Skip to content
Skip to main content
Email Evidence Technical Explainer
Pathway: I have been given a suspicious email

What changes when a shared mailbox, Send As or Send on Behalf access is used?

The visible address may identify a team mailbox while a delegate, application or administrator performed the sending action. Attribution must move from the shared identity to the permission and session actually used.

Permissions shape what the recipient and audit see

Full Access commonly allows mailbox management but not automatically sending. Send As can make the message appear directly from the shared mailbox; Send on Behalf normally exposes the delegate relationship. Platform configuration controls the precise presentation and audit fields.

Sent copies may be stored in the delegate mailbox, the shared mailbox or both. Their absence from one location does not disprove use. Applications and service identities can also send through shared authority.

Reconstruct delegate, session and human control

Preserve native message and trace, historical permission assignments, mailbox audit, authentication, application consent and relevant Sent Items. Identify SendAs or SendOnBehalf events, the delegate or application, session, device and any permission changes.

Audit may establish the technical sender while authorship or approval remains separate. Shared access does not make attribution impossible; it defines the records needed to narrow the action. Protected EML-024 explains how to corroborate the weakest remaining link.

The point to remember

Move from the shared address to the permission, delegate or application, session and device that used it.

Sources

Reference: EML-023Email Evidence