Skip to content
Skip to main content
Email Evidence Orientation
Pathway: I have been given a suspicious email

I’ve been given an email that may be relevant to an investigation. What can I do with it?

An email can be much more than the words visible on screen. Properly preserved, it can connect the message the recipient saw with delivery records, mailbox activity, provider records and device evidence.

The first job is therefore simple: preserve the best version of the message you can, identify the question you are trying to answer, and then follow the evidence source that can answer it.

The short version
Start with the original message, then work outward. The email itself, the mailbox, the provider and the device can each answer a different part of the investigation.

Start with the message you actually have

A recipient may hand you a screenshot, a forwarded message, a PDF printout or the original message still sitting in the mailbox. Those are not equivalent.

The native message can preserve:

  • the visible From, To, Subject and Date fields;
  • the complete header and delivery route;
  • Message-ID and other identifiers;
  • plain-text and HTML bodies;
  • attachments and embedded content;
  • underlying link destinations; and
  • formatting and MIME structure.

A screenshot remains useful for showing what the recipient saw, including display names, warnings and rendering. But if the original still exists, preserve that original message before reducing the evidence to a representation. A screenshot or forwarded copy may have lost information needed later.

Decide what you are trying to establish

Different questions need different evidence.

Investigative question Best starting evidence
What did the recipient receive? Native message, body, attachments and rendered view
How did the message reach the recipient? Full header and provider message trace
Did a particular mailbox or platform send it? Provider submission, mailbox audit or platform records
Was the account compromised? Sign-in, session, authentication and mailbox-change records
Did the recipient interact with a link or attachment? Device, browser, endpoint and security records
Who was responsible for sending it? Account/session/device evidence plus corroboration

This is why email evidence often becomes a chain rather than one magic field.

For example, From, Reply-To and Return-Path help explain the identities and routes presented in the message. Account-access records may then show which session or application acted through a mailbox. Device and recovery records can help connect that account activity to wider evidence.

Preserve before you explore

If the email may be malicious, avoid creating fresh activity unnecessarily.

  • Leave the original in place where possible.
  • Do not ask the recipient to open an attachment or follow a link again.
  • Record what they have already done.
  • Acquire a native copy that retains the complete message.
  • Keep attachments in their relationship to the message.
  • Record the account, folder, device/application and acquisition time.
  • Preserve relevant provider records early where retention may be short.

Use the email evidence triage checklist when the immediate task is deciding what needs protecting now, and the email preservation checklist when you need the fuller preservation layer.

Read the email as part of a system

A complete email header can describe parts of the delivery route, but modern email often separates the person's device from the infrastructure that finally delivers the message.

A webmail user may connect to a provider, while the recipient sees only the provider's outbound mail server. A CRM or mailing platform may generate the message after a user changes a customer record. A shared mailbox may allow several authorised users to send through one address.

That is why the next useful question is often not “Who owns this From address?” but which system or account caused this particular message event?

The supplier-payment walkthrough shows that process end to end: preserve the original, read the delivery records, follow the sending arrangement, then join email evidence with account, device and financial records.

Finish triage with a short position

A good first assessment should leave the next investigator with five things:

  1. What you have — original message, native file, screenshot, forward or other representation.
  2. What has been preserved — message, attachment, mailbox context and any short-lived provider records.
  3. What has already happened — clicks, attachment opening, replies, credential entry or payment.
  4. What question remains — delivery, account control, compromise, device activity, attribution or something narrower.
  5. Where the next evidence is likely to be — mailbox, provider, platform, device or another recipient.

That is enough to turn “we have an email” into a defined line of enquiry without trying to solve the entire investigation at first contact.

The point to remember

Operational takeaway
Preserve the original message and let the investigative question determine how far you expand. Email, mailbox, provider and device evidence are complementary sources, not interchangeable versions of the same thing.
Reference: EML-014Email Evidence