Chapter 8: Emails Flashcards
where can you find digital evidence relating to an email investigation
local machine
what will the local machine tell you about an email
- destination
- email server(s)
- device that was used to access the email
- logs from the internet service provider
what is an emaill protocol
a standard that is used to allow 2 computer hosts to exchange email communication
what does SMTP stand for
simple mail transfer protocol
what does RFC stand for and what is it
- request for comments
- used on internet/communications technology to create standards
what do mail servers use SMTP for
to send and receive email messages from all points of the internet
what is the SMTP pathway
describe POP3
- standardized protocol
- allows users to access their inbox and download emails
- cannot send emails (only receive)
what does POP3 stand for
post office protocol
what does IMAP stand for
internet message access protocol
describe IMAP
- standard protocol
- used by clients to access emails on an email server
- complete inbox management w multiple clients
what is the main difference between IMAP and POP
- POP retrieves contents of the mailbox
- IMAP was designed as a remote access mailbox protocol
what are some examples of standard webmail providers
- gmail
- yahoo
- outlook
what happens to user deleted emails on web-based email servers
remain on the server until the system deletes them
what is a characteristc feature of web-based emails
when a user deletes an email, it goes into “trash/deleted” folder for a period of time before actually being deleted
what allows a DFI to serve judicially approved subpoenas/search warrants on emails
- mailbox and domain name
- message ID