all projects
completed 5 October 2026

Postfix Recipient Tracing

I configured an Ubuntu mail server for local delivery and sent a test email to five accounts. I followed its Message-ID through SMTP output, Postfix logs and Maildir copies to identify every recipient, including those missing from To and Cc.

investigation question

Can one received email and local server logs establish all recipients, including those absent from To/Cc?

This foundational mail flow exercise uses a benign message and five local users. It isolates recipient tracing from phishing analysis so the delivery evidence can be understood on its own.

01

Message correlation

The Message-ID in a received copy identifies the relevant Postfix cleanup record and queue ID 20B261E01F8.

02

Five deliveries

The queue records show nrcpt=5 and a final status=sent, delivered to Maildir, for Alice, Bob, Carol, Edoardo and Vittorio.

03

Header limits

To names Alice and Cc names Bob and Edoardo. Carol and Vittorio are envelope-only recipients in this intentionally configured lab.

evidence & scope

The prepared message, native SMTP transcript, queue delivery log, Alice’s received copy and SHA-256 checksums. SMTP acceptance is checked against final local delivery.

what this does not establish

This is a benign local mail flow test. Delivery does not establish whether someone read the message or interacted with it, and these records do not identify recipients of the archived phishing sample.

reproduce the lab

Configure Postfix for local delivery to lab.test, create five local users, submit the message with Swaks and correlate the received Message-ID with the queue’s delivery records.

Have a role
or idea
in mind?

Available for work

GET IN TOUCH

Available for work

Tell me what you have in mind.

Your name, email and message are used to reply to your enquiry. privacy

email me directly ↗

About your data.

This portfolio has no advertising or analytics scripts added by me. Your light or dark theme preference is stored in your browser. The contact form asks for your name, email, topic and message so I can reply. Messages are sent through Formspree; its privacy policy applies to the form submission. Contact links open GitHub, LinkedIn, Instagram or your email app. The hosting provider may process technical data needed to deliver the site. The linked reports are downloadable PDFs. The Projects page retrieves public GitHub profile, pinned repository and contribution data through this site’s server, with a short cache. No GitHub login is required.