What corroboration should I look for?¶
Look for independent evidence that tests the particular link you are trying to make: the message, delivery, account, session, device or person. Corroboration is not simply collecting more material that repeats the same observation. It is finding records from other systems or sources that support - or challenge - the weakest part of the developing case.
Start with the proposition - not a shopping list¶
In the supplier-payment investigation, the records develop two suspects. Provider details associate Ellis Ward with the lookalike domain and mailbox; bank records associate Sam Dyer with the receiving account; exchange records bring Ellis into the onward movement of the money.
The records justify further investigation of Ellis and Sam. They do not yet answer every question about control or responsibility. The best corroboration is therefore evidence that tests those open links rather than another copy of the email or another report based on the same provider return.
Independent systems place Ellis-associated details in the sending arrangement and onward account, while Sam-associated records appear in the receipt and movement of the payment. Their convergence supports a developing case involving both suspects.
The records do not by themselves prove who possessed each device, who controlled every account, what each suspect knew or whether somebody else participated. Those are the propositions that further evidence should test.
Break attribution into separate links¶
“The email came from Ellis” may conceal several different propositions. Separate them before deciding what evidence is needed.
Did this particular message exist, and did the recipient's service receive it at the recorded time?
Which tenant, mailbox, platform, campaign or customer account caused the message to be submitted?
Which session, application, token or device controlled the account when the relevant activity occurred?
Who controlled the device or account, what did they know, and what part did they play in the conduct under investigation?
The evidence needed to prove delivery is not the same as the evidence needed to prove authorship. A recipient provider may confirm delivery. A sending provider may identify the account. An identity service may identify the session. A device may contain the draft. Communications and financial records may test the person's knowledge and involvement.
Independent systems can reinforce one another¶
Different records are valuable because they were created by different systems for different operational purposes. The recipient provider records delivery. The sending service records submission. The identity service records a sign-in. A device records local activity. A bank or exchange records movement of money.
Agreement between those sources is more persuasive than several formats derived from one source.
Three documents may still be one observation¶
A screenshot, PDF export and witness statement may all reproduce the same displayed email. Three analysts may write reports based on the same provider log. Several header fields may all come from one message.
Those items may help explain or present the evidence, but they are not automatically independent corroboration.
Email → screenshot → PDF → reportSeveral outputs repeat what one displayed message showed. They do not create separate proof of its delivery route or account control.
Provider + identity + device + bankSeparate systems record different parts of the conduct and can test whether the proposed chain holds together.
The point is not to dislike copies. It is to understand what each item independently contributes.
Choose corroboration for the question¶
- native copies in recipient or sender mailboxes;
- recipient and sending provider trace;
- gateway, archive or journal records;
- matching Message-ID or provider identifiers; and
- replies or actions referring to receipt.
- mailbox audit and account activity;
- sign-in, session and token records;
- registered-device or managed-device identifiers;
- drafts, cached messages and source files;
- witness and communications evidence; and
- related financial or operational activity.
The available record names will differ between services. Frame the request around the event and question rather than assuming that every provider uses the same fields.
Corroboration should also test other explanations¶
If the account holder denies sending the message, test compromise, delegation, shared access, automation and device sharing. If an IP address appears to place a user somewhere, test whether it belongs to a provider server, VPN, proxy, mobile gateway or other intermediary. If SPF, DKIM and DMARC passed, test whether a genuine account or authorised platform was abused.
Evidence that challenges the working theory is useful. It may expose a different suspect, prevent a mistaken operational decision or make the final case more robust by showing that realistic alternatives were examined.
Work from the weakest link¶
- State the proposition
Write the link you are trying to establish because “connect the email to the suspect” is too broad to guide a useful enquiry.
- List what already supports it
Identify the source of each observation because several documents may repeat the same underlying record.
- Find the weakest link
Separate message, delivery, account, session, device and person because the gap often sits between two of them.
- Choose an independent source
Seek records made by another system or witness because they can test the link without relying on the original observation.
- Test realistic alternatives
Consider compromise, delegation, automation, shared devices and intermediaries because the same account activity may have more than one explanation.
- Record what remains open
State the supported conclusion and unresolved gap because this directs the next line of enquiry and prevents the evidence being overstated.
The point to remember¶
Continue from here
See it used in an investigation
Go deeper