Email evidence

Email Forensics

Preserve mailboxes, authenticate messages, reconstruct account activity and explain the email record in language a court, regulator or board can use. Microsoft 365, Google Workspace and hybrid environments. Since 1992.

Forensic examiner at a review workstation with email evidence on screen

The practice

Email evidence, from preservation to a report that survives review

Email is one of the most contested categories of digital evidence. A dispute may hinge on whether a single message is authentic, when it moved, whether it was altered or deleted, whether it exposed information to an unauthorized account, or whether a mailbox rule was used to hide activity. Email forensics is the documented preservation, examination and reporting of that evidence.

Our practice covers Microsoft 365 and Exchange, Gmail and Google Workspace, hybrid environments and legacy mail stores. We collect remotely where possible, preserve originals, correlate messages against server and audit records, and explain the findings in language counsel, a board or a fact-finder can use.

Start here

When to use which email service

Email work usually falls into one of four buyer intents. Each links to a dedicated service page with scope, deliverables and limits.

Capability

What email forensics can prove, and what it cannot

Email evidence is not a single artifact. A defensible finding usually rests on several sources: the original message file with its full headers, the mailbox and cloud copies, the sending and receiving server records, tenant audit logs, device evidence and any independent third-party copies. Where these agree, the record is strong. Where they disagree, that gap is itself evidence.

  • Authenticity. Compare native message files, header fields, timestamps, message IDs and attachments to independent copies. Verify DKIM signatures, SPF and DMARC alignment where available.
  • Routing and delivery. Reconstruct mail flow from the evidence: server hops, mail-flow logs, delivery records and mailbox activity.
  • Access and account activity. Correlate sign-ins, mailbox actions, forwarding rules, delegation, MFA challenges and administrator changes.
  • Deletion and recovery. Identify deleted-item traces in mailbox stores, native cloud recycle bins, backups and available restore points. State what recovery is possible, and where and why it is not.
  • Exfiltration. Detect mailbox rules used to hide activity, delegation abuse used to read others' mail, download or export activity, and use of personal or third-party accounts.

The report separates what the artifacts show from what must be inferred. A displayed sender name, a screenshot or a forwarded copy alone does not establish authorship. When the record cannot answer the question, that is what the report says.

Evidence commonly examined

Evidence reviewed

  • Native email and attachments (PST, OST, MBOX, EML, MSG)
  • Microsoft 365 mailbox, sign-in and unified audit records
  • Google Workspace mailbox, Vault export and admin audit records
  • Message headers with DKIM, SPF and DMARC results
  • Mailbox rules, forwarding, delegation and permissions
  • OneDrive, SharePoint and Google Drive files associated with the messages
  • Endpoint and device evidence supporting attribution

What you can expect

What you receive

  • Acquisition record with source, method, timing and integrity values
  • Authentication findings with header analysis and independent-source correlation
  • Timeline and communication map within the agreed scope
  • Search results, review material and ESI production load files
  • Technical report separating observed facts from expert interpretation
  • Deposition and testimony support when retained

What counsel receives

A file another examiner could pick up.

The report ties each finding to a source artifact and records how the email evidence was acquired, handled and examined.

A court decides admissibility. The engagement file documents the method and foundation counsel may need to address it.

  • Scope letter and stated assumptionsWhat was asked, what was examined, what was out of scope, and the assumptions the analysis rests on.
  • Evidence handling recordAcquisition details, hash values, storage and transfer, and a chain-of-custody log for each mailbox, export or file.
  • Methodology statementTools, versions and procedures described so a second qualified examiner can repeat the work.
  • Findings, separated from interpretationObserved facts first; expert opinion identified as opinion, with the basis for each conclusion.
  • Limitations and unresolved questionsWhat the evidence cannot show, what was unavailable, and what the report does not conclude.

Court-tested

Email evidence tested in court

In COMLAB, Corp. v. Kal Tire, an SDNY matter involving disputed email evidence, a GDF expert testified about the technical explanation offered for missing native messages. The court credited the testimony and dismissed the action after finding fabrication and spoliation. Read the case and the court's findings, or meet the forensic experts.

Frequently asked

Common questions about email forensics

What is email forensics?

Email forensics is the documented preservation, examination and reporting of email evidence: messages, headers, attachments, mailbox rules, activity and security logs. The goal is to answer whether a message is authentic, who sent or received it, when it moved, whether it was altered, deleted or forwarded, and what the surrounding account activity shows.

How much does an email forensic examination cost?

Cost depends on the number of mailboxes, the platform, the deadline and whether testimony is required. Discovery of a single mailbox for a straightforward authentication question is a very different scope from a multi-custodian breach reconstruction. We define scope, deliverables and price during the first conversation.

How long does an email forensic analysis take?

Routine remote collection of a mailbox is often same-day. Analysis and reporting depend on the volume and the questions. A focused authentication review of a small message set may take days; a multi-custodian breach or eDiscovery matter can take weeks. We commit to milestones during scoping.

Do you collect Microsoft 365 and Gmail email?

Yes. We collect Microsoft 365 mailboxes, Outlook data files, OneDrive and SharePoint files, and Gmail and Google Workspace including Drive. Collection can normally proceed remotely while users continue working in their accounts. See our Microsoft 365 and Google Workspace pages.

Can you tell whether an email is real or altered?

Yes, within the limits of the evidence. We compare original message files, headers, timestamps, message identifiers, attachments and available independent copies for inconsistencies. A screenshot, forwarded copy or displayed sender name alone does not establish authorship; our report separates observations from inferences.

Can you identify who actually sent a message?

In some cases. Authentication (DKIM, SPF, DMARC), routing information, mailbox activity, device evidence and correlating records can support or contradict claimed authorship. In others, the available material only narrows possibilities. We say what the evidence supports and what it does not.

Do you handle business email compromise and hacked mailboxes?

Yes. Our business email takeover service examines unauthorized access, phishing, forwarding rules, delegation abuse, data access and persistence in Microsoft 365 and Gmail. Time matters, so call the hotline before changing passwords or exporting.

Do you provide expert testimony on email evidence?

Yes. Our examiners have provided testimony in federal and state courts on email authentication, spoliation and interpretation of Microsoft 365 audit records. See expert witness and neutral examinations.

Do you accept individual (non-corporate) matters?

Yes. Matrimonial, family, estate and personal-dispute matters that involve email evidence follow the same preservation and chain-of-custody procedures. We assess proportionality and scope before proceeding.

Do you handle internal corporate matters?

Yes. Trade-secret, executive-conduct, departing-employee, business-partner separation and other internal reviews follow the same evidence-preservation and reporting discipline as litigation work. See trade secret and employee forensics.

Can we work to our ESI stipulation?

Yes. We align collection, search, deduplication, review preparation and production to counsel-approved specifications, including metadata, attachments, text and load-file requirements. See our eDiscovery collections workstream.

Talk with an examiner

Discuss your matter and next step

Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Discuss the email evidence and next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Talk with an examiner

Discuss your matter and next step

Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.