MOBILE FORENSICS

Android email forensics

Email applications on Android often contain information relevant to both business and personal matters. As part of an IT forensic investigation, local email artefacts, synchronisation data and metadata can provide valuable insights into communication patterns.

Local email databases
Gmail, Outlook and Samsung email artefacts
IMAP, POP3 and Exchange accounts
Attachments and downloaded files
Synchronisation information
SQLite databases
Timestamps and header information
Cache and configuration files
Account and profile settings

TECHNICAL BACKGROUND

Technical Fundamentals

Depending on the email application used, different databases and storage areas are utilised.

Forensically relevant artefacts include, amongst others:

  • Local email databases
  • Gmail, Outlook and Samsung email artefacts
  • IMAP, POP3 and Exchange accounts
  • Attachments and downloaded files
  • Synchronisation information
  • SQLite databases
  • Timestamps and header information
  • Cache and configuration files
  • Account and profile settings

Storage locations and data structures vary depending on the app, Android version and manufacturer.

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
Following a suitable forensic data backup, email databases, headers, attachments and synchronisation artefacts are examined using recognised IT forensic tools and manual analysis. Timestamps and communication data are correlated with other technical artefacts. All stages of the investigation are documented in a reproducible manner.
2
LanCologne produces expert reports for private individuals, as well as for companies and solicitors. Our reports have already been used in court proceedings. In some cases, we have been directly commissioned to produce IT forensic reports. Upon request, we can provide anonymised or redacted sample reports or extracts.

TYPICAL QUESTIONS

When is this analysis required?

  • Which emails are stored locally?
  • Which accounts have been set up?
  • Which attachments have been saved?
  • Is it technically possible to recover deleted emails?
  • How significant are the existing artefacts?

LIMITATIONS & CONCLUSION

What you should know

The scope of the data that can be analysed depends, amongst other things, on synchronisation, app settings, deleted content and the available data set. Conclusions are drawn solely on the basis of objectively verifiable technical artefacts.

Android email forensics enables the technical analysis of local email artefacts and their metadata. Only a comprehensive analysis of all available data sources allows for a reliable IT forensic assessment.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Would you like to have email data from an Android device professionally examined? LanCologne can assist you with an objective IT forensic analysis and comprehensive expert documentation.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

Which email apps can be analysed?
These include Gmail, Outlook, Samsung Email and other Android email apps.
Are attachments analysed?
Yes. Where available, downloaded attachments will be included in the investigation.
Are email headers relevant in a forensic context?
Yes. They provide important technical information on transmission and delivery.
Can deleted emails be recovered?
That depends on the data set and the artefacts available.
Could an expert report be drawn up on this matter?
Yes. The results are documented in a transparent manner and assessed from a technical perspective.