How do I establish whether messages really belong to the same email thread?¶
A conversation view is an email application's reconstruction of a thread, not proof that every displayed message belongs to one genuine exchange. Preserve the individual messages and compare their Message-ID relationships, participants, provider records, times and content. The more of those independent features agree, the stronger the thread relationship becomes.
Start with the apparent conversation¶
In the supplier-payment investigation, the payment-change email appears underneath genuine correspondence about invoice RC-10482. That familiarity matters because it helps explain why the finance officer trusted the message. It does not establish how the suspicious message entered the conversation.
Re: Invoice RC-10482The In-Reply-To value supports that Message B was constructed as a reply to Message A. It does not prove that the sender possessed Message A in a genuine mailbox or used the normal Reply button. Software can insert identifiers, and a hostile sender may copy material from an earlier message.
The later message contains a technical reference to the earlier message. When matching references also appear in preserved mailbox and provider records, they can strongly support the reconstructed sequence.
The fields do not prove that the same person, account or device sent both messages, or that every quotation and attachment is unchanged. Those questions require the wider evidence.
Message-ID fields describe technical relationships¶
Each email can carry its own Message-ID. A reply may also carry In-Reply-To and References fields linking it to earlier messages.
For a straightforward exchange, these fields form a consistent chain. The original has its identifier; the first reply points to it; later replies retain the earlier references while adding new Message-IDs of their own.
The identifiers are still data created by sending software. A service may omit them, replace them or build a new structure. A user can start a fresh email with an old subject. A ticketing platform may turn replies into new cases. A hostile sender may copy a known Message-ID into a fabricated reply.
Go deeper into the identifier
Subject lines and quotations are useful - but easy to reproduce¶
Applications commonly group messages by subject, but anybody who knows the subject can reuse it. Repeated “Re:” or “Fwd:” prefixes do not create a genuine relationship.
A reply may reproduce earlier words, but quoted text can be edited, removed or fabricated. The preserved earlier message is stronger than its quotation inside a later one.
From, To and Cc values help reconstruct the exchange, but displayed addresses can be spoofed and BCC or delegation can create branches not visible to everyone.
Invoice numbers, attachments or details known within the conversation may support access to earlier material and create a line of enquiry about how that knowledge was obtained.
The content can therefore support the relationship without proving the mechanism. A fraudster may know the invoice number because a mailbox was compromised, an earlier email was forwarded, a document was obtained elsewhere or somebody inside the businesses supplied it.
Provider and mailbox records strengthen the reconstruction¶
The strongest thread assessment usually combines the messages with records made outside them:
- native messages in corresponding mailboxes;
- Sent Items, drafts and deleted-item records;
- provider message trace or email logs;
- organisational gateway or archive records;
- matching provider network identifiers; and
- account audit showing relevant mailbox activity.
- whether one account was compromised;
- whether a delegate or shared mailbox was used;
- whether a platform reconstructed the thread;
- whether quoted content was changed; and
- who controlled the relevant accounts or devices.
Matching records at the recipient and sending providers can support delivery and sequence. A corresponding Sent item may support that an account generated a message, while account and device evidence is needed to test who controlled that account at the time.
A real conversation can branch¶
Threads are not always a single straight line. One recipient may Reply All while another replies only to the sender. A BCC recipient may start a separate exchange. Somebody may forward one message into a new subject. A ticketing system may create its own message identifiers.
Two branches can therefore belong to the same real-world conversation without every message referring directly to every other message. The investigation should preserve the branch points rather than force the material into one neat chain because the email application has drawn it that way.
Reconstruct the thread in a repeatable sequence¶
- Preserve each message
Retain the native messages rather than only the collapsed conversation because each one carries its own header, body and attachments.
- Record the identifiers
Extract Message-ID, In-Reply-To and References because they describe the technical relationships asserted by the sending software.
- Normalise the times
Compare full timestamps and time zones because display times may be localised and different systems may record separate stages of delivery.
- Compare participants and content
Check addresses, quotations, attachments and knowledge because they can support or challenge the apparent sequence.
- Check independent systems
Use mailbox, gateway and provider records because they can confirm that the messages existed and were handled in the reconstructed order.
- State the relationship narrowly
Describe a thread as established, strongly supported or merely apparent according to the evidence because the conclusion should expose any remaining gap.
Use a conclusion that matches the evidence¶
A strong conclusion might say:
The preserved messages contain a consistent chain of Message-ID, In-Reply-To and References values, appear in the corresponding mailboxes and match the provider delivery timeline.
If only the subject and quoted text match, say that the messages appear related or were presented together. That still records something useful without pretending that the technical relationship has been established.
The point to remember¶
Continue from here
See it used in an investigation
Go deeper