Wireshark decode SMTP


I'm analyzing a SMTP transfer and not sure what Wireshark is reporting in the Info section of "D: DATA fragment, xx bytes". Has anyone seen this before?

One Answer:


The content of an email (headers + body) is sent after the SMTP DATA command. If that content is larger than one TCP segment, Wireshark will show every packet that belongs to the DATA "command" as "C: DATA fragment" in the Info column. So, those packets are basically the content of the email.

You can see the whole SMTP communication.

  • select any packet of the SMTP connection
  • right click the packet
  • select "Follow TCP Stream"


Thanks Kurt. It's the DATA Fragment in the info that i was concerned with.

It's just an info, that Wireshark detected one part (one fragment) of the mail message.

what concerns do you have?

