Skip to content
EML-033 Email Evidence

What records may link an email account to a device or recovery account?


title: What records may link an email account to a device or recovery account? subtitle: Registered devices, session identifiers, recovery details and authentication methods may connect the account to a wider identity. slug: what-records-may-link-an-email-account-to-a-device-or-recovery-account series: email-evidence section: provider-and-account-records card_type: question_card pathway_order: 33 section_order: 5 status: draft public_safe: true video_ready: true word_count: 687 estimated_read_time_seconds: 284 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - email evidence - device attribution - recovery account - authentication methods - identity sources: - title: 'Microsoft Learn: Track identity activities with linkable identifiers' url: https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-track-linkable-identifiers - title: 'Microsoft Learn: Manage device identities in Microsoft Entra ID' url: https://learn.microsoft.com/en-us/entra/identity/devices/manage-device-identities - title: 'Microsoft Learn: Authentication Methods Activity' url: https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-methods-activity - title: 'Google Account Help: See devices with account access' url: https://support.google.com/accounts/answer/3067630?hl=en-GB - title: 'Google Account Help: Set up recovery options' url: https://support.google.com/accounts/answer/183723?hl=en-GB - title: 'Google Account Help: Tips to complete account recovery steps' url: https://support.google.com/accounts/answer/7299973?hl=en-GB


What records may link an email account to a device or recovery account?

Registered devices, session identifiers, recovery details and authentication methods may connect the account to a wider identity.

Script

An email account may be linked to other identifiers that help explain who controlled it.

These can include registered devices, recent devices, authentication methods, recovery email addresses, recovery phone numbers, alternate addresses, connected applications and session identifiers.

Those records can be valuable.

They still need to be interpreted carefully.

Start with devices.

A provider may record devices that recently accessed the account.

An organisational identity system may hold a device ID, registration date, ownership, management status, compliance status and audit history showing when the device was added, changed or removed.

Sign-in logs may include the same device ID, allowing an investigator to connect an authentication event to a registered device.

That is stronger than a generic browser label.

But a registered device isn’t automatically a physical identification.

The device may be shared.

The displayed name may be user-created.

The registration may be old.

A virtual machine, rebuilt device or copied profile may complicate the record.

And an intruder may access an already trusted session on the device.

Use provider device records alongside physical examination, organisational asset records, mobile-device management and evidence of who had access.

Authentication methods provide another link.

The account may have a registered phone, authenticator application, security key, passkey or other multi-factor method.

Records may show when a method was registered, changed, used or disabled.

That can help establish whether a security change happened before a disputed email or during a suspected compromise.

A phone number used for verification may connect the account to a subscriber or handset enquiry.

But don’t assume the account holder was the only person able to receive the code.

Numbers are reassigned, devices are shared, messages can be diverted and authentication prompts can be approved by mistake.

Recovery email addresses and phone numbers can be especially useful when an account was created under a false or unfamiliar name.

A recovery address may connect it to another established account.

A recovery number may connect it to a communications provider.

Security notifications may also have been sent to those destinations.

But recovery data is not permanent proof of ownership.

It may be outdated.

It may belong to a family member, employee or administrator.

An attacker may add or change it after taking over the account.

Some providers retain or temporarily recognise previous recovery information after a change, while others may record the change in security or audit history.

Preserve the current details and the timeline of changes where available.

Connected applications and tokens may link the email account to another service or device.

A mail client, CRM, automation tool or mobile application may have been authorised to access the account.

The authorising user, application ID, token, device and session may help explain how the message was sent.

Linkable identifiers are particularly useful in organisational systems.

A user ID, session ID, device ID and token identifier may appear across sign-in, Exchange and other workload logs.

That allows activity to be followed from authentication into mailbox use and message sending.

Preserve the exact identifiers rather than relying on screenshots of friendly device names.

The common mistake is:

“The recovery phone belongs to this person, so the person created and used the account.”

That may be one supporting link.

It doesn’t explain when the number was added, who controlled it at the relevant time or whether the account was later shared or compromised.

Another mistake is:

“The account lists this device, so every email from the account came from that device.”

The account may have several sessions, applications and devices.

A careful attribution builds several links:

the account was associated with this recovery address or phone;

this authentication method was registered or used at this time;

this session was linked to this device ID;

this device was physically or organisationally linked to this person;

and the message activity occurred within that session or account context.

The more independent those links are, the stronger the conclusion.

Recovery and device records help connect an email identity to the wider world.

They are evidence of association and access.

They aren’t a shortcut past the need to establish who actually controlled the account when the message was sent.

Key takeaway

A device or recovery detail can strengthen account attribution, but it may be shared, outdated, compromised or added by somebody else.

Source notes


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.