Skip to content
Skip to main content
Email Evidence Operational Explainer

How do I preserve an email properly?

Preserve the native message and the context that explains where it came from.

A screenshot can be useful for showing what somebody saw, but a native email may also contain routing, message identifiers, authentication results, hidden HTML, attachment structure and other material that a screenshot cannot preserve.

The practical rule
Keep the original where possible, acquire a native copy, record exactly where it came from, and examine a working copy rather than altering the preserved source.

Preserve the message as an email object

Depending on the platform, a suitable native acquisition may be an EML, MSG or mailbox export.

The important point is not the file extension by itself. It is whether the acquisition retains the relevant message structure, including where available:

  • complete headers;
  • plain-text and HTML bodies;
  • MIME structure;
  • attachments and embedded items;
  • filenames;
  • underlying link destinations;
  • message identifiers; and
  • provider-specific identifiers.
Screenshot / print / PDFGood for appearanceMay show what the recipient saw, but often loses routing, hidden fields, native structure and provider identifiers.
Native message / mailbox exportBetter evidential sourceRetains the message object and technical structure needed for later examination.

Record where the message came from

A preserved file without provenance is harder to interpret later.

Record, where relevant:

  • mailbox or account;
  • folder;
  • device or application used for acquisition;
  • acquisition method;
  • date and time;
  • person carrying out the acquisition; and
  • any conversion or export process.

If the message sits within an important conversation, preserve the relevant surrounding thread as well.

Avoid creating a new event while trying to preserve the old one

Ordinary forwarding creates a new message and may lose or alter fields.

Opening remote content can contact an external server.

Following links or opening an attachment may create new activity or introduce risk.

That does not mean the email must never be examined. It means preservation and analysis should be treated as separate steps.

OriginalLeave source intact where possibleKeep the mailbox item and native message relationship.
AcquireCreate a traceable native copyRecord account, folder, method, time and handler.
ProtectKeep preserved source unchangedApply local integrity and evidence-handling procedure.
ExamineUse a working copyDecode, render or extract only in the examination copy.

The mailbox and provider may hold evidence the message does not

The email object is only one layer.

The mailbox or provider may separately hold:

  • message trace;
  • mailbox audit;
  • deleted items;
  • rules and forwarding;
  • delegate activity;
  • sign-in and session records; and
  • security events.

Email preservation checklist gives the broader preservation pass when those layers matter.

The practical point is: preserve the native message first, record its provenance, and keep enough mailbox or provider context to answer the actual investigative question later.

Sources

Reference: EML-010Email Evidence