Skip to content
Skip to main content
Messaging, Social Media & Telecoms Operational Explainer

How should message evidence be described in an investigative report?

Describe message evidence by source, object and supported event, then set out the separate reasoning used for interpretation and personal attribution.

Make the evidential route visible

Identify whether the material came from a device extraction, provider return, recipient endpoint, native export, screenshot, organisational system or witness. Name the relevant account, device, session, message, attachment, call or group identifiers and state the time basis.

Quote or summarise content accurately before explaining its significance. Record missing material, edits, deletions, synchronisation differences and limits of screenshots or exports. Preserve a route from the report back to the original record.

Match language to the proven layer

“The account sent the message” differs from “the seized device sent it” and “the named person authored it.” Explain the evidence connecting each layer and any realistic unresolved alternatives such as linked access, compromise or automation.

Avoid certainty language unsupported by the records. A reader should be able to understand what was observed, how the conclusion follows and what remains uncertain. Authorship uncertainty should be expressed directly, not hidden in technical wording.

The point to remember

Report the source and event first, then expose every account, endpoint and personal-attribution step with its supporting evidence and limits.

Reference: MSG-119Messaging, Social Media & Telecoms