What can a Message-ID tell me?¶
A Message-ID is an identifier intended to distinguish a message version. It is a valuable search and correlation handle across mailboxes, gateways, archives and provider trace - not a cryptographic fingerprint or human identity.
The generating system controls the value¶
Message-IDs commonly appear inside angle brackets and may contain a domain associated with the generating software. Hostile or misconfigured systems can create misleading, absent or duplicate values. Forwarding, resending, mailing lists and transformation can preserve an identifier or create a new outer message with another one.
The same Message-ID does not prove two files are byte-for-byte identical, and different IDs do not prove their content or conversation is unrelated.
Use all identifiers at their proper scope¶
Preserve the complete value, including brackets, and compare it with recipient and sender copies, message trace and security or archive records. Also retain provider network, transport, campaign, ticket and delivery IDs; these may be more precise within one service.
Combine identifiers with content, recipients, timestamps and In-Reply-To or References. A supported finding is that matching records refer to the same message - not that the Message-ID names its author.
The point to remember
Use Message-ID to find and correlate a message version while keeping authorship and byte-level integrity as separate questions.