Skip to content
EML-036 Email Evidence

What should I ask the recipient not to do?


title: What should I ask the recipient not to do? subtitle: Protect the recipient and the evidence without turning a simple email enquiry into uncontrolled technical activity. slug: what-should-i-ask-the-recipient-not-to-do series: email-evidence section: first-actions card_type: question_card pathway_order: 4 section_order: 3 status: draft public_safe: true video_ready: true word_count: 578 estimated_read_time_seconds: 239 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - email evidence - recipient advice - phishing - preservation - first response sources: - title: 'Gmail Help: Download and send emails as attachments' url: https://support.google.com/mail/answer/9261412?hl=en-GB - title: 'Microsoft Support: Save an Outlook message as an EML file, PDF file, or draft' url: https://support.microsoft.com/en-us/outlook/mail/save-an-outlook-message-as-a-eml-file-a-pdf-file-or-as-a-draft - title: 'Microsoft Learn: Respond to a compromised email account in Microsoft 365' url: https://learn.microsoft.com/en-us/defender-office-365/responding-to-a-compromised-email-account


What should I ask the recipient not to do?

Protect the recipient and the evidence without turning a simple email enquiry into uncontrolled technical activity.

Script

When somebody reports a relevant or suspicious email, the first advice should be simple.

Ask them not to interact with it any further.

That normally means:

don’t reply;

don’t click links;

don’t open or run attachments;

don’t forward it around;

don’t delete it;

and don’t edit, rename or resave anything inside it.

Ask them to leave the original message in the mailbox and tell you what they have already done.

That last part matters.

They may already have replied, opened an attachment, entered credentials, approved a payment, called a telephone number, downloaded a file or forwarded the message to somebody else.

You need an honest timeline, not an embarrassed answer shaped by what they think they should have done.

Reassure them that the priority is understanding the event and limiting harm.

Don’t ask them to repeat an action so you can watch what happens. Don’t ask them to click a link again, reopen a file or send another reply to confirm that the address works.

If you need the message, arrange a safe method to preserve the original. A screenshot can help you identify it, but don’t make “send me a screenshot” the whole evidence plan.

If the email may involve active harm, the protective response may need to happen immediately.

Examples include compromised credentials, ongoing payment fraud, a live threat, malware execution, account takeover or the unauthorised disclosure of sensitive information.

In those situations, containment may be more urgent than perfect preservation.

The account may need to be secured, sessions revoked, payments stopped, systems isolated or security teams alerted. Record when those actions happened and preserve the available evidence as part of the response.

Don’t let a fear of changing the evidence prevent necessary protection.

Equally, don’t encourage the recipient to improvise.

Changing passwords, deleting messages, installing software, factory-resetting a device or running online “header checker” tools may alter the situation or expose information to third parties.

Use the organisation’s incident, security, evidence or support process.

Ask the recipient to preserve the wider context as well.

They shouldn’t delete related messages, clear the conversation, remove sent replies or tidy the mailbox before it has been assessed.

If the communication continued through text messages, messaging apps or telephone calls, ask them not to remove those records either.

Where the email contains links or images, ask whether they appeared automatically or only after the recipient interacted with the message. Some mail clients load remote content, while others block it. Don’t ask the recipient to change settings and reopen the email just to test this.

Also ask which device and application they used.

The message may have been viewed in a browser, desktop client, mobile application or security gateway. That helps identify where additional records may exist.

A useful first response sounds like this:

“Please leave the original email where it is. Don’t reply, forward it, click anything, open attachments or delete it. Tell me which account and device received it, and let me know anything you have already done. We’ll arrange to preserve the original safely.”

That gives the recipient something practical to do without overwhelming them.

The common mistake is to give a long technical lecture while the person is still interacting with the message.

The other is to blame them for clicking or replying. That makes incomplete disclosure more likely and weakens the investigation.

Stop further interaction. Preserve the original. Record what has already happened. Then decide whether the priority is evidence recovery, immediate protection or both.

Key takeaway

Ask the recipient to stop interacting with the message, leave the original in place and report any action they have already taken.

Source notes


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.