Specialized Email Evidence Collection & Processing
When your case involves email, Aid4Mail adds depth most forensic platforms don’t specialize in—email-specific collection, recovery, and AI analysis in one workflow. Process evidence up to 10× faster, recover double-deleted and carved messages, and apply AI analysis that goes beyond keywords—all with audit-logged forensic integrity.
Why Forensics Teams Choose Aid4Mail
Up to 10× Faster
Process terabytes of local data overnight
40+ Formats Supported
PST, OST, MBOX, EMLX, cloud accounts
Advanced Recovery
Recover deleted & carved emails
AI-Powered Intelligence
Context-aware analysis beyond keywords
Trusted by law enforcement and government agencies worldwide
25+
Years Experience
100+
Countries Served
EDRM
Recognized
24/7
Unattended
Forensic Email Processing Capabilities
Aid4Mail brings email-specific depth to your forensic toolkit, so evidence other tools overlook is captured and verifiable through export logs
Comprehensive Collection
- 40+ email formats and cloud services
- Native pre-acquisition filtering
- Cloud attachments with metadata
- Enterprise M365 & Google Workspace
Forensic Email Recovery
- Double-deleted mail restoration
- MIME carving from disk images
- Corrupted mailbox reconstruction
- Unallocated space extraction
AI-Powered Intelligence
- Natural language filtering
- Automated classification
- Multi-language understanding
- Offline AI for sensitive data
Advanced Search
- Proximity & Boolean operators
- Regular expressions (PCRE2)
- Multilingual stemming (8 dictionaries)
- Deep attachment searching
High-Speed Processing
- Up to 10× faster local processing
- Concurrent task execution
- Unattended workflows
- Incremental processing
Flexible Export
- 15+ export formats
- Court-ready PDF with Bates
- Portable HTML viewer
- EDRM MIH/MIH+ deduplication
Verifiable, Defensible Results
Forensic work demands proof. Aid4Mail’s key claims are testable, documented, and built for the audit trail
Reproducible AI Benchmark
We evaluated 42 AI models and retained 11. On our insider-threat classification test, every retained model reached at least 99% recall—a miss rate under 1%. Download the benchmark kit and the full 2,000-email corpus to reproduce the results on your own model and hardware.
May 2026 benchmark snapshot.
Explore the AI benchmark →Evidenced Email Recovery
In an internal test, Aid4Mail recovered all 100 deleted and partially corrupted MIME messages from a disk image, while two leading forensic tools returned only unusable fragments. Scoped to email/MIME recovery—not a general carving comparison.
Internal Fookes test.
MIH+ Completeness
MIH+ produces EDRM-recognized message hashes even for the roughly 10–20% of mail that standard EDRM MIH cannot hash—drafts, some sent items, and malformed headers that lack a Message-ID. Deduplication lists stay interoperable across tools.
EDRM DupeID-recognized.
Developed in Switzerland by Fookes Software, with 25+ years of email-processing expertise. Every collection is backed by detailed audit logs and per-message logging—export logs are the authoritative record of collection completeness.
A Specialized Email Layer for Your Forensic Platform
Aid4Mail works alongside your existing tools, handling email-specific collection, recovery, and production inside one workflow
Why Pair Aid4Mail with Your Forensic Suite?
Add Email Depth
Specialized email handling: server-side pre-acquisition filtering, cloud-attachment collection, and email-specific AI analysis
Reduce Downstream Cost
Cull email at the source before ingestion—often a large reduction (illustratively up to ~90% on email-heavy collections), lowering storage, indexing, and review time
Dependency-Free PST Production
Create PST, PDF/A, and load-file productions with no Outlook, MAPI, or CDO on the processing host
Parallel Processing
While your suite handles other evidence, Aid4Mail processes all email tasks concurrently (Investigator and Enterprise)
Works With Leading Platforms:
Real-World Forensic Applications
Aid4Mail excels in the most demanding investigative scenarios
Financial Crime & Fraud
Uncover embezzlement schemes, insider trading, and money laundering through email patterns and deleted communications.
- ⯈ Trace financial transactions in attachments
- ⯈ Interpret coded language with AI
- ⯈ Recover deleted evidence trails
Cybersecurity Incidents
Analyze breach vectors, track lateral movement, and identify compromised accounts through email forensics.
- ⯈ Analyze phishing campaigns
- ⯈ Track malware distribution
- ⯈ Identify data exfiltration
IP Theft & Trade Secrets
Protect intellectual property by uncovering unauthorized disclosures and data theft through comprehensive email analysis.
- ⯈ Track document sharing patterns
- ⯈ Identify unauthorized recipients
- ⯈ Preserve cloud attachment metadata
Criminal Networks
Map criminal organizations and uncover conspiracies through email communication patterns and metadata analysis.
- ⯈ Identify communication networks
- ⯈ Surface coded language with AI
- ⯈ Establish timelines and relationships
Choose Your Forensic Edition
Flexible licensing designed for forensic professionals
Converter
Basic conversion & migration
- 40+ format support
- Folder filtering
- Free portable viewer
- No advanced filtering
- No email recovery & carving
Investigator
Advanced forensics & AI
- Everything in Converter
- Email recovery & carving
- Pre- & Post-acquisition filtering
- AI analysis & classification
- Cloud attachments & metadata
Enterprise
Unlimited scale & automation
- Everything in Investigator
- Mimecast/Proofpoint support
- CLI automation
- Server or USB deployment
- Priority support
Ready to Enhance Your Forensic Capabilities?
Experience the specialized email forensics that complements your existing platform