ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

Email / Microsoft 365 / Google Workspace

The message is only one part of the email record

Headers, mailbox state, tenant audit events, identity logs, transport records, and endpoint artifacts can show how a message moved and which accounts or sessions had access. They do not necessarily identify the person operating an account.

eDiscovery record flow from source mapping and preservation through collection, review, and production
Mailbox content, identity, audit, transport, and endpoints form one email record.

A screenshot or forwarded message strips away technical context. GDF preserves native messages and the records around them, then correlates mailbox, cloud, identity, transport, and endpoint data. The approach supports authenticity disputes, eDiscovery, account compromise, insider activity, and delivery questions.

Preserve the tenant records before retention changes them

Microsoft 365 and Google Workspace contain multiple evidence sources with different availability and retention periods. Mailbox contents, message-trace data, unified audit logs, sign-in events, inbox rules, OAuth grants, administrative changes, and security alerts may not remain available on the same schedule. Availability depends on workload, license, audit configuration, retention policy, event age, and provider changes. A preservation plan records those conditions, legal holds, exports, and collection timestamps.

For litigation, the work can be aligned with eDiscovery data preservation and production requirements. For a security event, collection proceeds alongside containment so remediation does not erase the facts needed to understand entry, persistence, or misuse.

Authenticate, correlate, test

Email authentication results, routing headers, Message-IDs, MIME structure, server timestamps, and domain controls are examined together. A header can be forged; the conclusion depends on the full path and corroborating records. For suspected business email compromise, analysts also look for session anomalies, malicious forwarding, application consent, credential resets, unusual access, and payment-thread manipulation.

  • Native MSG, EML, PST, MBOX, and supported cloud collections
  • Mailbox rule, forwarding, delegate, and permission review
  • Microsoft Entra and Google identity-event correlation
  • Phishing path, sender-domain, and attachment analysis
  • Chronologies prepared for counsel, insurers, and response teams

Explain the record without claiming more than it says

A successful login identifies an account event, not necessarily the person at the keyboard. IP reputation, geolocation, device identifiers, multifactor records, and user-agent data can narrow an explanation but may be shared, proxied, stale, or manipulated. A display name does not authenticate a sender. Reports separate those limits from the facts that can be established and identify any additional source that could resolve the gap.

Preserve an email or cloud record

Tell us what is disputed, which devices or systems may hold the answer, and the next deadline. Counsel retains all legal decisions.

Contact GDF