Email evidence triage checklist¶
Use this when somebody has just handed you a suspicious or relevant email and you need to work out what needs doing first.
You are not trying to solve the whole case at this point. You are trying to stop anything getting worse, keep the useful evidence, and make sure the next investigator knows what question they are picking up.
What have you actually been given?¶
- [ ] Original message still present in the recipient's mailbox
- [ ] Native EML or MSG file
- [ ] Forwarded copy
- [ ] Screenshot
- [ ] PDF or printout
- [ ] Copied header or text extract
- [ ] Summary only
Record which one you have and whether the native original still exists.
A screenshot can be enough to recognise what the recipient saw, but it may not contain the full delivery route, underlying links, attachments or message identifiers. If the original exists, preserve it rather than repeatedly forwarding the message around.
Has anything already happened?¶
Ask the recipient what they actually did.
- [ ] Clicked a link
- [ ] Opened an attachment
- [ ] Enabled active content or macros
- [ ] Entered credentials
- [ ] Approved or changed a payment
- [ ] Replied
- [ ] Forwarded the message
- [ ] Changed account settings
- [ ] Knows of other recipients
Record the approximate times as well as the actions.
If a link was followed or an attachment opened, the enquiry may already extend beyond the email itself. The worked example of an opened suspicious attachment shows how the evidence then moves onto the device and account.
Is there an immediate risk to contain?¶
Consider whether:
- money can still be stopped or recalled;
- credentials may have been exposed;
- the account should be secured;
- an affected device needs incident-response action;
- other recipients may still interact with the same message; or
- a malicious rule, forwarding arrangement or session may still be active.
Protective action and preservation often need to happen together. Record what was changed and when.
Preserve the useful evidence¶
- [ ] Leave the original message in place where possible.
- [ ] Acquire a native copy retaining the complete header and body.
- [ ] Preserve attachments and embedded content with the message.
- [ ] Record the recipient account, folder, device/application and acquisition time.
- [ ] Keep relevant thread, Sent, Draft, Deleted or Junk context where it matters.
- [ ] Preserve mailbox rules or forwarding where compromise is suspected.
- [ ] Identify relevant message-trace, audit, sign-in, session or security records.
- [ ] Record containment actions that changed the account, mailbox or device.
For a fuller preservation pass, use the email preservation checklist.
What question should the next investigator answer?¶
Try not to hand the next person a vague job like “look at this suspicious email”. Give them a question they can actually investigate.
| If you need to establish… | The next useful evidence is likely to include… |
|---|---|
| What the recipient received | Native message, body, attachments and rendered view |
| How the message was delivered | Complete header and provider message trace |
| Which mailbox or platform sent it | Submission, mailbox-audit or platform records |
| Whether an account was compromised | Sign-in, session, authentication and mailbox-change records |
| What happened after a click or attachment | Device, browser, endpoint and security records |
| Who was responsible | Account/session/device evidence plus independent corroboration |
What can I do with an email relevant to an investigation? explains how these evidence sources fit together.
Write a short triage outcome¶
A useful handover might read:
Original message remains in the employee's mailbox. Native copy and attachment preserved. Recipient reports opening the attachment at about 09:18 UTC and enabling active content. Device use was stopped and the incident-response team notified. Provider trace and account audit have been identified for preservation. Next question: what executed on the workstation and was the account affected?
That is enough for triage. If the next investigator knows what happened, what has been protected, what evidence is safe and what they are trying to answer next, you have done the useful bit.