Skip to content
Skip to main content
Email Evidence Foundation explainer
Pathway: I have been given a suspicious email

What corroboration should I look for?

Look for independent evidence that tests the particular link you are trying to make: the message, delivery, account, session, device or person. Corroboration is not simply collecting more material that repeats the same observation. It is finding records from other systems or sources that support - or challenge - the weakest part of the developing case.

The short version
Define the proposition, identify its weakest link and find independent evidence that tests it. More records are useful only when they help answer a real investigative question.

Start with the proposition - not a shopping list

In the supplier-payment investigation, the records develop two suspects. Provider details associate Ellis Ward with the lookalike domain and mailbox; bank records associate Sam Dyer with the receiving account; exchange records bring Ellis into the onward movement of the money.

Message lineLookalike domain and mailbox
Money lineReceiving and exchange accounts
Developing suspectsEllis Ward and Sam Dyer
QuestionWho controlled and knew?
Combined investigative position
Registrar / provider   account details associated with Ellis WardReceiving institution   account and handset associated with Sam DyerExchange   onward account verified to Ellis WardStill open   account control, devices, communications, knowledge and intent

The records justify further investigation of Ellis and Sam. They do not yet answer every question about control or responsibility. The best corroboration is therefore evidence that tests those open links rather than another copy of the email or another report based on the same provider return.

The combined records support

Independent systems place Ellis-associated details in the sending arrangement and onward account, while Sam-associated records appear in the receipt and movement of the payment. Their convergence supports a developing case involving both suspects.

They do not yet establish

The records do not by themselves prove who possessed each device, who controlled every account, what each suspect knew or whether somebody else participated. Those are the propositions that further evidence should test.

Choose the next evidence deliberatelyAsk what remains unproved, then seek a different source capable of testing that exact link.

“The email came from Ellis” may conceal several different propositions. Separate them before deciding what evidence is needed.

Message and delivery

Did this particular message exist, and did the recipient's service receive it at the recorded time?

Provider account

Which tenant, mailbox, platform, campaign or customer account caused the message to be submitted?

Session and device

Which session, application, token or device controlled the account when the relevant activity occurred?

Person and responsibility

Who controlled the device or account, what did they know, and what part did they play in the conduct under investigation?

The evidence needed to prove delivery is not the same as the evidence needed to prove authorship. A recipient provider may confirm delivery. A sending provider may identify the account. An identity service may identify the session. A device may contain the draft. Communications and financial records may test the person's knowledge and involvement.

Independent systems can reinforce one another

Message eventRecipient and sending recordsConfirm delivery, route, provider identifiers and the account used.
Account controlSession and device recordsConnect account activity to a session, application or device.
Person and conductWider case evidenceTests possession, knowledge, communications, benefit and responsibility.

Different records are valuable because they were created by different systems for different operational purposes. The recipient provider records delivery. The sending service records submission. The identity service records a sign-in. A device records local activity. A bank or exchange records movement of money.

Agreement between those sources is more persuasive than several formats derived from one source.

Three documents may still be one observation

A screenshot, PDF export and witness statement may all reproduce the same displayed email. Three analysts may write reports based on the same provider log. Several header fields may all come from one message.

Those items may help explain or present the evidence, but they are not automatically independent corroboration.

Repeated sourceEmail → screenshot → PDF → report

Several outputs repeat what one displayed message showed. They do not create separate proof of its delivery route or account control.

Independent sourcesProvider + identity + device + bank

Separate systems record different parts of the conduct and can test whether the proposed chain holds together.

The point is not to dislike copies. It is to understand what each item independently contributes.

Choose corroboration for the question

To test the message or delivery
  • native copies in recipient or sender mailboxes;
  • recipient and sending provider trace;
  • gateway, archive or journal records;
  • matching Message-ID or provider identifiers; and
  • replies or actions referring to receipt.
To test the account, device or person
  • mailbox audit and account activity;
  • sign-in, session and token records;
  • registered-device or managed-device identifiers;
  • drafts, cached messages and source files;
  • witness and communications evidence; and
  • related financial or operational activity.

The available record names will differ between services. Frame the request around the event and question rather than assuming that every provider uses the same fields.

Corroboration should also test other explanations

If the account holder denies sending the message, test compromise, delegation, shared access, automation and device sharing. If an IP address appears to place a user somewhere, test whether it belongs to a provider server, VPN, proxy, mobile gateway or other intermediary. If SPF, DKIM and DMARC passed, test whether a genuine account or authorised platform was abused.

Evidence that challenges the working theory is useful. It may expose a different suspect, prevent a mistaken operational decision or make the final case more robust by showing that realistic alternatives were examined.

Corroboration is a testLook for evidence that could prove the working theory wrong as well as evidence that supports it.
  1. State the proposition

    Write the link you are trying to establish because “connect the email to the suspect” is too broad to guide a useful enquiry.

  2. List what already supports it

    Identify the source of each observation because several documents may repeat the same underlying record.

  3. Find the weakest link

    Separate message, delivery, account, session, device and person because the gap often sits between two of them.

  4. Choose an independent source

    Seek records made by another system or witness because they can test the link without relying on the original observation.

  5. Test realistic alternatives

    Consider compromise, delegation, automation, shared devices and intermediaries because the same account activity may have more than one explanation.

  6. Record what remains open

    State the supported conclusion and unresolved gap because this directs the next line of enquiry and prevents the evidence being overstated.

The point to remember

Operational takeaway
Corroborate the weakest link, not merely the existence of the email. Use independent provider, identity, device, financial, communications and witness evidence to test who controlled the relevant account or system and what part they played.
Continue from here

See it used in an investigation

Go deeper

Reference: EML-024Email Evidence