Skip to content
EML-024 Email Evidence

What corroboration should I look for?


title: What corroboration should I look for? subtitle: 'Choose corroboration that tests the particular link you are trying to make: message, account, session, device, location or person.' slug: what-corroboration-should-i-look-for series: email-evidence section: evidential-limits-and-corroboration card_type: question_card pathway_order: 41 section_order: 7 status: draft public_safe: true video_ready: true word_count: 687 estimated_read_time_seconds: 284 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - email evidence - corroboration - attribution - alternative explanations - decision making sources: - title: 'Microsoft Learn: Trace an email message in Exchange Online' url: https://learn.microsoft.com/en-us/exchange/monitoring/trace-an-email-message/trace-an-email-message - title: 'Microsoft Learn: Search the audit log for mailbox activities' url: https://learn.microsoft.com/en-us/purview/audit-log-search-for-mailbox-activities - title: 'Microsoft Learn: Sign-in log activity details' url: https://learn.microsoft.com/en-us/entra/identity/monitoring-health/concept-sign-in-log-activity-details - title: 'Google Workspace Admin Help: Troubleshoot message delivery with Email Log Search' url: https://support.google.com/a/answer/7513679?hl=en-GB


What corroboration should I look for?

Choose corroboration that tests the particular link you are trying to make: message, account, session, device, location or person.

Script

Corroboration means finding other evidence that supports or challenges the link you are trying to make.

The right corroboration depends on the proposition.

If you haven’t defined the proposition, collecting more records can produce a large pile of information without answering the real question.

Start by separating the possible conclusions.

Did this message exist?

Was it delivered to the recipient?

Did a particular provider or platform send it?

Did a particular account cause it to be sent?

Did a particular session or application control the account?

Was a particular device involved?

Did a particular person write, approve or trigger it?

Was that person in a particular location?

Those are different links.

For the existence and content of the message, look for:

the native original in the recipient’s mailbox;

another recipient’s copy;

the sender’s Sent item or draft;

a provider message trace;

an organisational archive or journal;

a valid DKIM or end-to-end signature;

and matching Message-ID or provider identifiers.

For delivery, look for:

the recipient provider’s email log or message trace;

mailbox receipt;

gateway records;

quarantine or filtering events;

and replies or actions that refer to receiving the message.

For the sending account, look for:

provider trace linked to the mailbox or tenant;

Sent Items and drafts;

mailbox audit;

campaign, workflow or API records;

account identifiers;

and evidence that the platform or organisation recognises the event.

For the session or device, look for:

sign-in logs;

session and token identifiers;

registered-device IDs;

browser or application information;

endpoint records;

local drafts or cached messages;

notifications;

attachments or source files;

and organisational asset or mobile-device-management records.

For the person, look for independent evidence of control and involvement.

That may include:

exclusive or normal access to the account and device;

knowledge reflected in the content;

the wider conversation;

witness evidence;

admissions;

instructions given to another person;

related payments or transactions;

matching communications on another channel;

and activity before or after the email.

Be alert to alternative explanations.

If the account holder denies sending the message, test compromise, shared access, delegation, automation and device sharing.

If an IP address appears to place the sender somewhere, test VPN, mobile routing, roaming, proxy use and whether the address belonged to a mail server instead.

If the message appears genuine because authentication passed, test whether a real account, platform or API credential was abused.

Good corroboration is independent.

Three reports generated from the same underlying provider log may look like three sources but repeat one observation.

A screenshot, exported PDF and witness statement all created from the same displayed email may not independently establish the delivery route.

Look for records created by different systems for different operational reasons.

For example:

the recipient provider records delivery;

the sending platform records the customer account;

the identity service records the session;

the device holds the draft;

and a financial record shows the transaction described in the message.

Those links reinforce one another because they don’t all depend on the same single source.

Also look for evidence that challenges the theory.

Was the account accessed from another device?

Was an inbox rule created?

Was the message automated?

Did another person have delegate access?

Does the content conflict with the supposed author’s knowledge or actions?

Corroboration is not just confirmation.

It is a way of testing whether the conclusion survives realistic alternatives.

The common mistake is to say:

“We have the email, the header and the IP address, so the evidence is corroborated.”

Those may all be parts of the same message.

The stronger approach is to identify the weakest step and find evidence outside the email that tests it.

A careful report explains the chain.

“The recipient provider confirms delivery. The sending provider links the message to this account. The account audit links the event to this session. The session is associated with this device. Other communications and records support this person’s involvement.”

Then state any unresolved gap.

No single checklist fits every case.

The practical rule is:

Decide what you are trying to prove.

Break it into links.

Find independent evidence for the weakest links.

And actively test the explanations that could make the same email point somewhere else.

Key takeaway

More evidence isn’t automatically better. Look for independent records that support or challenge the weakest link in the attribution chain.

Source notes


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.