Web-forensics use case

Forensic acquisition of email from a webmail interface

Eviquire Desktop Expert can support the documented acquisition of email evidence presented through an authorized browser-accessible webmail account. The workflow can preserve mailbox and folder context, messages and threads, visible addressing and time information, attachments, available message headers and native exports, investigator activity, hashes, timestamps, and custody records. It is not a mail-server acquisition tool and does not image mailbox databases, endpoint PST or OST files, or content that the authorized web interface does not expose.

What this use case means

Eviquire Desktop Expert can support the documented acquisition of email evidence presented through an authorized browser-accessible webmail account. The workflow can preserve mailbox and folder context, messages and threads, visible addressing and time information, attachments, available message headers and native exports, investigator activity, hashes, timestamps, and custody records. It is not a mail-server acquisition tool and does not image mailbox databases, endpoint PST or OST files, or content that the authorized web interface does not expose.

Webmail interfaces transform and organize email for convenient reading. They may group separate messages into conversations, collapse quoted text, hide full headers, load remote images, translate content, apply account-specific timezones, and expose only the messages permitted by the authenticated account. A defensible acquisition must preserve the message in its mailbox and conversation context while distinguishing the rendered web presentation, any downloaded native message, and authoritative provider or server-side records.

Common situations

When this workflow is useful

  • Preserving authorized business or personal email relevant to litigation, fraud, workplace, compliance, due-diligence, or criminal investigation
  • Documenting an email conversation, sender and recipient presentation, attachments, mailbox location, labels, and related thread context before access or retention changes
  • Creating a reviewable acquisition record when direct mail-server, provider API, eDiscovery, or endpoint mailbox acquisition is unavailable or outside the assigned scope

Recommended process

A documented acquisition workflow

  1. Confirm authority and mailbox scope

    Document the legal or organizational authority, mailbox and account owner, authorized credentials or delegated access, relevant folders, custodians, addresses, search terms, date range, messages, attachments, and exclusions before collection.

  2. Validate webmail access

    Confirm that the webmail interface works through Eviquire’s integrated browser with the required network or VPN, SSO, MFA, proxy, client certificate, region, and account permissions. Test access without beginning the formal evidential navigation where the procedure requires separation.

  3. Prepare the acquisition record

    Create the case and acquisition, identify the workstation, operating system, Eviquire version, investigator, webmail service and URL, authenticated account role, time source and timezone, network route, and required session-video or network options without recording passwords or authentication secrets.

  4. Establish mailbox and conversation context

    Navigate from the mailbox and relevant folder or search result to the specific conversation and message. Preserve folder or label, message position, thread participants, subject, displayed sender and recipients, visible date and time, and enough surrounding navigation to explain where the item originated.

  5. Expand and acquire the complete relevant message

    Expand quoted text, trimmed sections, recipient details, attachment lists, images, and relevant thread messages where authorized. Record missing remote content, warnings, blocked images, translations, condensed headers, or other transformations rather than implying that the rendered view is the raw message.

  6. Preserve headers, attachments, and native exports

    Use authorized portal functions to display or download available message headers, original-message or EML exports, attachments, print or PDF views, and related files. Preserve the supplied originals with hashes and document which investigator action generated each artifact.

  7. Verify, close, and transfer

    Confirm that expected messages and attachments are present, distinguish original downloads from rendered captures and working copies, close and verify the case, and transfer the preserved package under the approved chain-of-custody and independent-review procedure.

Technical guidance

Conditions that affect a webmail acquisition

Validate account authority, interface behavior, message completeness, export options, and time presentation before the formal acquisition.

Browser-based scope

A practical suitability test is whether the authorized mailbox and relevant messages can be opened and operated through a standards-based browser. Eviquire can document the webmail presentation and files made available through that interface.

  • Suitable: authorized browser-accessible webmail, including private enterprise mail reached through a corporate network or VPN.
  • Not directly acquired: mail-server stores, provider backends, local PST or OST files, endpoint mail clients, deleted items no longer exposed, and data outside the account’s permissions.
  • Use mail-server, provider API, eDiscovery, cloud-forensic, or endpoint methods when the assignment requires those underlying sources.

Authentication, account role, and access

The authenticated user, delegated role, mailbox permissions, tenant policy, region, network route, and security controls can change what the interface exposes. Use the normal authorized login procedure and test SSO, MFA, VPN, proxy, and certificate requirements before formal collection.

  • Record the account or delegated role without exposing passwords, session tokens, recovery data, or MFA secrets.
  • Document shared-mailbox, archive, delegated, legal-hold, or administrator access when it affects the visible evidence.
  • Do not infer that an unavailable folder or message does not exist outside the permissions of the acquired account.

Threads and rendered message content

A webmail conversation view may combine multiple independently transmitted messages, hide repeated quoted content, shorten addresses, suppress external images, or display a cleaned HTML representation. Preserve both the relevant thread context and each specific message needed for review.

  • Expand trimmed or quoted content where relevant and record whether it was initially collapsed.
  • Capture complete sender, reply-to, recipient, CC and BCC presentation when the interface lawfully exposes it.
  • Document translations, remote-image loading, phishing warnings, safe-link rewriting, blocked content, and other interface transformations.

Headers and native message exports

Visible From, To, subject and date fields are not the same as the complete transport headers or raw message source. When the portal provides an authorized 'show original', 'view source', download, or EML function, preserve that artifact separately and connect it to the displayed message.

  • Prefer the portal’s native original-message or EML export when available.
  • Record whether headers were displayed in the interface, downloaded as a file, or unavailable.
  • Do not claim that a print view, screenshot, PDF, or session video is a bit-for-bit copy of the transmitted email.

Attachments and linked content

Preserve authorized attachments as separate downloaded artifacts where possible, together with their displayed names, sizes, message relationship, hashes, and acquisition action. Links, cloud-file references, embedded objects, and remote images may point to content outside the message itself and may require separate authority or acquisition.

  • Retain the original attachment before conversion, preview, annotation, redaction, or analysis.
  • Document preview-only files, password-protected archives, blocked attachments, unavailable links, and malware warnings.
  • Treat a linked cloud document as a separate source unless the preserved message contains the file itself.

Time interpretation, corroboration, and review

A webmail interface may display time according to the user profile, mailbox setting, browser, workstation, tenant, or sender metadata. Preserve the displayed time and timezone and compare them with native headers when important. Acquisition timestamping protects the collected artifact; it does not prove when the original email was sent or received.

  • Distinguish displayed message time, header dates, server receipt times, file timestamps, and acquisition time.
  • Correlate disputed delivery, routing, authorship, deletion, or access with mail-server logs, provider records, audit logs, endpoint evidence, or other authoritative sources.
  • Preserve the original package and perform later search, redaction, conversion, or production on controlled copies.

Reviewable output

What the evidence package should explain

Mailbox and conversation context

The account role, mailbox or folder, search or navigation path, thread, subject, participants, message position, and surrounding interface explain where the email was found.

Rendered message record

Screenshots, pageshots, session video, expanded content, visible addressing, dates, warnings, and interface state document what the investigator observed.

Native messages and attachments

Available EML or original-message exports, headers, attachments, print views, and related downloads can be preserved separately with hashes and their acquisition relationship.

Integrity and review package

Acquisition metadata, timestamps, activity and custody records, reports, and the closed case support controlled transfer and independent examination.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • Email can contain privileged, confidential, regulated, personal, financial, health, employment, and third-party information. Define necessity, custodians, date ranges, search terms, exclusions, access, retention, redaction, and disclosure before collection.
  • A webmail acquisition preserves what the authorized interface presented and exported; it does not independently prove authorship, delivery, receipt, account control, message truth, or absence of undisclosed server-side content.
  • Do not claim completeness when messages, folders, quoted content, remote resources, attachments, headers, archives, deleted items, or audit records were unavailable or outside the account’s permissions.
  • Avoid altering mailbox state unnecessarily. Actions such as marking messages read, changing labels, downloading remote content, following links, or opening attachments may affect the account, external systems, or security posture and should follow the approved procedure.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

Can Eviquire acquire email from a webmail account?

Yes, when the mailbox is authorized and accessible through Eviquire’s integrated browser. Eviquire can preserve the webmail presentation, acquisition activity, available headers and downloads, attachments, hashes, timestamps, and custody records.

Is a screenshot of an email the original message?

No. It documents the rendered webmail view. When available, preserve the portal’s original-message or EML export and complete headers as separate artifacts.

Can Eviquire acquire a PST, OST, mail server, or provider backend?

No. Those sources require an appropriate endpoint, mail-server, provider API, eDiscovery, or cloud-forensic acquisition method. Eviquire’s role here is authorized web-interface acquisition.

Should the entire conversation thread be captured?

Preserve enough authorized thread context to explain the relevant message and relationships, while applying scope and minimization. Each evidentially important message should remain individually identifiable.

What should be done with attachments?

Download authorized attachments through the webmail workflow when appropriate, preserve the original files, record their relationship to the message, calculate hashes, and use controlled copies for analysis or conversion.

Do displayed dates prove when an email was sent?

No. The interface date is one source of information. Important timing should be examined with native message headers, server receipt data, provider or audit records, timezone settings, and other corroborating evidence.

Can opening an email change evidence?

It can change read status or trigger remote content, security scanning, link rewriting, or other account activity. Document the starting state and use an approved procedure designed to minimize and explain investigator-caused changes.

Can another examiner review the acquisition?

Yes. After closure and integrity verification, the preserved case and artifacts can be transferred under the approved custody procedure, reviewed with the Portable Viewer where applicable, or imported into another authorized Eviquire Desktop Expert installation.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.