Message correlation
The Message-ID in a received copy identifies the relevant Postfix cleanup record and queue ID 20B261E01F8.
security lab / 03
completed 5 October 2026I configured an Ubuntu mail server for local delivery and sent a test email to five accounts. I followed its Message-ID through SMTP output, Postfix logs and Maildir copies to identify every recipient, including those missing from To and Cc.
01 / overview
Can one received email and local server logs establish all recipients, including those absent from To/Cc?
This foundational mail flow exercise uses a benign message and five local users. It isolates recipient tracing from phishing analysis so the delivery evidence can be understood on its own.
02 / what I found
The Message-ID in a received copy identifies the relevant Postfix cleanup record and queue ID 20B261E01F8.
The queue records show nrcpt=5 and a final status=sent, delivered to Maildir, for Alice, Bob, Carol, Edoardo and Vittorio.
To names Alice and Cc names Bob and Edoardo. Carol and Vittorio are envelope-only recipients in this intentionally configured lab.
03 / evidence & scope
The prepared message, native SMTP transcript, queue delivery log, Alice’s received copy and SHA-256 checksums. SMTP acceptance is checked against final local delivery.
This is a benign local mail flow test. Delivery does not establish whether someone read the message or interacted with it, and these records do not identify recipients of the archived phishing sample.
04 / reproduce the lab
Configure Postfix for local delivery to lab.test, create five local users, submit the message with Swaks and correlate the received Message-ID with the queue’s delivery records.