Email, Microsoft 365, Google Workspace

Email & Microsoft 365 Forensics

The message is only one part of the email record. Headers, mailbox state, tenant audit events, identity logs, transport records, and endpoint artifacts can show how a message moved and which accounts or sessions had access.

Bagged hard drive beside a forensic write blocker.

The engagement

Preserve tenant records before retention changes them

A screenshot or forwarded message strips away technical context. GDF preserves native messages and the records around them, then correlates mailbox, cloud, identity, transport, and endpoint data. The approach supports authenticity disputes, eDiscovery, account compromise, insider activity, and delivery questions.

Microsoft 365 and Google Workspace contain multiple evidence sources with different availability and retention periods. Mailbox contents, message-trace data, unified audit logs, sign-in events, inbox rules, OAuth grants, administrative changes, and security alerts may not remain available on the same schedule.

For litigation, the work can be aligned with eDiscovery data preservation and production requirements. For a security event, collection proceeds alongside containment so remediation does not erase the facts needed to understand entry, persistence, or misuse.

Scope

  • Native message preservation

    MSG, EML, PST, and MBOX preserved with hash, source, and collection notes. Native format retained so headers and attachments remain examinable.

  • Mailbox and rule review

    Mailbox rule, forwarding, delegate, and permission review. OAuth application grants and administrative changes reviewed against the relevant period.

  • Microsoft 365 tenant collection

    Message trace, unified audit log, sign-in and identity events, application consent, security alerts, and supported Purview collections.

  • Google Workspace collection

    Gmail messages, admin audit, login events, and application-level records preserved with collection parameters documented.

  • Authentication and header analysis

    SPF, DKIM, DMARC results, routing headers, Message-IDs, MIME structure, and server timestamps examined together. Conclusions rely on the full path and corroborating records.

  • Business email compromise support

    Session anomaly review, malicious forwarding detection, application consent audit, credential and MFA event review, and payment-thread reconstruction.

Methodology

How email work runs

  1. Preserve

    Native messages and tenant records are collected under the client's approved access process. Short-retention sources are prioritized.

  2. Authenticate

    Authentication results, routing headers, Message-IDs, MIME structure, server timestamps, and domain controls are examined together.

  3. Correlate

    Mailbox activity, identity events, endpoint records, and administrative changes are placed on one chronology with time-zone conventions stated.

  4. Report

    Findings distinguish confirmed events, likely explanations, unresolved alternatives, and the limits of the available records.

Evidence commonly examined

Evidence reviewed

  • Native MSG, EML, PST, MBOX exports
  • Message trace and transport records
  • Unified audit and sign-in logs
  • Inbox rules, delegates, forwarding, and OAuth grants
  • Endpoint artifacts, browser history, and MFA records
  • Phishing infrastructure, domain, and DNS records

What you can expect

What you receive

  • Authentication analysis with the full path documented
  • Cross-source timeline with time-zone conventions stated
  • Rule, forwarding, delegate, and consent findings
  • Chronology prepared for counsel, insurers, and response teams
  • Documented limits: retention, workload, license, and provider constraints

Frequently asked

Common questions

Can you authenticate an email from a forwarded copy alone?

Sometimes. Conclusions depend on the retained headers, mailbox records, and server logs. A forwarded copy strips information; native messages and server-side records typically support stronger conclusions.

Does a successful login identify the person at the keyboard?

No. A login identifies an account event. IP reputation, geolocation, device identifiers, multifactor records, and user-agent data can narrow explanation but may be shared, proxied, stale, or manipulated.

How do you support business email compromise response?

Preserve native messages, headers, message trace, mailbox audit, sign-ins, authentication changes, inbox and transport rules, delegates, application consent, security alerts, device records, and administrator actions while each source is still available.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.