Skip to content
Skip to main content
Email Evidence Technical Explainer

What can login history show?

Login history can show how an account-access attempt was recorded by the provider.

It may tell you that access succeeded, failed or was challenged, and record useful context such as time, source address, client, device or authentication method.

That can be strong evidence about the account event. It is not automatically proof of the person behind it.

The short version
Use login history to establish the authentication event and its technical context. Then connect that event to the relevant session, device and mailbox activity before making a personal attribution.

What might a sign-in record contain?

Depending on the provider and product, a record may include fields such as:

Example sign-in record
Account: finance@example.orgTime: 2026-08-14 07:48 UTCResult: SuccessSource IP: 203.0.113.24Client: BrowserAuthentication: Password + MFASession ID: S-4812

The exact fields vary, but the record may help answer:

  • which account was involved;
  • when the provider handled the access attempt;
  • whether it succeeded;
  • what authentication route was accepted;
  • what network or client context was recorded; and
  • whether a session or device identifier can be carried into later activity.

Read location and device labels carefully

An IP-derived location is usually an estimate about the network address, not a GPS fix for the person.

A device name may be user-supplied or reflect a registered device record rather than proving current physical possession.

A successful MFA event means the provider accepted its configured authentication process. It does not by itself explain who controlled every factor.

Those details are still useful — they simply need to be interpreted for what they actually represent.

The important event may happen later

Suppose the account signs in at 07:48 and a disputed email is sent at 09:12.

There may be no second login at 09:12.

The account may still be operating through session S-4812, a connected application or delegated access.

AuthenticationAccess acceptedProvider records the login event.
SessionAuthority continuesThe account can keep operating without another password entry.
Mailbox actionMessage sent or rule changedLater event may link back through session or application identifiers.

What account-access records may exist? shows the wider set of records that can complete that chain.

Compare the login with normal and disputed activity

Useful comparisons may include:

  • other sign-ins from the same account;
  • known devices or browsers;
  • session and token history;
  • mailbox audit;
  • message submission;
  • password or recovery changes;
  • connected applications; and
  • independent evidence about who had the device.
Login history may support

That the provider accepted or rejected access to a particular account in a recorded technical context at a particular time.

It does not automatically establish

Who personally controlled the credential, factor, device or continuing session, or who performed every later mailbox action.

The practical point is: login history is often the start of the account timeline, not the end of the attribution exercise.

Sources

Reference: EML-021Email Evidence