A screenshot or forwarded message strips away technical context. GDF preserves native messages and the records around them, then correlates mailbox, cloud, identity, transport, and endpoint data. The approach supports authenticity disputes, eDiscovery, account compromise, insider activity, and delivery questions.
Preserve the tenant records before retention changes them
Microsoft 365 and Google Workspace contain multiple evidence sources with different availability and retention periods. Mailbox contents, message-trace data, unified audit logs, sign-in events, inbox rules, OAuth grants, administrative changes, and security alerts may not remain available on the same schedule. Availability depends on workload, license, audit configuration, retention policy, event age, and provider changes. A preservation plan records those conditions, legal holds, exports, and collection timestamps.
For litigation, the work can be aligned with eDiscovery data preservation and production requirements. For a security event, collection proceeds alongside containment so remediation does not erase the facts needed to understand entry, persistence, or misuse.
Authenticate, correlate, test
Email authentication results, routing headers, Message-IDs, MIME structure, server timestamps, and domain controls are examined together. A header can be forged; the conclusion depends on the full path and corroborating records. For suspected business email compromise, analysts also look for session anomalies, malicious forwarding, application consent, credential resets, unusual access, and payment-thread manipulation.
- Native MSG, EML, PST, MBOX, and supported cloud collections
- Mailbox rule, forwarding, delegate, and permission review
- Microsoft Entra and Google identity-event correlation
- Phishing path, sender-domain, and attachment analysis
- Chronologies prepared for counsel, insurers, and response teams
Explain the record without claiming more than it says
A successful login identifies an account event, not necessarily the person at the keyboard. IP reputation, geolocation, device identifiers, multifactor records, and user-agent data can narrow an explanation but may be shared, proxied, stale, or manipulated. A display name does not authenticate a sender. Reports separate those limits from the facts that can be established and identify any additional source that could resolve the gap.