Email evidence triage checklist¶
title: Email evidence triage checklist subtitle: Work out what you have, what may still be at risk and which evidence needs preserving before the enquiry expands. slug: email-evidence-triage-checklist series: email-evidence section: practical-tools card_type: checklist pathway_order: 42 section_order: 1 status: draft public_safe: true video_ready: true word_count: 427 estimated_read_time_seconds: 177 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - email evidence - triage - checklist - first actions - supervision sources: - title: 'NCSC: How to spot and report phishing scams' url: https://www.ncsc.gov.uk/collection/phishing-scams - title: 'NCSC: Phishing attacks — defending your organisation' url: https://www.ncsc.gov.uk/guidance/phishing - title: 'Microsoft Learn: Email entity page in Defender for Office 365' url: https://learn.microsoft.com/en-us/defender-office-365/mdo-email-entity-page - title: 'Microsoft Learn: Message trace in the Microsoft Defender portal' url: https://learn.microsoft.com/en-ca/defender-office-365/message-trace-defender-portal - title: 'Google Workspace Admin Help: Troubleshoot message delivery with Email Log Search' url: https://support.google.com/a/answer/7513679?hl=en-GB
Email evidence triage checklist¶
Work out what you have, what may still be at risk and which evidence needs preserving before the enquiry expands.
Script¶
You’ve been given an email and need to decide what happens next.
This first assessment shouldn’t become a full technical examination.
The purpose of triage is to protect the evidence, identify any immediate harm and work out which question the email may help answer.
Start with the source.
Do you have the original message in the recipient’s mailbox, a native message file, a forwarded copy, a screenshot, a PDF or somebody’s written summary?
Record which one you have.
A screenshot may be enough to recognise a threat or fraud allegation. It isn’t the same as the original email.
Next, ask whether the original still exists.
Which account received it?
Which folder is it in?
Has it been deleted, moved, forwarded or reported through a security tool?
Can another recipient or organisational archive provide a better copy?
Then deal with immediate risk.
Has anybody clicked a link, opened an attachment, entered credentials, approved a payment or replied?
Is the account, device or organisation still exposed?
Does money need stopping, an account need securing, or a security team need alerting?
Protective action and preservation may need to happen together.
Now identify the question.
Are you trying to show what the email said?
Whether it was delivered?
Which service sent it?
Which account triggered it?
Whether the account was compromised?
Whether a device or person can be linked to it?
The answer determines which records matter.
Preserve the complete original where possible.
Keep the header, body, attachments, embedded content and mailbox context.
Record the acquisition method, date, time, account and folder.
Ask the recipient not to reply, click, open, forward or delete anything else.
Then identify the systems behind the message.
Which provider received it?
Which system appears to have sent it?
Was a mailing platform, customer-management system, security gateway or forwarding service involved?
Are message-trace, audit, sign-in or campaign records likely to exist?
Act early where provider records may expire.
Finally, record the main limitation.
Perhaps you only have a screenshot.
Perhaps the source port is missing.
Perhaps the header shows a mail server rather than a user address.
Perhaps several people used the mailbox.
That limitation should shape the next action rather than being hidden.
A good triage outcome is a short, clear position:
what has been preserved;
what immediate harm has been addressed;
what question remains;
which records are at risk;
and who needs to take the next action.
You don’t need to solve the whole email at triage.
You need to stop it getting worse and make sure the next person starts with the right evidence.
Key takeaway
Triage is about protecting the evidence and identifying the next decision. It isn’t a full technical examination.
Triage checklist¶
- [ ] Identify what you have: original mailbox message, native file, forward, screenshot, PDF or summary.
- [ ] Confirm whether the original still exists and where it is stored.
- [ ] Record the recipient account, folder, device, application, date and time.
- [ ] Ask what the recipient has already clicked, opened, entered, approved, downloaded, replied to or forwarded.
- [ ] Address any immediate risk to money, credentials, accounts, devices or other recipients.
- [ ] Tell the recipient to stop further interaction and leave the original in place.
- [ ] Acquire the complete original message and attachments where possible.
- [ ] Define the exact question: content, delivery, account, session, device, person or location.
- [ ] Identify the recipient provider, sending provider and any third-party platform.
- [ ] Protect short-lived message-trace, audit, sign-in, security and campaign records.
- [ ] Record the main evidential limitation and the next responsible person or team.
Related questions¶
- I’ve been given an email that may be relevant. What can I do with it?
- How do I preserve an email properly?
- What should I ask the recipient not to do?
- Who may hold relevant email records?
Source notes¶
- NCSC: How to spot and report phishing scams
- NCSC: Phishing attacks — defending your organisation
- Microsoft Learn: Email entity page in Defender for Office 365
- Microsoft Learn: Message trace in the Microsoft Defender portal
- Google Workspace Admin Help: Troubleshoot message delivery with Email Log Search