Skip to content
Skip to main content
Email Evidence Technical Explainer

Can an email identify the person who wrote it?

An email can help build a case about authorship, but there is rarely one field that names the person who actually composed the words.

The useful approach is to separate several questions: what message was sent, which account or service submitted it, which session or device was involved, and what evidence connects that activity to a person?

The short version
Sending and writing are not the same proposition. Provider records may identify the account, application or session that submitted a message; authorship normally needs additional evidence about who controlled that route and who composed or approved the content.

Start with the message, then build outward

Suppose a disputed email appears in a genuine company mailbox and in Sent Items.

That is useful. It may establish that the organisation's real account submitted the message.

It does not yet establish who typed it.

Message
Sending account or service
Session / application
Device
Person

Each link can be supported by a different source.

What can connect the message to an account or session?

Useful material may include:

  • native message and complete header;
  • provider message trace;
  • mailbox audit;
  • session or token identifiers;
  • application or delegate records;
  • Sent Items and Drafts;
  • message IDs and provider network IDs; and
  • timestamps that can be joined across those records.

A shared mailbox, delegated user, connected application or automated workflow can all submit a genuine message without the named account holder personally composing it.

What account-access records may exist? explains the account and session side in more detail.

What can connect the activity to a device or person?

The next layer may come from:

  • browser or mail-client artefacts;
  • local drafts or temporary files;
  • device possession and access records;
  • surrounding messages or notes;
  • document metadata;
  • contemporaneous communications;
  • admissions or witness evidence; and
  • content showing knowledge that can independently be attributed.

Writing style can add context, but it is rarely enough on its own. Templates, copied text, collaborative drafting and generated text can all weaken a simple “this sounds like them” conclusion.

The email evidence may support

That a particular message was submitted through a particular account, service, session, application or device at a recorded time.

It may still leave open

Who physically or remotely controlled that route, and whether that person personally composed, approved or merely transmitted the words.

The From field is only the first layer

The visible sender identity is useful because it tells you what the recipient was shown. It is not a shortcut to authorship.

Does the From address identify the sender? explains why the displayed identity, the sending route and the person behind the message must be tested separately.

The practical point is: build authorship as a chain of corroborated links. Do not collapse “this account sent the email” into “this person wrote it”.

Sources

Reference: EML-001Email Evidence