Skip to content
EML-043 Email Evidence
Pathway: I have been given a suspicious email

Email preservation checklist

Preserve the message as an email object, the mailbox context around it and the provider records that may disappear.

Script

Email preservation has three layers.

The message itself.

The mailbox context around it.

And the provider or identity records behind the account.

You may not need every layer in every enquiry.

But you should decide consciously rather than assuming that downloading one attachment or taking one screenshot preserved everything.

Start with the message.

Leave the original in the mailbox where possible.

Acquire a native copy that retains the full source, such as an EML, MSG or appropriate mailbox export.

Preserve the complete header, plain-text and HTML bodies, attachments, embedded content and MIME structure.

Record the filename, acquisition time, account, folder and method used.

Where local procedure requires it, calculate and record a hash and handle the preserved file as an exhibit.

Then preserve the mailbox context.

Keep relevant Inbox, Sent, Draft, Deleted, Junk and archive items.

Preserve the conversation around the message, including replies and related messages.

Record mailbox rules, forwarding settings, delegated access and any relevant changes.

If compromise, repeated contact or deletion is possible, a single message may be too narrow.

Then consider provider records.

Message trace may show delivery, rejection, redirection, quarantine or later security action.

Mailbox audit may show access, sending, deletion, movement, rules or delegate activity.

Sign-in and identity records may show sessions, devices, authentication methods, recovery changes and connected applications.

A platform may hold campaign, workflow, customer, API or transaction records.

Those datasets often have different retention periods.

Preserve them early where they may matter.

Also preserve what the recipient saw.

A screenshot can show the rendering on a particular device, warnings, display names, link text and folder context.

Keep it as supporting evidence, not as a replacement for the original.

Don’t repeatedly open a suspicious email with remote content enabled.

Your own examination may trigger tracking pixels, previews or security events.

Don’t click links or open attachments on an ordinary device simply to identify them.

Use working copies and the appropriate safe environment.

Record every transformation.

If you extract an attachment, decode a URL, convert a file, decompress an archive or render HTML, keep the output separate and state how it was produced.

Don’t overwrite the preserved source.

The common preservation failure is to keep the visible content and lose the route, identifiers and context.

The opposite failure is to collect an entire mailbox and years of unrelated material without identifying the investigative need.

Preserve enough to answer the question and test realistic alternatives.

A proper preservation record should allow another person to explain:

where the email was found;

what was acquired;

what remained in place;

which related records were protected;

which actions changed the account or device;

and how the working copies were produced.

The aim isn’t to freeze the whole world.

It is to stop the evidence you may need from disappearing or being confused with a later copy.

Key takeaway

Preservation has three layers: the message, the mailbox and the provider or identity records behind them.

Preservation checklist

  • [ ] Leave the original message in its mailbox where possible.
  • [ ] Record the account, folder, device, application, date and time.
  • [ ] Acquire a native EML, MSG or appropriate mailbox export.
  • [ ] Preserve the full header, MIME structure, plain-text and HTML bodies.
  • [ ] Preserve attachments, embedded content, filenames and underlying links.
  • [ ] Keep screenshots as evidence of rendering, not as substitutes for the original.
  • [ ] Preserve relevant Inbox, Sent, Draft, Deleted, Junk and archive items.
  • [ ] Preserve related conversation messages, mailbox rules, forwarding and delegate settings where relevant.
  • [ ] Protect message-trace, audit, sign-in, security, device and platform records.
  • [ ] Record any containment action that changed the account, mailbox or device.
  • [ ] Create working copies for analysis and keep the preserved source unchanged.
  • [ ] Record hashes and exhibit handling where required by local procedure.
  • [ ] Document every extraction, conversion, decoding or other transformation.
  • How do I preserve an email properly? (outside pilot sample)
  • Should I preserve the mailbox as well as the individual message? (outside pilot sample)
  • What should I ask an email provider to preserve? (outside pilot sample)
  • What information may disappear if the message is forwarded or exported incorrectly? (outside pilot sample)

Source notes

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.