Web-forensics use case
Forensic acquisition of email from a webmail interface
Eviquire Desktop Expert can support the documented acquisition of email evidence presented through an authorized browser-accessible webmail account. The workflow can preserve mailbox and folder context, messages and threads, visible addressing and time information, attachments, available message headers and native exports, investigator activity, hashes, timestamps, and custody records. It is not a mail-server acquisition tool and does not image mailbox databases, endpoint PST or OST files, or content that the authorized web interface does not expose.
What this use case means
Eviquire Desktop Expert can support the documented acquisition of email evidence presented through an authorized browser-accessible webmail account. The workflow can preserve mailbox and folder context, messages and threads, visible addressing and time information, attachments, available message headers and native exports, investigator activity, hashes, timestamps, and custody records. It is not a mail-server acquisition tool and does not image mailbox databases, endpoint PST or OST files, or content that the authorized web interface does not expose.
Webmail interfaces transform and organize email for convenient reading. They may group separate messages into conversations, collapse quoted text, hide full headers, load remote images, translate content, apply account-specific timezones, and expose only the messages permitted by the authenticated account. A defensible acquisition must preserve the message in its mailbox and conversation context while distinguishing the rendered web presentation, any downloaded native message, and authoritative provider or server-side records.
Common situations
When this workflow is useful
- Preserving authorized business or personal email relevant to litigation, fraud, workplace, compliance, due-diligence, or criminal investigation
- Documenting an email conversation, sender and recipient presentation, attachments, mailbox location, labels, and related thread context before access or retention changes
- Creating a reviewable acquisition record when direct mail-server, provider API, eDiscovery, or endpoint mailbox acquisition is unavailable or outside the assigned scope
Recommended process
A documented acquisition workflow
- Confirm authority and mailbox scope
Document the legal or organizational authority, mailbox and account owner, authorized credentials or delegated access, relevant folders, custodians, addresses, search terms, date range, messages, attachments, and exclusions before collection.
- Validate webmail access
Confirm that the webmail interface works through Eviquire’s integrated browser with the required network or VPN, SSO, MFA, proxy, client certificate, region, and account permissions. Test access without beginning the formal evidential navigation where the procedure requires separation.
- Prepare the acquisition record
Create the case and acquisition, identify the workstation, operating system, Eviquire version, investigator, webmail service and URL, authenticated account role, time source and timezone, network route, and required session-video or network options without recording passwords or authentication secrets.
- Establish mailbox and conversation context
Navigate from the mailbox and relevant folder or search result to the specific conversation and message. Preserve folder or label, message position, thread participants, subject, displayed sender and recipients, visible date and time, and enough surrounding navigation to explain where the item originated.
- Expand and acquire the complete relevant message
Expand quoted text, trimmed sections, recipient details, attachment lists, images, and relevant thread messages where authorized. Record missing remote content, warnings, blocked images, translations, condensed headers, or other transformations rather than implying that the rendered view is the raw message.
- Preserve headers, attachments, and native exports
Use authorized portal functions to display or download available message headers, original-message or EML exports, attachments, print or PDF views, and related files. Preserve the supplied originals with hashes and document which investigator action generated each artifact.
- Verify, close, and transfer
Confirm that expected messages and attachments are present, distinguish original downloads from rendered captures and working copies, close and verify the case, and transfer the preserved package under the approved chain-of-custody and independent-review procedure.
Technical guidance
Conditions that affect a webmail acquisition
Validate account authority, interface behavior, message completeness, export options, and time presentation before the formal acquisition.
Browser-based scope
A practical suitability test is whether the authorized mailbox and relevant messages can be opened and operated through a standards-based browser. Eviquire can document the webmail presentation and files made available through that interface.
- Suitable: authorized browser-accessible webmail, including private enterprise mail reached through a corporate network or VPN.
- Not directly acquired: mail-server stores, provider backends, local PST or OST files, endpoint mail clients, deleted items no longer exposed, and data outside the account’s permissions.
- Use mail-server, provider API, eDiscovery, cloud-forensic, or endpoint methods when the assignment requires those underlying sources.
Authentication, account role, and access
The authenticated user, delegated role, mailbox permissions, tenant policy, region, network route, and security controls can change what the interface exposes. Use the normal authorized login procedure and test SSO, MFA, VPN, proxy, and certificate requirements before formal collection.
- Record the account or delegated role without exposing passwords, session tokens, recovery data, or MFA secrets.
- Document shared-mailbox, archive, delegated, legal-hold, or administrator access when it affects the visible evidence.
- Do not infer that an unavailable folder or message does not exist outside the permissions of the acquired account.
Threads and rendered message content
A webmail conversation view may combine multiple independently transmitted messages, hide repeated quoted content, shorten addresses, suppress external images, or display a cleaned HTML representation. Preserve both the relevant thread context and each specific message needed for review.
- Expand trimmed or quoted content where relevant and record whether it was initially collapsed.
- Capture complete sender, reply-to, recipient, CC and BCC presentation when the interface lawfully exposes it.
- Document translations, remote-image loading, phishing warnings, safe-link rewriting, blocked content, and other interface transformations.
Headers and native message exports
Visible From, To, subject and date fields are not the same as the complete transport headers or raw message source. When the portal provides an authorized 'show original', 'view source', download, or EML function, preserve that artifact separately and connect it to the displayed message.
- Prefer the portal’s native original-message or EML export when available.
- Record whether headers were displayed in the interface, downloaded as a file, or unavailable.
- Do not claim that a print view, screenshot, PDF, or session video is a bit-for-bit copy of the transmitted email.
Attachments and linked content
Preserve authorized attachments as separate downloaded artifacts where possible, together with their displayed names, sizes, message relationship, hashes, and acquisition action. Links, cloud-file references, embedded objects, and remote images may point to content outside the message itself and may require separate authority or acquisition.
- Retain the original attachment before conversion, preview, annotation, redaction, or analysis.
- Document preview-only files, password-protected archives, blocked attachments, unavailable links, and malware warnings.
- Treat a linked cloud document as a separate source unless the preserved message contains the file itself.
Time interpretation, corroboration, and review
A webmail interface may display time according to the user profile, mailbox setting, browser, workstation, tenant, or sender metadata. Preserve the displayed time and timezone and compare them with native headers when important. Acquisition timestamping protects the collected artifact; it does not prove when the original email was sent or received.
- Distinguish displayed message time, header dates, server receipt times, file timestamps, and acquisition time.
- Correlate disputed delivery, routing, authorship, deletion, or access with mail-server logs, provider records, audit logs, endpoint evidence, or other authoritative sources.
- Preserve the original package and perform later search, redaction, conversion, or production on controlled copies.
Reviewable output
What the evidence package should explain
Mailbox and conversation context
The account role, mailbox or folder, search or navigation path, thread, subject, participants, message position, and surrounding interface explain where the email was found.
Rendered message record
Screenshots, pageshots, session video, expanded content, visible addressing, dates, warnings, and interface state document what the investigator observed.
Native messages and attachments
Available EML or original-message exports, headers, attachments, print views, and related downloads can be preserved separately with hashes and their acquisition relationship.
Integrity and review package
Acquisition metadata, timestamps, activity and custody records, reports, and the closed case support controlled transfer and independent examination.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Email can contain privileged, confidential, regulated, personal, financial, health, employment, and third-party information. Define necessity, custodians, date ranges, search terms, exclusions, access, retention, redaction, and disclosure before collection.
- A webmail acquisition preserves what the authorized interface presented and exported; it does not independently prove authorship, delivery, receipt, account control, message truth, or absence of undisclosed server-side content.
- Do not claim completeness when messages, folders, quoted content, remote resources, attachments, headers, archives, deleted items, or audit records were unavailable or outside the account’s permissions.
- Avoid altering mailbox state unnecessarily. Actions such as marking messages read, changing labels, downloading remote content, following links, or opening attachments may affect the account, external systems, or security posture and should follow the approved procedure.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can Eviquire acquire email from a webmail account?
Yes, when the mailbox is authorized and accessible through Eviquire’s integrated browser. Eviquire can preserve the webmail presentation, acquisition activity, available headers and downloads, attachments, hashes, timestamps, and custody records.
Is a screenshot of an email the original message?
No. It documents the rendered webmail view. When available, preserve the portal’s original-message or EML export and complete headers as separate artifacts.
Can Eviquire acquire a PST, OST, mail server, or provider backend?
No. Those sources require an appropriate endpoint, mail-server, provider API, eDiscovery, or cloud-forensic acquisition method. Eviquire’s role here is authorized web-interface acquisition.
Should the entire conversation thread be captured?
Preserve enough authorized thread context to explain the relevant message and relationships, while applying scope and minimization. Each evidentially important message should remain individually identifiable.
What should be done with attachments?
Download authorized attachments through the webmail workflow when appropriate, preserve the original files, record their relationship to the message, calculate hashes, and use controlled copies for analysis or conversion.
Do displayed dates prove when an email was sent?
No. The interface date is one source of information. Important timing should be examined with native message headers, server receipt data, provider or audit records, timezone settings, and other corroborating evidence.
Can opening an email change evidence?
It can change read status or trigger remote content, security scanning, link rewriting, or other account activity. Document the starting state and use an approved procedure designed to minimize and explain investigator-caused changes.
Can another examiner review the acquisition?
Yes. After closure and integrity verification, the preserved case and artifacts can be transferred under the approved custody procedure, reviewed with the Portable Viewer where applicable, or imported into another authorized Eviquire Desktop Expert installation.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law enforcement
Preserve volatile online evidence for authorized criminal and intelligence investigations.
See role-specific guidance →Law firms
Preserve websites and online content for litigation, disclosure, legal holds, and expert review.
See role-specific guidance →In-house legal teams
Preserve early evidence for disputes, compliance, legal holds, and outside-counsel review.
See role-specific guidance →