Email, Microsoft 365, Google Workspace
Email & Microsoft 365 Forensics
The message is only one part of the email record. Headers, mailbox state, tenant audit events, identity logs, transport records, and endpoint artifacts can show how a message moved and which accounts or sessions had access.
The engagement
Preserve tenant records before retention changes them
A screenshot or forwarded message strips away technical context. GDF preserves native messages and the records around them, then correlates mailbox, cloud, identity, transport, and endpoint data. The approach supports authenticity disputes, eDiscovery, account compromise, insider activity, and delivery questions.
Microsoft 365 and Google Workspace contain multiple evidence sources with different availability and retention periods. Mailbox contents, message-trace data, unified audit logs, sign-in events, inbox rules, OAuth grants, administrative changes, and security alerts may not remain available on the same schedule.
For litigation, the work can be aligned with eDiscovery data preservation and production requirements. For a security event, collection proceeds alongside containment so remediation does not erase the facts needed to understand entry, persistence, or misuse.
Scope
Native message preservation
MSG, EML, PST, and MBOX preserved with hash, source, and collection notes. Native format retained so headers and attachments remain examinable.
Mailbox and rule review
Mailbox rule, forwarding, delegate, and permission review. OAuth application grants and administrative changes reviewed against the relevant period.
Microsoft 365 tenant collection
Message trace, unified audit log, sign-in and identity events, application consent, security alerts, and supported Purview collections.
Google Workspace collection
Gmail messages, admin audit, login events, and application-level records preserved with collection parameters documented.
Authentication and header analysis
SPF, DKIM, DMARC results, routing headers, Message-IDs, MIME structure, and server timestamps examined together. Conclusions rely on the full path and corroborating records.
Business email compromise support
Session anomaly review, malicious forwarding detection, application consent audit, credential and MFA event review, and payment-thread reconstruction.
Methodology
How email work runs
-
Preserve
Native messages and tenant records are collected under the client's approved access process. Short-retention sources are prioritized.
-
Authenticate
Authentication results, routing headers, Message-IDs, MIME structure, server timestamps, and domain controls are examined together.
-
Correlate
Mailbox activity, identity events, endpoint records, and administrative changes are placed on one chronology with time-zone conventions stated.
-
Report
Findings distinguish confirmed events, likely explanations, unresolved alternatives, and the limits of the available records.
Evidence commonly examined
Evidence reviewed
- Native MSG, EML, PST, MBOX exports
- Message trace and transport records
- Unified audit and sign-in logs
- Inbox rules, delegates, forwarding, and OAuth grants
- Endpoint artifacts, browser history, and MFA records
- Phishing infrastructure, domain, and DNS records
What you can expect
What you receive
- Authentication analysis with the full path documented
- Cross-source timeline with time-zone conventions stated
- Rule, forwarding, delegate, and consent findings
- Chronology prepared for counsel, insurers, and response teams
- Documented limits: retention, workload, license, and provider constraints
Frequently asked
Common questions
Can you authenticate an email from a forwarded copy alone?
Sometimes. Conclusions depend on the retained headers, mailbox records, and server logs. A forwarded copy strips information; native messages and server-side records typically support stronger conclusions.
Does a successful login identify the person at the keyboard?
No. A login identifies an account event. IP reputation, geolocation, device identifiers, multifactor records, and user-agent data can narrow explanation but may be shared, proxied, stale, or manipulated.
How do you support business email compromise response?
Preserve native messages, headers, message trace, mailbox audit, sign-ins, authentication changes, inbox and transport rules, delegates, application consent, security alerts, device records, and administrator actions while each source is still available.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189