Can an email identify the person who wrote it?¶
An email can help build a case about authorship, but there is rarely one field that names the person who actually composed the words.
The useful approach is to separate several questions: what message was sent, which account or service submitted it, which session or device was involved, and what evidence connects that activity to a person?
Start with the message, then build outward¶
Suppose a disputed email appears in a genuine company mailbox and in Sent Items.
That is useful. It may establish that the organisation's real account submitted the message.
It does not yet establish who typed it.
Each link can be supported by a different source.
What can connect the message to an account or session?¶
Useful material may include:
- native message and complete header;
- provider message trace;
- mailbox audit;
- session or token identifiers;
- application or delegate records;
- Sent Items and Drafts;
- message IDs and provider network IDs; and
- timestamps that can be joined across those records.
A shared mailbox, delegated user, connected application or automated workflow can all submit a genuine message without the named account holder personally composing it.
What account-access records may exist? explains the account and session side in more detail.
What can connect the activity to a device or person?¶
The next layer may come from:
- browser or mail-client artefacts;
- local drafts or temporary files;
- device possession and access records;
- surrounding messages or notes;
- document metadata;
- contemporaneous communications;
- admissions or witness evidence; and
- content showing knowledge that can independently be attributed.
Writing style can add context, but it is rarely enough on its own. Templates, copied text, collaborative drafting and generated text can all weaken a simple “this sounds like them” conclusion.
That a particular message was submitted through a particular account, service, session, application or device at a recorded time.
Who physically or remotely controlled that route, and whether that person personally composed, approved or merely transmitted the words.
The From field is only the first layer¶
The visible sender identity is useful because it tells you what the recipient was shown. It is not a shortcut to authorship.
Does the From address identify the sender? explains why the displayed identity, the sending route and the person behind the message must be tested separately.
The practical point is: build authorship as a chain of corroborated links. Do not collapse “this account sent the email” into “this person wrote it”.