Mailboxes

Traces collects full email accounts (often called custodians) using the platform's native capabilities. What this means is there is no eDiscovery licensing required or software to install on your side. Instead, Traces talks directly to Microsoft or Google to collect every single email in full, with all attachments and threads intact.

What is collected?

As standard, we collect emails from the following folders:

  1. Inbox

  2. Sent Items

We can, at your request, also collect:

  1. Deleted Items

  2. Junk

  3. Drafts

  4. Recoverable Items*

  5. Any specific folder from any custodian, e.g. "Accounts 2025", "Sales Pipeline"

  6. All folders from any custodian

* A recoverable item (also called a partial) occurs when a deleted email has been fully deleted. Sometimes, the full delete process leaves artefacts and fragments of the email that was deleted. We cannot guarantee that there will be any recoverable items in a custodian's account.

What do you need from me?

We use a simple and secure approach called global consent - we send a link to a person (either yourself or a colleague, or your client) who has 'Global Administrator' permissions (every Microsoft and Google tenant has one). They will receive an email from Traces that details what they are approving and a button. When they click the button, they will be granting Traces access to every mailbox and the basic details of every user in the tenant. They have the ability to remove this permission at any time and we provide instruction on how to do so in the email. Once they click Authorise, a Traces analyst will be notified and can start the collection.

We appreciate that a lot of IT teams will run for the hills when asked to grant global consent. And this is entirely understandable; they are granting Traces a lot of read-only access to every mailbox. To help mitigate this risk, Traces only collects (and is only aware of) the custodians we manually enter for the scope of the collection. The chain of custody document details every mailbox that was accessed, what was accessed, and when.

If tenant-wide email access is too broad, we can provide a guide and instructions on manually setting up the access directly in the tenant. However, this is (in our experience) messier and more prone to errors than using the platform-provided access via global consent. We are here to help you and we understand security concerns, so we can explore your specific access requirements in more detail on the scoping call.

What do I get back?

Your evidence

For mailboxes you will receive a folder that contains EML files. An EML is the most universally-accepted format for an email, and can be opened in Apple Mail or similar programs. Each EML is a full email, so includes the original sender and recipients, timestamps, and attachments - it is like viewing the email as if you had received it yourself. The emails are arranged into the folders as they appear in the mailbox, e.g. Inbox, Sent Items. The attachments in their native format e.g. xlsx, docx are also in the folder if you wish to review outside a mail application.


Chain of custody

This is what shows how Traces collected the mailbox, the details of the instruction to us and authorisation details, and a summary of what was in scope of our collection with anything we couldn't get noted in the table. The chain of custody is what is needed to show that this collection is repeatable. Someone following the exact same steps, and at the exact same time, would have collected the exact same data. We do not include the forensic signature for each file in our chain of custody. Instead we rely on our hash list to contain these signatures, so the chain of custody can focus on recording the process we followed.


Hash list

A hash is a mathematical signature of a file. It is a way of looking at the contents of the file and the information about the file itself and deriving a long number. That long number is globally unique to that exact file in that exact state. It can be used to verify at any point if an email is used as evidence, that the email exhibited is exactly the same as the email that was collected by Traces. The file itself is a CSV, and can be viewed in Excel or similar spreadsheet software.


Item manifest

Another CSV file but this time much more usable. This contains details about each email and includes the following columns:

  1. Custodian

  2. Folder path

  3. Provider item ID

  4. Internet message ID

  5. Subject preview

  6. From address

  7. Sent at

  8. Received at

  9. Size (bytes)

  10. SHA256 (hash)

There are a few other columns, related to the forensic integrity of the email. You can download a sample email collection below. All collections are provided to you as a ZIP. It is password protected, and your analyst will provide your password to you in a different way (such as via text message or a secure messaging app). We do not publish the exact details on how we will provide you with the password upfront (for security reasons). You will be sent a link to download the ZIP folder. This link is one time use. Other links can be generated upon request.

Our own records of the engagement - who instructed us, what we were asked to do, what we did - is retained for six years. Traces will hold a copy of the ZIP for 90 days once we have confirmed you have downloaded and can access the bundle. You can at any time request the deletion of your collection from Traces.

Traces is a managed digital evidence collection service, offering acquisitions from mailboxes, code repositories and many other systems e.g. Jira and Slack.

All analysts are trained in the principles of digital evidence processing and best practices. All reports are reviewed by Kieran Maher, listed on the UK Register of Expert Witnesses.

All methodology details, information related to a certain platform or technology, and similar documents can be found in the 'How it works' section

Menu

Legal Policy

Our offices

20 Swan Street, Manchester, M4 5JW

© 2026 Deeptrace Consulting Limited. Traces is the trading name for Deeptrace Consulting Limited, registered in England & Wales no. 16518995. We are registered with the ICO, no. ZC044407

Traces does not offer legal advice.

Traces is a managed digital evidence collection service, offering acquisitions from mailboxes, code repositories and many other systems e.g. Jira and Slack.

All analysts are trained in the principles of digital evidence processing and best practices. All reports are reviewed by Kieran Maher, listed on the UK Register of Expert Witnesses.

All methodology details, information related to a certain platform or technology, and similar documents can be found in the 'How it works' section

Menu

Legal Policy

Our offices

20 Swan Street, Manchester, M4 5JW

© 2026 Deeptrace Consulting Limited. Traces is the trading name for Deeptrace Consulting Limited, registered in England & Wales no. 16518995. We are registered with the ICO, no. ZC044407

Traces does not offer legal advice.

Traces is a managed digital evidence collection service, offering acquisitions from mailboxes, code repositories and many other systems e.g. Jira and Slack.

All analysts are trained in the principles of digital evidence processing and best practices. All reports are reviewed by Kieran Maher, listed on the UK Register of Expert Witnesses.

All methodology details, information related to a certain platform or technology, and similar documents can be found in the 'How it works' section

Menu

Legal Policy

Our offices

20 Swan Street, Manchester, M4 5JW

© 2026 Deeptrace Consulting Limited. Traces is the trading name for Deeptrace Consulting Limited, registered in England & Wales no. 16518995. We are registered with the ICO, no. ZC044407

Traces does not offer legal advice.