Skip to content
EML-014 Email Evidence
Pathway: I have been given a suspicious email

I’ve been given an email that may be relevant to an investigation. What can I do with it?

Preserve the original, decide what question the email can help answer, and keep the message, account and person separate.

Script

You’ve been given an email that may matter to an investigation.

It might be a threat, a fraud message, an instruction to transfer money, a conversation with a victim, a notification from an online service, or something said to link a person to an account or event.

The email may be useful. But before you start pulling IP addresses out of the header or deciding that the From address identifies the sender, take a step back.

An email isn’t one piece of evidence. It is a package.

It contains the message the recipient saw. It may contain attachments, links, images and hidden formatting. It also contains technical information about how the message was created, addressed, authenticated and delivered. The mailbox and provider may hold another layer of information about when it arrived, who accessed it, what happened to it and whether related messages exist.

Those layers answer different questions.

The visible content may help you understand what was communicated.

The header may help you understand how the message travelled and which systems handled it.

Provider records may help link the message to an account, session or sending service.

Device evidence may help show where it was composed or accessed.

None of those automatically identifies the person who typed the words.

The first job is preservation.

Keep the original message in its original mailbox where possible. Obtain a native copy that retains the full message source, rather than relying only on a screenshot, printout or forwarded version. Preserve the complete header, message body, attachments, embedded content and the context in which the recipient received it.

If the email may be malicious, tell the recipient not to reply, click links, open attachments, delete it or forward it around. A screenshot can be useful for an urgent first look, but it isn’t a substitute for the original.

Then ask what you are actually trying to establish.

Are you trying to show that a message was received?

That a particular account sent it?

That a particular device was used?

That the named account holder wrote it?

That an attachment was delivered?

That the recipient clicked a link?

That the message formed part of a wider conversation?

Those are separate questions. The same email may help with several of them, but the strength of the answer will differ.

Next, consider whether the individual message is enough.

If this is a simple complaint about what was written, preserving the original message and its attachments may be proportionate.

If account compromise, fraud, repeated contact, deleted messages, mailbox rules or a longer conversation may matter, preserving the mailbox context and relevant provider records becomes more important. The individual email won’t show every login, deletion, forwarding rule, draft or related message.

Act early where records may be short-lived. Organisational email systems may have message-trace, audit and sign-in information that isn’t contained inside the email itself. Identify the service provider or system owner and ask what can be preserved before retention periods or routine processing remove it.

Be careful with attribution.

The From address is the identity presented to the recipient. It may be genuine, spoofed, used by an automated system, sent through a marketing platform, controlled by several people or accessed by somebody who compromised the account.

SPF, DKIM and DMARC can help assess domain-level authentication. They don’t prove which person composed the message.

An IP address in a Received line may identify a mail server rather than the sender’s phone or computer. A Message-ID may help match the email across provider systems, but it doesn’t prove authorship either.

So the route through an email enquiry is usually:

Preserve the complete original.

Protect against immediate harm.

Identify the precise question.

Separate message content from delivery, account and person attribution.

Preserve the mailbox or provider records where the wider context matters.

Interpret each header field only for the narrow fact it can support.

Then corroborate the conclusion with account, device, communications, financial, witness or other case-specific evidence.

A supervisor doesn’t need to become an email engineer before making a sensible decision.

They do need to ask whether the original has been preserved, whether the team is relying on a copy, what conclusion is actually being drawn, what alternative explanations remain and which records may disappear if nobody acts.

The email is neither proof of the named sender nor useless technical clutter.

Treat it as a structured line of enquiry.

Preserve it properly. Decide what you need it to prove. Then follow the evidence to the system, account, device or person that can answer the next question.

Key takeaway

An email is a useful package of content, routing and account clues. Preserve it first, then be precise about which part of the story each clue supports.

Choose your next question

  • How do I preserve an email properly? (outside pilot sample)
  • Is a screenshot or forwarded copy enough? (outside pilot sample)
  • What should I ask the recipient not to do? (outside pilot sample)
  • Should I preserve the mailbox as well as the individual message? (outside pilot sample)
  • Does the From address identify the sender? (outside pilot sample)
  • Can an email identify the person who wrote it? (outside pilot sample)

Source notes

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.