Skip to content
Skip to main content
Email Evidence Worked example

Worked example - a message generated by a CRM or mailing platform

An organisation's name in the visible From field does not mean a member of staff personally composed and sent the email from their own mailbox. Customer relationship management systems and mailing platforms can create and transmit messages on an organisation's behalf.

This example shows how to separate the message, the platform activity and the person responsible.

The scenario

A recipient receives an email headed:

From: Northbridge Training <updates@northbridge.example> Subject: Your course booking has changed

The investigator needs to establish whether the email genuinely came through Northbridge's mailing platform and who caused it to be sent.

The preserved message contains header fields resembling:

From: Northbridge Training <updates@northbridge.example>
Return-Path: <bounce-3942@mailer.crm-platform.example>
Message-ID: <campaign-8821.3942@mailer.crm-platform.example>
Received: from outbound.crm-platform.example (198.51.100.24)
Authentication-Results: spf=pass; dkim=pass; dmarc=pass

These are fictional values using reserved example domains and documentation addresses.

What the clues suggest

Clue What it may support What it does not prove
Visible From address The identity presented to the recipient Which individual wrote, approved or triggered the message
Platform Return-Path The platform handled delivery and bounce processing That the visible sender personally used the platform
Platform Message-ID A value that may be matched with campaign or delivery records Authorship or responsibility by itself
Received field A stage in the route recorded by a mail system The sender's personal device or physical location
SPF, DKIM and DMARC passes The message followed an authorised or aligned domain-sending route, subject to the relevant mechanism's limits The identity of the human who created or initiated it

Taken together, the fields may support the conclusion that the message travelled through the organisation's authorised mailing arrangement. They do not identify the person behind the campaign.

Three different ways the message could have been created

The platform might have sent the same message because:

  1. a staff member manually created and launched a campaign;
  2. an authorised user changed a customer record and triggered an automated workflow; or
  3. a scheduled rule sent the message without a person taking action at the delivery time.

There are other possibilities, including compromised credentials or misuse of a shared account. The email header alone will not distinguish them. Mailing-platform and customer-management systems explain the platform route in more depth; account-access records become important where a named user or session needs to be tested.

What to preserve and request

Preserve the original email in a native format that retains the complete header and body. Record where it came from and avoid relying only on a screenshot or forwarded copy.

Then identify the platform owner or administrator and consider preserving:

  • campaign, workflow or automation records;
  • the message or template version used;
  • campaign and recipient-list identifiers;
  • creation, approval, scheduling and delivery timestamps;
  • user and administrator audit logs;
  • account sign-in, session and security records;
  • role and permission information;
  • changes to the recipient's CRM record; and
  • records linking the platform message identifier to the delivered email.

The exact request should follow the investigative question. If the issue is whether the message was delivered, delivery records may be central. If the issue is who caused it to be sent, audit, identity and workflow records are likely to matter more.

Match the conclusion to the evidence

The available material might support progressively stronger conclusions:

  • the recipient received a message displaying Northbridge's identity;
  • the message was transmitted through Northbridge's authorised platform arrangement;
  • a particular platform account created, approved or triggered the message;
  • a named person controlled that account at the relevant time; or
  • the whole evidential picture establishes who was responsible.

Each step requires additional evidence. Do not collapse them into one conclusion. Where the question is which organisation or service may hold those records, continue to who may hold relevant email records.

Operational takeaway

Use the email header to understand the delivery route, then use platform audit, workflow and identity records to investigate who created, approved or triggered the message.

Reference: EML-045Email Evidence