Skip to content
Skip to main content
Email Evidence Operational Explainer

What should I ask an email provider to preserve?

Ask for the identifiable message, the relevant account activity and the provider records that connect them. Give the provider enough detail to locate the event: full account identifiers, sender and recipient addresses, complete Message-ID, precise time and timezone, subject, and any trace, campaign or transaction identifier already available.

Preserve records that answer the case question

The useful scope depends on what needs to be established. Delivery may be answered by message trace, rejection, redirection, quarantine and mailbox records. A disputed sending event may also require account sign-ins, sessions, authentication events, mailbox audit, delegated access, connected applications, forwarding rules and evidence of compromise.

Where a platform or shared mailbox was involved, include tenant, campaign, workflow, API and delegate records. Those may identify the process that caused the message without attributing it prematurely to the named account holder.

Specify a proportionate time window around the event. It should be wide enough to capture access, drafting, submission, deletion, rule changes and follow-up activity. State the timezone rather than leaving the provider to infer it.

Describe records, not conclusions

A request to preserve records “identifying the person who sent the email” assumes the provider recorded a person. Ask instead for the account, message, session, device, authentication and audit records associated with the defined event and period.

Different datasets may have different names, owners and retention periods. If one record type is unavailable, establish whether an equivalent event exists in another system. Record what was requested, when, through which route and with which identifiers.

Preserving only the message can lose the activity needed to test attribution or compromise. Requesting an account's entire history without a defined need can be equally unsound. Map the likely record holders, then target the records that may disappear.

Key takeaway

Identify the message, account, period and evidence types precisely enough for the provider to preserve the records that can test delivery, control and compromise.

Sources

Reference: EML-035Email Evidence