The #1 forensic email collector and search tool for professionals.
Email is still king when it comes to communication, especially in the professional world. According to Statista, around 347 billion emails are sent daily in 2023. And those numbers keep increasing!
Why does this matter?
Because email produces such vast amounts of Electronically Stored Information (ESI), it’s usually a dominating component of ediscovery and digital forensics investigations. Many cases have been solved after finding incriminating data in email messages or their attachments. Unfortunately, investigations relying on suboptimal email forensics tools have taken longer to resolve than necessary and, in some cases, may even have failed.
Don’t make that mistake! Choosing a quality forensic email collector can make the difference between quickly solving a crime and failing to find the incriminating information. This is why you should consider Aid4Mail an essential component of your digital forensics tools. It is based on years of expertise in the field of email processing. Expertise that began in 1999 and led to the release of our first email forensics tool in 2002. That’s way longer than all our competitors.
First of all, Aid4Mail only deals with emails and their attachments. But it can collect, find, and recover mail that other forensics tools miss—Aid4Mail is an industry leader in this domain.
Secondly, Aid4Mail’s workflow differs greatly from digital forensics software like FTK, Encase, and Nuix. As its primary job is to collect, filter, and convert emails, the whole process takes a fraction of the time needed by traditional computer forensics tools. Here’s why:
As a result, you can process terabytes of email data, unattended from start to finish, fast and accurately.
Furthermore, since the whole process happens on-premises, you don’t incur any third-party charges for the volume of data processed and stored. This can significantly reduce costs.
Although you can’t review email data directly in Aid4Mail, if your forensic email collection is small enough, Aid4Mail can easily convert it to a searchable format. For example:
If you cannot cull down your forensic email collection to a reasonable size, consider transferring Aid4Mail’s output into a comprehensive e-discovery platform (e.g., FTK, Encase, AXIOM, etc.). In this respect, Aid4Mail is an excellent complement to other digital forensics tools.
Aid4Mail has been optimized for speed and stability. It can work through terabytes of data without user intervention. In tests with local files, Aid4Mail performed 6 to 10 times faster than its competitors! For example, a forensic email collection taking a week to complete with a competing solution would require just one day with Aid4Mail—a considerable time-saving.
With Aid4Mail Investigator and Aid4Mail Enterprise, you can run multiple processing tasks simultaneously, taking full advantage of your computer’s hardware and saving more time. For example, four tasks may all use the same input but different filters, and output to separate folders within the same PST file. All four tasks could be run concurrently and unattended while you’re working on something else. This example is shown in the screenshot below.
Alternatively, simultaneously collect email accounts from several employees under investigation, or multiple source formats from a single custodian. For example, their Microsoft 365 account, Gmail account, local Thunderbird files, and archived EML files, merging them into the same batch of target PST files. Set the project up and let it run overnight so no time is wasted.
Collecting email from your custodians’ cloud-based accounts is made easier with Aid4Mail Remote Authenticator, a free stand-alone utility that they can download and run without installation. It enables the account owner to grant Aid4Mail secure, temporary access to their email service or IMAP account without providing full login credentials and without having a copy of Aid4Mail.
Collecting the appropriate data and finding specific incriminating information is crucial. Fortunately, Aid4Mail’s forensic email search and filter features are second to none.
In addition to the basic folder filtering available in all editions, Aid4Mail Investigator and Aid4Mail Enterprise add date and keyword filtering, and the ability to create complex search queries. These can include:
Native pre-acquisition search is also available for mail services that support it, like Outlook (including PST files), Gmail, Microsoft 365, and IMAP. This can significantly reduce the data Aid4Mail needs to process locally, speeding up the whole operation.
Support for Python scripts means you can completely customize Aid4Mail’s filters and add complementary features. For example, integrate OCR into your search or scan images for nudity.
Aid4Mail Investigator and Aid4Mail Enterprise can search hidden places—often the location of incriminating evidence. These include double-deleted (unpurged) emails, hidden Exchange folders (Recoverable Items), and unallocated space that’s been forensically extracted or is part of an uncompressed disk image. They can “carve” out MIME emails from almost any file, including corrupt and unsupported mailboxes.
While these features are not unique to Aid4Mail, its performance is outstanding. In tests, Aid4Mail finds emails in unallocated space that other forensic email recovery tools can’t detect. It finds whole emails when others often only find fragments. Even if you already use a digital forensics platform, Aid4Mail can be beneficial by finding evidence that these tools often miss.
Aid4Mail supports most popular email formats, mail apps, and webmail services, including PST files, as input and output. When available, additional metadata can be added to email headers.
Output formats for manual review or producing evidence in court are also available. Many, like PDF, HTML, CSV, and TSV, can be customized: Header fields can be included or excluded, Bates stamps inserted, and folder hierarchies and filenames tailored. HTML exports even provide an option to create an online viewer with email and folder selection, and a metadata search bar to filter the email list.
Here’s a complete list of Aid4Mail’s supported source and target mail formats:
¹ With or without Outlook
² Aid4Mail Enterprise only.
Maintaining the integrity of email after conversion from one format to another is crucial to avoid loss of evidence. Aid4Mail’s email conversion engine is the most accurate on the market. It is fully Unicode-compatible and preserves more visible and hidden data than any of its competitors.
Here’s an example of how much better Aid4Mail performs with visible data. Notice that it has no problem with the accented characters in the first line, the embedded image, or the Chinese attachment name at the bottom.
The following example shows Aid4Mail’s superiority with hidden data. Notice how much more metadata in the email SMTP header is preserved by Aid4Mail:
From: =?UTF-8?Q?"Bill Caff=c3=a9" <firstname.lastname@example.org>?= To: =?UTF-8?Q?"St=c3=a9phane Fran=c3=a7ois" <email@example.com>?= cc: =?UTF-8?Q?"'Lisa Gruy=c3=a8re'" <firstname.lastname@example.org>?= cc: "John Fire" <email@example.com> cc: "Tim Sand" <firstname.lastname@example.org> Priority: Low X-Priority: 5 X-Mozilla-Status: 0001 Subject: Poem by Charles Baudelaire MIME-Version: 1.0 Message-ID: <email@example.com> Date: Fri, 18 Feb 2011 17:18:13 0100 Content-Type: multipart/alternative;boundary="Next_Item:_(A3CB49KFSA19)/1"
Conversion by a competitor (hidden data)
Return-path: <firstname.lastname@example.org> Envelope-to: email@example.com Delivery-date: Fri, 18 Feb 2011 11:18:13 -0500 Received: from 131-39.62-81.cust.bluewin.ch ([184.108.40.206]:17353 helo=PrecisionT3500) by centaur.dewahost.net with esmtpa (Exim 4.69) (envelope-from <firstname.lastname@example.org>) id 1PqT25-00058l-7Z; Fri, 18 Feb 2011 11:18:13 -0500 From: =?utf-8?Q?Bill_Caff=C3=A9?= <email@example.com> To: =?utf-8?Q?St=C3=A9phane_Fran=C3=A7ois?= <firstname.lastname@example.org> Cc: =?utf-8?Q?'Lisa_Gruy=C3=A8re'?= <email@example.com>, "John Fire" <firstname.lastname@example.org>, "Tim Sand" <email@example.com> Subject: Poem by Charles Baudelaire Date: Fri, 18 Feb 2011 17:18:08 +0100 Organization: Fookes Software Message-ID: <firstname.lastname@example.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Priority: 5 (Lowest) X-MSMail-Priority: Low X-Mailer: Microsoft Outlook 14.0 Importance: Low Thread-Index: AcvPhydgtD/Fiez1TJSn19MfhrGhJw== Content-Language: en-us Status: RO X-Folder: Inbox
Conversion by Aid4Mail (hidden data)
Improve case completion with the help of Aid4Mail:
Options to avoid pre/post-processing and manual review in your email forensics investigation. For example:
We’re known for our customer support! All editions of Aid4Mail come with:
Aid4Mail licenses allow you to process an unlimited number of mail accounts and files, whether in-house or external. You can purchase a one-year license, or three years at a reduced price. You benefit from free software updates and our award-winning customer support during the license validity period.
On purchasing a license, you will receive an activation code that gets you up and running with Aid4Mail within minutes of making your payment. Once activated, trial mode is turned off, and your license becomes tied to your computer and Windows login account. See our EULA for details on how this works.
If you need to run Aid4Mail on a computer that doesn’t allow Internet access, simply contact us for an offline activation code. There is no charge for this option, but it offers less flexibility than online activation.
We also offer licensing options for running Aid4Mail in a virtual environment. Pricing is determined by the number of concurrent users plus the total number of users and installations. Contact us for a quote.
If you’re ready to buy an Aid4Mail license, visit our Buy Now page for pricing details and links to our online store.
To see a detailed feature comparison between the three Aid4Mail editions, check our Aid4Mail 5 feature comparison table in PDF format.
There’s much more to Aid4Mail; the best way to discover its capabilities is to try it out. We offer a free trial version with no time limit and no obligations. Simply visit our Downloads page to get your free trial and start using it within minutes.