Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is an email-security log?

An email-security log records how a gateway or protection service assessed and handled a message. It does not alone prove the message was malicious or that a recipient opened or acted on it.

Product stages and verdicts differ

Receipt, scan, quarantine, delivery, rejection, link checking and sandboxing may be separate events. Records can contain message ID, sender, recipient, source, subject, attachments, URLs, rule, verdict and time. “Delivered” may mean mailbox acceptance; “clicked” can describe a security scanner; verdicts can change.

Identify product and stage and preserve original message, headers, attachment hashes, URLs, rules and reclassification where lawfully available.

Correlate mailbox audit, identity, endpoint, browser and network records before concluding open, click or execution.

The point to remember

Email-security records explain system handling; mailbox and endpoint evidence establish what the user encountered and did.

Reference: LOG-025Logs, Records & Provider Evidence