Skip to content
Skip to main content
Email Evidence Operational Explainer

What should I ask the recipient not to do?

Ask the recipient to stop interacting with the message: do not reply, forward, click links, open attachments, delete it or alter it. The original should remain in the mailbox while a safe preservation method is arranged.

Establish what has already happened

The recipient may already have replied, followed a link, entered credentials, approved a payment or opened a file. Obtain an honest timeline, including the account, device and application used. Do not ask them to repeat an action so that somebody can observe the result.

A screenshot can help identify the message, but it is not a substitute for preserving the native email and complete header. Related replies, sent items and communications through other channels may also supply necessary context, so they should not be tidied away.

Protection can take priority

Active account compromise, malware, payment fraud, threats or data exposure may require immediate containment. Sessions may need revoking, accounts securing, payments stopping or devices isolating. Record those actions and their times; preserving evidence does not require allowing harm to continue.

Avoid uncontrolled experimentation. Changing settings, installing unapproved tools, submitting material to public analysis services or resetting a device may change the evidence or disclose it to another party. Use the organisation's established incident and evidence routes.

A concise instruction is usually enough: leave the original where it is, do not interact with it, and report everything already done. That protects both the recipient and the investigation without implying blame.

Key takeaway

Stop further interaction, preserve the original context and record prior actions - while taking any urgent protective steps needed to limit continuing harm.

Sources

Reference: EML-036Email Evidence