Skip to content
Skip to main content
Messaging, Social Media & Telecoms Technical Explainer

What can messaging records prove about a device?

Messaging records may establish that a device stored, displayed, transmitted or synchronised account activity. The exact event must be distinguished from a service label and from the identity of the person using the endpoint.

Device evidence has several forms

Local databases, notifications, application files and account tokens can show content or state on a seized endpoint. Linked-device and provider session records may associate an account with a device type, identifier or session. A visible device name can be generic or user-defined and may not uniquely identify the physical hardware.

Synchronised history can place a message on a phone even when another endpoint originated it. Conversely, device-specific logs or session identifiers may narrow an event to the actual sender.

Separate presence, origin and control

Preserve hardware and application identifiers, session details, account links, timestamps, connectivity and the device's condition at collection. Compare the record with other linked sessions, unlock activity, possession, location and witnesses.

Report “present on this device,” “sent from this session” and “used by this person” only when evidence supports each proposition. Possession at seizure does not prove control during an earlier event, and shared, stolen or remotely accessed devices remain possible.

The point to remember

Identify what the device record actually shows - storage, display, synchronisation or origin - before using separate evidence to attribute human control.

Reference: MSG-106Messaging, Social Media & Telecoms