Skip to content
EML-023 Email Evidence
Pathway: I have been given a suspicious email

What changes when a shared mailbox, Send As or Send on Behalf access is used?

The address shown to the recipient may represent a team mailbox while another authenticated user or application performed the sending action.

Script

An email appears to come from a shared address such as finance, complaints, reception or support.

Several people may have legitimate access to that mailbox.

The visible address therefore identifies the mailbox or team identity.

It doesn’t automatically identify the individual who created or sent the message.

Different permissions can produce different results.

Full Access normally allows a delegate to open and manage another mailbox.

It doesn’t necessarily allow them to send from it.

Send As allows a delegate to send a message that appears to come directly from the mailbox.

The recipient may see only the shared address.

Send on Behalf normally shows that one user sent the message on behalf of the mailbox or group.

That gives the recipient more visible information about the delegate.

The exact wording and records depend on the platform and configuration, but the investigative principle is the same.

You need to identify who or what used the shared identity.

Start by preserving the original message and the provider trace.

Then establish the mailbox type and permissions that existed at the relevant time.

Who had Full Access?

Who had Send As?

Who had Send on Behalf?

Were any applications, service accounts, automations or administrators able to access it?

Did the permissions change before or after the disputed message?

Now obtain mailbox audit records where available.

Modern organisational systems may record SendAs, SendOnBehalf, delegate access, message access, deletion and rule changes.

The search method matters.

Shared-mailbox activity may need to be searched against the mailbox identifier rather than only against a named user.

Audit availability and retention also depend on the system and configuration.

Check Sent Items carefully.

In some configurations, a message sent through a shared mailbox is stored in the delegate’s Sent Items rather than the shared mailbox’s Sent Items.

The organisation can configure copies to be saved in the shared mailbox as well.

So the absence of the message from the shared Sent Items doesn’t prove that the shared identity wasn’t used.

Search the delegate mailboxes, message trace and audit records.

Also separate sending from authorship.

A team member may write the draft and ask another person to send it.

A template or CRM may create the content.

An application may send using the shared mailbox.

A manager may approve the message without touching the account.

The provider audit may identify the sending action while leaving the person who wrote or authorised the words unresolved.

Shared mailboxes also create compromise risks.

An intruder may use one delegate account to access the shared mailbox.

A malicious inbox rule may affect messages seen by the whole team.

Credentials or tokens belonging to an authorised application may be abused.

Don’t assume that because several people had access, attribution is impossible.

Build the timeline.

Which delegate or application authenticated?

Which session accessed the mailbox?

Which action sent the message?

Where was the sent copy stored?

Which device or account was linked to that session?

Who had operational responsibility and knowledge of the content?

The common mistake is:

“The email came from finance@example.com, so the finance manager sent it.”

Another is:

“Ten people had access, so we can’t take the enquiry further.”

Audit, message trace, session, device and workflow records may substantially narrow the action.

A careful conclusion might say:

“The message was sent using Send As permission for the shared Finance mailbox. Provider audit links the sending action to this delegate account and session.”

Then explain what links that delegate account to the device and person.

A shared mailbox is a team identity.

The investigation needs to move from that identity to the permission and session that actually used it.

Key takeaway

Move past the shared address and identify the delegate, permission, session or application that used it.

  • Can an email identify the person who wrote it? (outside pilot sample)
  • What account-access records may exist? (outside pilot sample)
  • What if the sender’s account was compromised? (outside pilot sample)
  • What should a supervisor ask before relying on email evidence? (outside pilot sample)

Source notes

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.