The core preservation principles for email are no different from those that apply to any digital evidence, but the environment is unusually hostile: mailboxes are actively curated by their users, automatically pruned by retention policies, and — in the case of departing employees — routinely deleted as a matter of standard IT practice within days of an exit interview. Getting instructions in early, and issuing a litigation hold before anything else, is the difference between a defensible investigation and an apology to the tribunal.
The first steps on any matter with email in issue
- 01Issue a written litigation hold. Named custodians, named mailboxes, named third-party providers (Microsoft 365 tenant admin, Google Workspace admin, hosted Exchange provider). Written, dated, and acknowledged in writing by the recipient.
- 02Suspend retention and auto-deletion. Enable Microsoft 365 In-Place Hold or Litigation Hold; enable Google Vault retention holds; disable mailbox retention policies on the relevant accounts. Preserves in place without alerting the custodian.
- 03Take a forensic export. Native format (PST, MBOX or provider-native export via eDiscovery/Vault), hash-verified, before any user-side deletion can occur. Screenshot and PDF prints are copies of copies — not the evidence.
- 04Preserve associated context. Calendar entries, contacts, mailbox rules (forwarding, auto-delete), signature blocks, journal archives and shared-mailbox delegations often carry the story that the messages alone do not.
- 05Preserve server-side artefacts. Message trace logs, admin audit logs and unified audit logs from the tenant — retention windows are short (90 days in default Microsoft 365 configurations) and once they roll over the evidence is gone.
What proper email evidence looks like
| Component | Why it matters |
|---|---|
| Native-format export (PST/MBOX/EML) | Preserves headers, attachments and structure that a print cannot |
| Full internet headers | Routing chain, sending IP, timestamps, SPF/DKIM/DMARC results — the basis of authentication analysis |
| SHA-256 hash of the export | Proves the exhibit has not been altered since acquisition |
| Server-side audit logs | Records logins, message sends, rule changes and admin actions that mailbox contents alone do not show |
| Custody and export note | Who exported, when, from which account, under what authority, with what tool |
Header analysis: what it can and cannot tell you
A full set of internet headers records the servers the message passed through, the timestamps at each hop, the sending IP address and the results of SPF, DKIM and DMARC authentication checks. Header analysis can confirm that a message was, or was not, genuinely sent by the domain it claims to be from; it can rebut spoofing allegations; and it can date a message to the second at the sending server. It cannot, on its own, prove which individual composed the message — that is a mailbox and endpoint question.
The common failure modes
- The client "prints the emails to PDF" and hands over the prints. Headers are lost, attachments are missing or reformatted, and the exhibit cannot support authentication analysis.
- The mailbox is deleted on the departing employee's leaving date, following the standard IT off-boarding checklist, before litigation is contemplated in writing.
- Auto-forwarding rules quietly move relevant messages to a personal account, and the mailbox export therefore omits the material that matters most.
- The IT team makes an export using a personal admin account, without recording the export path — and the chain of custody cannot be established under challenge.
- Tenant audit logs are allowed to roll over their default retention window before anyone realises they will be needed.
Ninety-nine per cent of the email-evidence problems we see in litigation would have been avoided by a one-page written litigation hold issued in the first week of the matter.
Personal and webmail accounts
Preservation of personal Gmail, Outlook.com or Yahoo accounts requires the account holder's consent (or a court order), and is normally achieved via the provider's native takeout export under written authority. The same principles apply: native format, hash-verified, contemporaneous note. What is not appropriate — and what will not survive cross-examination — is forwarding personal-account content to a corporate mailbox to "preserve" it. That is not preservation, it is duplication with metadata loss.
Frequently asked questions
Departing-employee mailboxes are commonly deleted within 30–90 days of the leaving date. Microsoft 365 default audit-log retention is 90 days. Individual messages can be deleted by the user in seconds. Early written hold is the only reliable safeguard.
They are admissible as exhibits, but they cannot support authentication analysis and are vulnerable to challenge on completeness and provenance. Native-format exports are the professional standard.
Yes. Microsoft 365 In-Place/Litigation Hold and Google Vault holds preserve in place without notifying the mailbox owner. Covert preservation is common in employment and fraud matters.
Services like ProtonMail and self-destructing message features preserve at rest but resist eDiscovery-style export. Preservation typically requires account-holder cooperation and provider-native takeout tools.
No — preservation should be scoped to identified custodians and issues. Over-broad holds are disproportionate and hard to lift. A tightly-scoped hold, revisited as the matter develops, is the defensible approach.
