Forensic Discovery
Home > Forensically Sound Email Collection

Preserve, Extract, and Analyze Email Data—The Right Way

Despite the emergence of electronically stored information (ESI) via text message and collaboration apps, email remains the most common source of ESI discoverable in litigation and investigations. While email has been in use for decades, the recent move to cloud-based email platforms has dramatically changed discovery workflows for collecting email in a forensically sound manner. Pioneers in collection from cloud-based sources, Forensic Discovery provides peace of mind to our clients in the knowledge that, whatever the email ESI source, our team has the skills and expertise to collect that ESI in a forensically sound manner and provide services that extend throughout the discovery lifecycle. Forensic Discovery is literally who we are!

Why Forensic Discovery

There are several reasons why you should choose Forensic Discovery for your forensic email collection needs. Here are five of them:

Pioneers in forensic cloud collection, having developed our own tools over 12 years ago.

Award winning as a top eDiscovery and digital forensics provider in 2023, as recognized by Enterprise Security magazine.

Peace of mind in working with the same expert team members case after case that take a consultative approach to client engagements, applying best practices to fit your custom requirements.

Expert services combining years of experience with respected certifications such as Certified Forensic Computer Examiner (CFCE).

Forensic Discovery is who we are – a unique combination of digital forensics and discovery lifecycle project management expertise!

Scope of Services

At Forensic Discovery, forensic email collection involves the collection of email ESI in a forensically sound manner that maintains the integrity and authenticity of the ESI, ensuring accuracy and defensibility for litigation, investigations and compliance audits. Here’s how we can support email collection across different platforms:

Collecting Email from Cloud-Based Servers

Forensic Discovery are pioneers in forensic cloud collection, having developed our own cloud collection tools (including eCloudCollect) over 12 years ago. We collect from all types of cloud-based environments, including:

  • Microsoft 365 (M365): Forensic Discovery is proficient in M365’s built-in tools for eDiscovery (including M365’s cloud attachments collection utility) that allow organizations to search, hold, and export email data efficiently. We’re also proficient with its Security and Compliance Center that helps in identifying, collecting, and managing email data across the organization, and Data Loss Prevention (DLP), which ensures sensitive information is protected while collecting emails.
  • Google Workspace (formerly Google Apps): We are experienced with Google Vault’s eDiscovery and archiving capabilities for retention, search, and export of email data.
  • Exchange Online: Our team is experienced with the Exchange Admin Center used to manage compliance and perform eDiscovery on email data and its In-Place eDiscovery and Hold capabilities that allow for the preservation of email data while investigations are ongoing.
  • IMAP, POP3 and API: We have considerable experience conducting forensically sound collections using different methods for accessing and managing email messages, including:
    • IMAP (Internet Message Access Protocol)
    • POP3 (Post Office Protocol Version 3)
    • API (Application Programming Interface)
  • eMail Clients Supported: Forensic Discovery can provide forensically sound collection services from any email client. Here’s a list of some of the email clients from which we have collected emails in discovery:
    • Microsoft Outlook
    • Mozilla Thunderbird
    • Gmail
    • Apple Mail
    • Yahoo Mail
    • ProtonMail
    • Hushmail
    • Zoho Mail
    • Mailbird
    • eM Client
    • Spark
    • Airmail
    • BlueMail
    • Postbox
    • Windows Mail
    • Outlook Express

Collecting Email from Physical Devices

Email isn’t just in the cloud – it still exists on physical devices which may contain the only copy of important emails. Forensic Discovery can also perform collections directly from physical devices, including desktop clients and mobile devices:

  • Desktop Clients: Our services include PST/OST file extraction of email data from Outlook and MBOX files from email clients like Thunderbird, which can be extracted and analyzed using forensic tools.
  • Mobile Devices: We use specialized forensics tools to extract email data from mobile devices for both iOS and Android, ensuring the collection process maintains data integrity. That service includes email retrieval from device backups, offering an alternative method for data collection.

Comprehensive Forensic Email Analysis

At Forensic Discovery, our digital forensics experts provide comprehensive forensic email analysis services after collection. Services include:

  • Metadata and Header Analysis: Metadata and email header data are key to authentication of the evidence and are often useful to identify patterns and construct timelines. Forensic Discovery’s team of experts can help your team identify the important facts in the data within the data.
  • Content Analysis: Our team of experts can also analyze the content of emails (including attachments) using keywords and analytics to identify important emails and communication or transaction patterns to determine “who knew what when” and “where did the money go”.
  • Recovery of Deleted Emails: Just because an email is “deleted”, that doesn’t ensure it’s gone forever. Forensic Discovery’s team of experts apply industry proven forensically sound collection techniques and technology to enable recovery of emails which may have been deleted accidentally or maliciously.

Expert Witness Testimony

Our team of certified forensics experts can back up our collection services with authoritative testimony during litigation proceedings. We can provide clear, straightforward explanations of complex technical concepts to help judges and juries understand our methods and the findings of our analysis.

Email Forensics Use Cases

At Forensic Discovery, we have nearly three decades of experience collecting and analyzing digital email evidence to support a variety of discovery use cases, including:

  • Litigation and Arbitration: We have supported our clients on numerous types of legal disputes, including breaches of fiduciary duty, contract disputes, fraudulent activities, business torts, employment disputes, intellectual property disputes and product liability cases. We understand the unique goals and requirements associated with each type of litigation and how email evidence can support your case.
  • Investigations: Email can play an important role in investigations as well. Our team has considerable experience with all types of investigations, including internal investigations within a company to identify harassment or fraudulent activity, investigations to support personal disputes (such as divorce and child custody disputes), and law enforcement and government investigations.
  • Incident Response: Did you know that response to a cyber incident includes a discovery workflow? It does, and our team understands how to collect email to identify potential causes of the cyber incident and also what customers or individuals were affected.
  • HSR Second Request: In the case of mergers and acquisitions for which an HSR second request has been issued by the FTC or DOJ, emails can be critical evidence to produce to those government agencies. The Forensic Discovery team has the skills and experience to support the large volume and short timeframes typically associated with HSR second requests.

Ensuring Data Integrity and Compliance

The key to successful forensic email collection is ensuring that the data is collected in a forensically sound manner that maintains its integrity and is defensible in court. This includes:

  • Chain of Custody: Maintaining a clear record of who has accessed the data and how it has been handled.
  • Data Preservation: Ensuring that collected data is stored securely and is protected from tampering.
  • Compliance with Legal Standards: Adhering to legal and regulatory requirements, such as GDPR and HIPAA, to ensure data is collected and processed lawfully.

Forensic Discovery has the expertise, the best practices and the tools to ensure forensically sound collection is conducted as efficiently and cost effectively as possible. We’re all about people, process and technology!

Abstract image of a dark blue and purple wave-like pattern of light dots. | Forensic Discovery

Award-Winning Cloud-Based Review Platforms

Clients We Work With

Keurig Dr Pepper logo | Forensic Discovery
Format.com logo | Forensic Discovery
Moye White logo | Forensic Discovery
Ogletree Deakins logo | Forensic Discovery
Gibson Dunn logo | Forensic Discovery
Lewis Brisbois logo | Forensic Discovery

Forensic Discovery Google Reviews

Headshot of a woman with blonde hair and a big smile. | Forensic Discovery
Five star review

Trent Walton has been the go-to computer forensics expert for our criminal defense firm. He's helped us in several criminal cases - from forensic examination of electronic devices to expert testimony in trial. We love working with him! He's very competent in his field, communicative, honest, intelligent, personable, and easy to work with. Our firm will continue using his services.

— Reegan O’Neill

Headshot of a woman with shoulder-length auburn hair and red lipstick. | Forensic Discovery
Five star review

Trent Walton has always been a pleasure to work with. He is responsive, personable, and qualified. I will gladly continue to use Forensic Discovery in the future!

— Chloe Gleichman

Abstract kaleidoscope pattern with faces, featuring a starburst logo in the bottom right corner. | Forensic Discovery
Five star review

Very knowledgeable and helpful. Give me a call back very promptly and we're very diligent. They heard me out and answered all my questions. I would highly recommend them and I'm looking forward to working with them.

— Moses

Contact Our Team for a Free Consultation!

Contact us online or call 877-764-0920 to schedule a free consultation with one of the certified digital forensics specialists at Forensic Discovery. We maintain offices in Arizona, California, Colorado, and Texas. We provide expert forensic email collection and analysis services for clients located throughout the country.

"*" indicates required fields