As an expert witness in the email forensics field, I get asked to examine various types of digital evidence. Not all email evidence is equal however.

For example, in a recent email expert witness case, I was asked to look these different types of email evidence:

  • PDF copy of an email
  • Screenshot of an email
  • EML copy of an email

Expert Forensic Evidence | Screenshot Email Copy

For the above types, the screenshot copy is the weakest type of email evidence, as the underlying headers cannot be examined. It is easy to fabricate a screenshot of an email.

Expert Forensic Evidence | PDF Email Copy

The PDF copy is also weak evidentially. Similar to the screenshot, the underlying message headers cannot be examined.

Expert Forensic Evidence | EML File

To determine if an email is fraudulent or not, an .EML copy would be the minimum level of evidence to examine. The EML format is supported by the internet message standards.

If one party has an EML file of an email, then this will have a higher evidence weighting compared to a PDF or screenshot.

EML File and Hash Value

If an EML file is provided as evidence, awareness is requried over the fact that it can be edited. EML files are text based and can be manipulated. An EML file together with access to supporting email delivery logs would be strong evidence. A hash value should be taken of any electronic evidence file – this forms a digital (time-based) fingerprint value. Any further edit of the EML file would result in a different hash value, showing it had been edited.

Expert Forensic Evidence | Email Transport Logs

Ideally, this would be supported by the SMTP message transaction logs from the sending and/or the receiving email systems. For cloud email systems, transaction logs may not be available beyond a certain timeframe.

Email Fraud Investigation | Hire Rob Walton

If you have a case which requires an email expert witness to examine an email to determine its provenance, then please contact Rob Walton.