Skip to content
Skip to main content
Email Evidence Technical Explainer

What can timestamps in an email header tell me?

They can reconstruct stages of message creation and transfer, provided each time is tied to the system that recorded it. There is no single universal “email time”.

Header times describe different events

The sender-supplied Date field may represent creation or submission and can reflect a wrong clock, altered value or delayed sending. Each trusted Received line records a server accepting the message from the previous hop. Mailbox and provider trace can add processing, filtering and delivery stages.

Queues, scanning, greylisting, retries and outages create genuine delays. An apparently impossible lower-hop sequence may instead reflect an untrusted line, clock error, time-zone mistake or transformation.

Preserve original offsets and trust before arithmetic

Work backwards from recipient infrastructure and identify the event behind every timestamp. Retain original value and offset, then convert a working comparison to UTC or another common zone. Do not equate provider receipt with human reading.

A defensible timeline says which system recorded composition, handover or delivery and carries uncertainty about untrusted fields and clocks. Provider, account and device records may be needed for submission or access questions.

The point to remember

Treat every email timestamp as one system's record of one stage, preserving its offset and trust context.

Sources

Reference: EML-022Email Evidence