Skip to content
Skip to main content
Email Evidence Technical Explainer

What records may link an email account to a device or recovery account?

Device registrations, sign-in and session IDs, authentication methods, recovery addresses and phone numbers can connect an email identity to wider records. Each is evidence of association, not automatic proof of who controlled the account at message time.

Historical changes matter as much as current values

Providers may record device ID, registration and management status, recent access, MFA methods and when recovery details were added, changed or removed. Those identifiers can link sign-in to mailbox activity more strongly than a friendly device name.

Devices and numbers can be shared, rebuilt, reassigned or compromised. Recovery details may be old, belong to staff or family, or have been changed during takeover. Current settings alone can therefore misstate the relevant period.

Build a time-specific chain of control

Preserve exact account, session, token and device IDs plus authentication-method and recovery-change history. Correlate provider data with asset management, physical examination, subscriber information and evidence of possession.

Connected application and consent records may reveal another access route. A defensible attribution explains when an identifier was associated, who could use it, and how the disputed message links to that session or application.

The point to remember

Device and recovery records strengthen attribution only when their historical ownership, control and link to the relevant session are established.

Sources

Reference: EML-033Email Evidence