Email preservation checklist¶
Email preservation has three possible layers: the message object, its mailbox context, and the provider or identity records behind the account. Decide which layers the enquiry needs instead of assuming that a screenshot or downloaded attachment preserves the whole event.
Preserve the source and its context¶
- [ ] Leave the original message in the mailbox where possible.
- [ ] Record the account, folder, device, application, acquisition time and method.
- [ ] Acquire a native EML, MSG or appropriate mailbox export.
- [ ] Retain the complete header, MIME structure, plain-text and HTML bodies.
- [ ] Preserve attachments, embedded content, filenames and underlying links.
- [ ] Keep relevant Sent, Draft, Deleted, Junk, archive and conversation items.
- [ ] Record mailbox rules, forwarding and delegated access where they bear on the question.
- [ ] Keep screenshots as evidence of a particular rendering, not as substitutes for the native message.
Use a working copy for examination. Opening remote content, following links or running attachments can create new events or risk harm. Keep the preserved source unchanged and document any extraction, decoding, conversion, decompression or HTML rendering used to produce an examination copy.
Protect records held outside the message¶
- [ ] Identify relevant message-trace, delivery, rejection, redirection and quarantine events.
- [ ] Preserve mailbox-audit records for access, sending, movement, deletion, rules and delegate activity.
- [ ] Preserve sign-in, session, authentication, recovery, device and connected-application records where compromise or attribution is in issue.
- [ ] Include campaign, workflow, customer, API or transaction records when a platform generated the message.
- [ ] Record containment actions that changed the account, mailbox or device.
- [ ] Record hashes and exhibit handling where local procedure requires them.
These datasets can have different owners and retention periods, so protect the short-lived records early. Scope preservation to the question and realistic alternatives: one message may be too narrow, while years of unrelated mailbox material may be disproportionate.
The preservation record should enable another person to explain what was acquired, what stayed in place, which surrounding records were protected, what later changed and how each derivative was produced.
Key takeaway
Preserve the native message, the mailbox context needed to interpret it and the provider records that may connect it to an account, session or platform event.