Which time zone is being shown in a message record?¶
Do not assume. Phone displays, provider logs, exports and forensic tools can present the same event in device local time, UTC, a stored offset or the reviewing system's current zone.
Establish display and storage rules¶
Record the source, raw timestamp, visible value, zone or offset, device automatic-time setting, location and capture date. Provider documentation may define whether a field is UTC, local or an epoch value.
Travel, roaming and manual clock changes can alter device time during a conversation. Some applications redisplay older messages in the device's current zone, while relative labels such as “today” depend on viewing time. Daylight-saving changes can create one-hour differences or repeated local times.
Convert transparently¶
Preserve original records before putting events into a common reference zone. Document the conversion, daylight-saving rule and any assumption so another reviewer can reproduce it.
Where the time basis is unknown, keep the uncertainty visible and seek specialist interpretation rather than silently applying local time. Different displayed values can still represent one event once zones are resolved.
The point to remember
Establish each record's storage and display zone, preserving original times and documenting every conversion.