even local mail clients can modify line endings, re-encode attachments, or strip metadata. More deliberately, an attacker can intercept, replace, or append content in transit, or a sender may have shared a file they did not create. That is why checking for tampering is not about gut feeling. It is about comparing technical evidence that travels with the file against what you expect. The two most reliable technical signals are cryptographic hashes, which fingerprint the exact sequence of bytes, and file metadata, which records creation tools, timestamps, authorship fields, and sometimes embedded location or editing history. Neither signal proves who sent the email or proves legal authenticity on its own, but together they document whether the file you have now is byte-for-byte identical to a known original and whether its internal records are consistent with its claimed origin. For journalists, auditors, lawyers, and engineers this distinction matters. You need a repeatable, documented way to say the file is unchanged since a certain point, or that it shows signs of modification, without making unsupported legal conclusions. Email headers can help with routing and timing, but they do not protect the attachment payload. The attachment itself must be examined.

Tampering in a forensic sense means the content or structure of the file has changed after the point you consider authoritative. It does not automatically mean malicious intent.

That is the first thing to keep clear. A file can be legitimately re-saved, converted, or compressed by a mail system and still be functionally the same, yet its hash will change. A file can also be opened and re-exported by the sender and retain the same visible content while the internal metadata updates. Because of that, you need both a byte-level comparison and a metadata review, and you need to document the context in which you received the file. Checking for tampering therefore starts with establishing a baseline. If you have a known good copy from the sender through a trusted channel, from version control, or from a prior delivery, you can compare hashes directly. If you do not, you can still build a technical profile of the attachment you received and look for internal inconsistencies that suggest editing, re-export, or manipulation.

Metadata is often where edits leave traces. Images carry EXIF, XMP, IPTC and sometimes GPS fields that record camera make and model, lens, shutter speed, original creation date, software used to edit, and geolocation if it was not stripped. A photo that claims to be taken yesterday on an iPhone 15 Pro but shows software tags from Adobe Photoshop, a different creation date in the EXIF DateTimeOriginal versus the file system modified time, or a mismatch between the claimed location and the GPS coordinates embedded in the frame is a red flag that warrants further inquiry. Video files contain container metadata and stream metadata, including encoder settings, creation time, device model, and sometimes location data. Audio files can carry ID3 tags, encoder history, and timestamps. Documents such as PDF and DOCX store author name, creation and modification dates, producer application, revision history, and embedded fonts. Archives like ZIP, RAR and 7Z contain internal timestamps for each entry and compression method. CAD files carry author, revision, and software version information. FilesAudit supports 200+ formats across images, video, audio, documents, archives, CAD and source code, so you can inspect a wide range of attachments without installing format-specific tools, and you can see the full list of supported file types on the full list of supported formats page. When you upload a file to FilesAudit, it extracts technical metadata, computes SHA-256, MD5 and CRC32 hashes, and generates a timestamped report that you can archive for later reference. That report documents what the file looked like at the time of analysis, which is useful when you need to show a reviewer exactly what was examined.

Hashes are the clearest test for byte-level identity. SHA-256 is the current standard for integrity verification because even a one-bit change produces a completely different digest. MD5 and CRC32 are still useful for quick comparison and legacy systems, though MD5 is not collision resistant for security purposes. If

FAQ

How can I tell if an email attachment was changed after it was sent?

Compare the file’s current cryptographic hash like SHA-256 or MD5 to a hash recorded when it was originally received. If the hashes match, the file content is identical; if they differ, the file was modified.

Can FilesAudit detect if someone tampered with an email attachment?

FilesAudit can extract technical metadata and compute SHA-256, MD5 and CRC32 fingerprints with timestamped documentation. It documents whether the current file matches a previously recorded version, but it does not determine legal ownership or authenticity by itself.

What metadata should I check on an email attachment for signs of tampering?

Check creation and modification timestamps and format-specific metadata such as EXIF, GPS, XMP, IPTC for images and metadata for PDFs, videos and audio. A change in those fields or a mismatched hash is a technical indicator the file was altered.

Does FilesAudit prove who sent an email attachment or that it’s authentic?

No. FilesAudit documents technical evidence such as hashes, metadata and a timestamped forensic PDF report. It does not determine legal ownership or authenticity by itself.

Ready to see what's hidden in your own files? Upload a file to FilesAudit and get a free forensic metadata report in seconds — no registration required.