Thousands of emails are being sent and received in a day, becoming an important part of evidence recovery in most of the litigation processes. It is possible now days to recover deleted messages, the header information that includes time stamp, routing information of mail, IP address etc. The mail clients and Servers often act as database source as they comprise of depository like mails, calendars, contacts etc. The three basic component of an email are Body, Header, and Attachment. For recovery and analysis, viewing an email in different views will help. Here is a list of Mail Views that help in forensic examination of messages and evidence recovery for litigations.
Email Hop View: A hope of an email is the routing path followed by a message between source and the destination. It helps to get details of routers and the gateways a message has pass through. For example: When a packet is passed through one device to another, a hop occurs. To check number of hops for a mail, trace path commands are used.