Outlook, Microsoft 365 and email evidence

Email & Microsoft 365 Forensics

Do you conduct email forensic examinations, email tracking and email eDiscovery? Yes. GDF forensically collects and analyzes Outlook, Microsoft 365 and other email stores, preserving their evidentiary value.

Bagged hard drive beside a forensic write blocker.

Collect the messages, files and activity behind the case

Scope: Accounts, dates, files and logs; Preserve: Messages, attachments and records; Correlate: Headers, activity and timelines; Explain: Findings, reports, and exhibits.
Scope · Preserve · Correlate · Explain

GDF collects mailboxes, Outlook email files, attachments, OneDrive and SharePoint documents, and relevant account activity logs. We authenticate disputed messages, trace communication and prepare email for review and production under agreed ESI stipulations.

Our email practice has collected thousands of mailboxes and includes hundreds of email-related depositions and testimony engagements. We explain the findings in language attorneys, business leaders, judges and juries can understand.

Remote collection while users keep working

  1. Define the scope. Identify the accounts, relevant dates, associated files and discovery requirements.
  2. Coordinate access. Work with the authorized account owner or administrator to arrange collection.
  3. Collect and preserve. Capture original email, attachments and agreed files and logs, with documented handling and integrity checks.
  4. Confirm the evidence inventory. Organize the sources and collected material for analysis or review.

Routine remote collection allows users to continue using their email accounts. We coordinate the work around your client's schedule and the case deadline.

Discuss your email evidence and deadline

Need to authenticate an email, trace a message or collect Microsoft 365 for discovery? Tell us which accounts and dates matter so we can plan remote collection and the analysis you need.

Get a free consultation Call 1-800-868-8189

Trace the attack across Microsoft 365

A compromised email account can expose more than the inbox. Depending on its permissions and the access obtained, the same identity may reach OneDrive files, SharePoint libraries, Teams conversations and shared business records. Examining one mailbox alone can leave important parts of the incident unexplained. Microsoft describes this wider account-compromise risk.

Connect the records into a single evidence timeline

GDF correlates available Microsoft Entra sign-in and audit records with Exchange mailbox activity, Microsoft Purview audit events, SharePoint and OneDrive file activity, and relevant Teams records. We connect account, application, session and file identifiers where recorded, align timestamps, and retain the original exports so each finding can be traced to its source.

That timeline helps test what happened before, during and after the suspicious access: which identity or application acted, what resources were involved, and whether the records show file access, downloads, sharing changes or other activity. Automated synchronization, legitimate user actions and response-team changes must be distinguished from attacker activity. Microsoft audit-event reference.

Follow access to shared data

One compromised identity may have access to documents owned by other people, shared libraries or files linked through Teams. We assess relevant group memberships, sharing links, delegated access and application permissions alongside the activity records. The question is both what the identity could reach and what the evidence shows it actually did.

For example, a suspicious sign-in followed by downloads from a shared library can expand the examination beyond that user's mailbox. A permission granting access to the library, by itself, does not prove its contents were taken.

Define the scope and the limits

The result is a connected account of affected identities, systems and data, supported by an evidence timeline, an information inventory and stated gaps. We identify confirmed activity, potential exposure requiring further analysis and questions the available records cannot resolve.

Coverage depends on licensing, audit configuration, retention, collection timing and the events each service records. Missing events do not prove that no access occurred, and an IP address alone does not identify a person. Preserve the available records promptly while coordinating containment. Microsoft audit availability and retention guidance.

Authenticate email and map communication

We compare original messages, headers, timestamps, message identifiers, attachments and related sender or recipient records. The examination tests the message's authenticity and explains the supporting findings.

Email tracking reconstructs message handling and communication through routing, delivery and related activity records. Relationship maps organize recorded exchanges between people and accounts, showing when they communicated and which messages connect them.

For example, a communication map can connect a project email, its recipients and subsequent messages containing the same attachment. A report can present that sequence alongside the original records and relevant dates. This illustrates the work product we can prepare for the questions in your case.

Use Microsoft 365 logs to explain account activity

Sign-ins, mailbox actions, delivery information, forwarding rules, permissions and file events help explain activity around an email or account. We identify the retained records and correlate them with messages and device evidence.

Microsoft's mail-access documentation describes the distinction between recorded access and synchronization events. Our findings explain the events actually recorded and how they connect to the examination.

Someone sent email from your account or changed invoice payment details? Read our plain-English guide to business email compromise analysis.

For a hacked mailbox, use our business email takeover service to examine the attack path, phishing, data access and persistence.

Control eDiscovery work and prepare usable production

We help counsel define custodians, dates, keyword searches and production specifications. Our internal tools support collection, deduplication, appropriate system-file filtering, review preparation and load-file creation. Those workflows reduce repetitive processing and unnecessary review.

A load file connects documents and metadata to the agreed review platform. The production can include original files, attachments, text and specified fields, with a documented connection to the collected evidence. Explore eDiscovery assistance and cost-effective hosting.

What an email forensic report explains

  • The question, accounts and time period examined.
  • The collection process and evidence inventory.
  • The authentication findings or communication timeline.
  • Relevant account activity and supporting records.
  • Exhibits that explain the technical findings to the intended audience.

In COMLAB v. Kal Tire, GDF provided expert testimony concerning disputed email and document evidence. The published case study explains the examination and the court's findings. Our expert witness service supports reports, affidavits, deposition and trial testimony.

For Gmail and Drive, see Google Workspace email forensics. For an employee departure, explore flat-rate Core Analysis.

One message, and the records around it

An email dispute starts with a single message. Was it sent? Was it altered? Did the recipient actually read it? The answer almost never sits in the message itself. It sits in the delivery records, the identity logs, the mailbox audit trail, the file activity and whatever cloud evidence still exists. Email and Microsoft 365 forensics at GDF connects the native message to all of it and explains what the combined record supports and what it does not.

Our email practice has collected thousands of mailboxes and supported hundreds of email-related deposition and testimony engagements. After that many, you develop a sense for when a simple-sounding question ("did he get the email?") actually requires a different source or a much more careful reading of the logs.

Is the message real, and who was using the account

Those are two different questions and we keep them apart until the end. The display name on a message proves nothing about who sent it. Native message structure, routing headers, message identifiers, attachments and any corroborating copies on other systems let us assess authenticity. Domain authentication results (SPF, DKIM and similar checks) provide useful context about the sending infrastructure. They do not tell you which human was at the keyboard or what they intended.

Account access is its own analysis. A successful sign-in records that a credential was accepted under certain conditions. Device identifiers, session context, the network address and what the session did next all strengthen or undercut the explanation for who was behind it.

Keeping the questions separate matters because the answers combine in more than one way. A message can be genuine while the account that sent it was hijacked. A message can also be authentic as sent and altered after export. The examination establishes which proposition the evidence can actually reach, then puts the pieces together.

Reading Microsoft 365 audit events for what they record

Microsoft 365 keeps several different records for several different purposes. Message trace covers transport: did the message move from here to there. Identity logs cover authentication and the context of each sign-in. Mailbox audit events describe actions taken on mail items. OneDrive and SharePoint records add file access, sharing and version history. Confusing one for another is how a chronology goes wrong.

The MailItemsAccessed event is a good example. It distinguishes between a sync operation, where a client downloaded mailbox content in bulk, and a bind, where an individual item was accessed. A sync entry does not mean a person read each message on screen. It means a client fetched them. We interpret each event within its session and account context instead of treating every audit line as proof of human reading. Reports that skip that step tend to overstate what was read.

Availability is the other constraint. Which logs exist depends on the license tier, the tenant configuration, the retention settings and how old the event is. We document those conditions at collection. A litigation hold on the mailbox should not be assumed to preserve the sign-in logs or the audit trail, which run on their own retention clocks. Early collection planning is frequently the difference between having the log and having a gap where the log used to be.

Attachments and linked documents are different evidence

A message can carry a fixed copy of a document or a link to a cloud file that kept changing after the email was sent. A useful collection plan identifies the linked file and its relevant versions, plus the sharing and activity history around it, rather than assuming the mailbox contains the whole story.

Say a payment instruction is discussed in a genuine thread, and the linked spreadsheet with the bank details is edited two days later. The thread alone tells you nothing about the edit. The document version history alone tells you nothing about who was told what. GDF connects both within the agreed scope and shows the supporting records side by side in the report.

Case material your team can use

Deliverables include a message chronology, a communication map, authenticity findings and supporting exhibits, with production sets prepared to agreed specifications. The report states which accounts and periods were examined and identifies every gap that bears on the conclusion.

If the matter is a suspected account takeover, ask us about the separate business email takeover service. For litigation collection, the scope can coordinate preservation and review preparation from the start. Either way, you get the right evidence and the analysis that explains it, rather than a mailbox export and a shrug.

Evidence reviewed

  • Authorized accounts, files and messages within scope
  • Relevant activity logs and supporting device records
  • Collection and chain-of-custody documentation

What you receive

  • Evidence inventory and documented findings
  • Activity timelines and relevant exhibits
  • Review-ready material, reports and expert support

Reviewed by Joseph Caruso. .

Examiners who can explain the evidence

Robert Knudsen, GDF's Northeast Regional Manager, brings experience in computer examinations, forensic acquisition, evidence handling and expert testimony. Collection records and clear findings give counsel a basis for the next discovery or reporting decision.

Meet our forensic experts and request a CV

Frequently asked

Common questions

Does an access event prove someone read the message?

Not on its own. We look at the event type, the coverage of the collection and the surrounding records before saying what the event shows.

Can you examine documents linked from email?

Yes, where authorized and available. Linked sources and their relevant versions are identified separately in the collection scope so they are not assumed to be in the mailbox.

Should we wait until the dispute is fully defined?

No. Call when records might expire or accounts might change. A focused preservation step now costs far less than a gap in the audit log later.

Can users keep using Outlook during collection?

Yes. Routine remote collection allows users to continue using their email accounts. We arrange authorized access and the collection plan with the account owner or administrator.

Can you determine whether an email is real or altered?

Yes. GDF examines original messages, headers, attachments and supporting records to authenticate email and explain the findings.

Can you collect OneDrive and SharePoint documents too?

Yes. We can include relevant files, versions and available activity records in the agreed scope alongside the email collection.

Can you build relationship maps from email?

Yes. We can organize recorded communication between people and accounts by date, message and attachment, with supporting evidence for the relationships shown in the map.

Can you follow our ESI stipulation?

Yes. We work with counsel on collection, search and production requirements, including metadata, attachments, text and load-file specifications.

Do you provide reports and testimony?

Yes. Our email forensic work can include an expert report, exhibits, affidavits, deposition and trial testimony. Our practice includes hundreds of email-related deposition and testimony engagements.

Put GDF on the email record

Put GDF on the email record before messages, logs or account history get harder to preserve. Tell us the accounts, the disputed activity, the date range, the systems involved and your deadline. We can discuss preservation, remote collection, email and Microsoft 365 forensics analysis, authenticity review, reports, exhibits and expert support. Your initial consultation is free.

Put GDF on the email record

Related services and resources: business email takeover forensics, Google Workspace email forensics, eDiscovery collections, computer forensics expert witness, COMLAB v Kal Tire.

Discuss the email evidence in your matter

Find regional collection and engagement information or meet the forensic team. Ask about the collection method and report format that fit your matter.

Discuss your email evidence and deadline

Call to discuss your next step and arrange secure information sharing.

Get a free consultation Call 1-800-868-8189

Talk with an examiner

Discuss your matter and next step

Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.