Email and Cloud Forensics: Both Ends of the Route

Nothing on these pages is more perishable than tenancy audit data. It is written automatically, it is comprehensive, it is sitting there now, and it expires on a schedule set by a licence nobody chose with an investigation in mind. That single fact governs the order of this page: arrange the export first, work out what you want to ask afterwards. Everything else — the forwarding rules, the sync client's local diary, the browser residue — waits perfectly well. The logs do not.

Most of the exporting is yours. The reading is ours. £800 + VAT for the examination and report, £400 + VAT for a verified image with deleted material extracted and no findings — the recorder-drive price, not a sixth tier. Free diagnostic, scope in writing. Investigations sit outside no fix, no fee. Ordinary bands.

Arrange the export on the day you first wonder about it

Microsoft 365 and Google Workspace record a great deal more than most administrators realise, and retrieving it requires nothing exotic — your own IT people can run it against a written list of what is wanted and for which dates. Sign-ins with times, addresses and device details. Activity at the level of individual files: opened, downloaded, shared, moved, removed. Sharing links, including anonymous ones. Every mailbox rule with the date it was created. Administrative actions, such as one account being granted rights over somebody else's mailbox. Access is not the difficulty. Retention is. Some of it survives ninety days, some considerably less, and how much depends on a licence tier chosen years ago for reasons unconnected to any of this. Waiting to see how the situation develops is, in this one respect, the most expensive decision available.

A mailbox is difficult to tidy up, which is the useful part

Mail is the oldest route out and it is still the busiest, and the patterns are tediously consistent. Attachments to a private address in ones and twos over several weeks, so that no single message would ever draw attention. A forwarding rule created quietly, frequently paired with a second rule that deletes the forwarded copy so that sent items goes on looking innocent. A burst of large sends in the last few days. Then a purge. What makes this workable is how little of it the sender actually controls: message headers, transport logging, mailbox audit entries and the tenancy's own retention all sit outside the folders anybody can clear out, and a rule that deletes its own evidence still has a creation date attached to it.

The cloud half writes itself onto the laptop

This is the part clients do not expect, and it is why the endpoint gets captured even when the argument appears to be entirely about a cloud account. OneDrive, Dropbox, Google Drive and Box each keep local databases on the machine recording which account is signed in, which folders are being mirrored, what was uploaded and when, and what was taken away afterwards. A personal account authenticated alongside the corporate one is among the most productive single findings in this practice, because it generally means a mirrored folder of company documents somewhere on the disk with an upload history attached to it. Browser artefacts complete the picture: transfer sites, webmail sessions, download history, and the sign-in pages visited immediately before each of them.

Two sources constrain each other. One source invites an answer

Take an evening on which the tenancy shows a document library downloaded at 20:14. Standing alone that is somebody working late, and it will be explained as exactly that. Now put the laptop beside it: the account signed in, a browser session open, an archive written into the downloads folder, and twenty minutes later a personal sync client pushing up a folder of comparable size. The second record does not repeat the first — it narrows what the first can plausibly mean, which is what corroboration is for. Where the two ends disagree, the disagreement is printed with both dates rather than resolved in favour of whoever commissioned the report.

Scope is a defence, not a limitation

A work mailbox is examined against the question in dispute, over defined dates and defined categories, and the reasons for that scope are written down before anything is read. That is partly a data protection obligation and partly self-interest: an examination that turned into a general read of somebody's correspondence is an examination the other side will spend the hearing attacking instead of answering. The hard boundaries sit outside it altogether. A private Gmail account or somebody's own Dropbox needs their consent or an order aimed at them or the provider. Live traffic is not intercepted. What remains inside the line is everything your own systems and your own hardware recorded about the transfer, and that is nearly always sufficient.

The handling underneath all of this is on the forensic practice hub. The endpoint half is captured at workstation deep imaging, credentials and standing access carry on at insider threat forensics, and where proceedings are in prospect the preservation duty begins at legal hold and chain of custody.

// what an exit through a mailbox looks like

Six patterns worth a closer look

Every one of these has a dull explanation available on its own. Three of them inside the same month is a pattern, and a pattern is what an examination is for.

Attachments going out in a steady trickle, always to the same private address
An outbound forwarding rule nobody spots until weeks after the leaver has gone
Corporate sign-ins timestamped at four on a Sunday morning
A private Dropbox or Google account authenticated on a company machine
A whole document library pulled down inside one evening
A mailbox emptied before anybody had a chance to go through it
// both ends, in one sequence

What a tenancy and a laptop produce together

Every entry carries its own date and its own source, and the two sources stay separate in the report so they can be compared rather than blended into one another.

What went out

Each attachment that reached a private mailbox, with its size and the date it went.

Rules and their dates

When each forwarding or deleting rule was made, and what it caught afterwards.

The shape of sign-ins

Times, addresses and devices, with out-of-hours clusters marked as such.

What the client left

Personal accounts, mirrored folders and upload records sitting on the disk.

Platform logging

Share, download and export events straight out of the tenancy's own audit trail.

Mail brought back

Messages and entire mailboxes restored from hold, retention or backup.

// the fee, and who may lawfully ask for it

What it costs, and the authority it stands on

Where the money goes on a tenancy job

Rather more of this instruction happens on your own systems than on ours, and the pricing follows that. Your administrators run the exports to a written list; the fee attaches to reading them, correlating them against whatever endpoint material exists, and writing the result up. £800 + VAT covers that examination and its report. £400 + VAT covers a machine imaged, verified and stripped of its deleted material with nothing analysed, which is the figure a recorder drive already carries and not a sixth tier bolted onto the list for investigations.

£800 + VATTenancy audit and endpoint read as one sequence, each finding dated, attributed to its source, and written so the other side can check it.
£400 + VATA laptop captured, verified and extracted for somebody else to interpret. The recorder and encrypted-volume price point.

Investigations are outside no fix, no fee — one of four published exclusions, with electronic and mechanical failure, chip-level work and DVR jobs — and the fee is settled at the start because the hours do not change with the answer. A single machine and a single question is what each figure assumes; a tenancy plus four laptops is measured in the free diagnostic and written down before you agree to it. The diagnostic itself costs nothing and closes two working days after an exhibit is booked in at Oxford, where the custody file opens at the same moment. Non-evidential recovery keeps its ordinary price.

Your own tenancy, your own hardware, or an instruction

Mailbox and tenancy work is done on a company's own systems with that company's authority, or on a solicitor's, insurer's or court's written instruction. The third route — hardware that genuinely belongs to the person asking — comes up here less often but applies in the same way. Nothing reaches beyond those three. A private Gmail account or somebody's own Dropbox needs their consent or an order aimed at them or at the provider, and reaching in without one would be unauthorised access under the Computer Misuse Act 1990. Live traffic is not intercepted here at all, that being reserved by the Investigatory Powers Act 2016 to bodies this is not one of. Passwords belonging to other people are not defeated, monitoring software is not supplied or recommended, and phones and tablets are not examined in any kind of matter.

// tenancies and mailboxes — asked before the export

What administrators and their solicitors ask

Less time than most people assume, and the exact figure depends on your licence rather than on any rule of thumb worth quoting. Some categories sit at around ninety days, several are shorter, and a handful are only retained at all on the higher tiers. Because nobody can tell you the answer over the telephone without looking, the sensible order is to have your administrators run the export now, against a written list, and argue about scope afterwards. An export you did not need costs a morning. One you needed and did not take cannot be recreated from anywhere.
Often not. A deleted mailbox is generally recoverable inside the tenancy's own retention window, and where litigation hold or an equivalent policy was in force the contents may have been preserved regardless of what was done to the visible folders. Backups and journal archives are a third route. All three windows are finite, which is the argument for making the request today rather than after somebody has decided whether the matter is serious.
In most cases, yes, and it is one of the more persuasive exhibits this work produces. The rule carries a creation date of its own. Message tracking or transport logging then records each message it caught afterwards, one line at a time, on the server side where the mailbox owner cannot reach it. The telling version is where the same person also set the forwarded copies to delete themselves: sent items then looks entirely unremarkable while the server record does not, and putting the two next to each other tends to end the conversation.
No, and it is better for everybody that we do not have them. The exports are run by your own administrators or your IT provider, against a written list of what is wanted and for which date range, and the output comes to us. Control of the tenancy stays where it belongs, the scope stays visible to everyone including the other side, and the person who ran the export can say so if anybody later asks how the material was obtained — which they will.
Take advice before touching it, because instinct and the right answer part company here. Disabling can stop further loss; it can equally start retention timers running or cut off the logging you were about to need. The order that works is preserve, then change: export the audit records, put the mailbox on hold, image the laptop, and adjust access afterwards on a plan rather than in the first ten minutes.
No, and no laboratory lawfully can. A private account belonging to somebody else requires their consent or an order directed at them or at the provider. What is available without either is your own record of the transfer: the account signed in on your laptop, the folders it mirrored, the files it uploaded and the hours it did so. In practice that carries the point, and it is obtained without going anywhere near the Computer Misuse Act 1990.
// getting your media to Oxford

Posting a device in — what goes in the box

The greater part of a tenancy investigation happens on your own systems, so ring 0800 689 0668 first and we will settle what has to be exported and by when. Where a laptop needs capturing as well, the drive travels to Oxford by tracked, insured post or across the counter there in office hours. Nothing is collected anywhere in this network and Coventry has no counter of its own.

As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.

  • Use a box or padded mailer with some rigidity to it, and pack around the drive until nothing shifts when the parcel is tilted. Mains adaptors, docks and leads are not wanted at this end.
  • Sending a RAID or a server? Only the member disks travel — not the chassis, not the controller — and each one wants its bay number written on it. Take a photograph of the front of the unit before anything is pulled; it costs nothing and now and again it saves a day.
  • Print the shipping and booking-in form (PDF), add a name, a number you will answer and a sentence on how the trouble began, and drop it in beside the media.
  • Most people use Special Delivery, which is tracked and covered; a courier of your own does the same job. You can also bring it: the Oxford reception takes devices over the counter, Mon–Fri 9:00am–5:30pm. Neither a Coventry counter nor a collection round exists.
// write this on the label

Oxford Data Recovery

John Eccles House
Oxford Science Park
Robert Robinson Avenue
Littlemore, Oxford, OX4 4GP

↓ Print the shipping & booking-in form (PDF)

Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.

Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.

The tenancy remembers. Not indefinitely.

Audit logging expires on a timetable nobody in your business chose. Ring the freephone and get the export arranged while the window is still open.