Certification & Online Trace Collection · service active
WACZ · ISO 28500/ eIDAS timestamping/ Client area
C.E.R.T.O.
Sign in Register free
IT EN
C.E.R.T.O. / Modules / Email & PEC
03 · MAIL

Email & PEC

Preserve messages directly from the mailbox, with full headers and proof of sender authenticity.

C.E.R.T.O. Desktop “Email/PEC Acquisition” screen: connection to the IMAP server in read-only mode (password or Microsoft OAuth), SSL/TLS, saved accounts. The info panel lists the forensic checks applied (read-only EXAMINE, BODY.PEEK, original EML, DKIM/SPF/DMARC, RFC 3161 timestamp).

C.E.R.T.O.'s Email/PEC module performs the forensic acquisition of emails and certified mail: it connects to the IMAP server in read-only mode, preserves the original EML with headers, body and attachments, verifies DKIM/SPF/DMARC and — for PEC — validates daticert.xml and the provider's S/MIME signature. Everything is sealed as digital evidence with hashes, an RFC 3161 timestamp and an Ed25519 signature. It is the tool for court-appointed and party experts, lawyers and law enforcement who must prove the content, origin and date of a message.

Key features

What this module does.

  • IMAP connection (password, App Password and OAuth2 for Microsoft).
  • DKIM signature and SPF/DMARC verification + transmission hop (Received) analysis.
  • PEC analysis: transport envelope, daticert.xml and provider S/MIME signature (AgID).
  • Preservation of the original message in EML format.
  • BagIt 1.0 bundle signed with Ed25519, double RFC 3161 timestamp and CASE/UCO.
Final forensic report: the interactive dashboard of the email bundle — summary, acquired emails, chain of custody, hash inventory, IMAP connection and protocol, SSL/TLS certificates, timestamp and integrity check.
Forensic pipeline

How the module operates.

A repeatable, non-invasive procedure: the mailbox is read in read-only mode and every message is preserved in its original format, then cryptographically sealed.

01 · NTP

Synchronised time

Multi-source NTP sync (Google/Cloudflare/pool) with documented offset and roundtrip: the moment of acquisition is anchored.

02 · IMAP

Read-only connection

IMAP connection over SSL/TLS in EXAMINE (read-only) mode, with password or Microsoft OAuth. Server, port, IP and server capabilities are recorded.

03 · PEEK

Non-invasive read

Messages are read with BODY.PEEK: flags are not modified, messages are not marked as “read”. The mailbox stays exactly as it was.

04 · EML

Original preserved

The complete original EML is saved — headers, MIME body and attachments — exactly as received from the server, without reformatting.

05 · AUTH

Email authenticity

For ordinary emails: DKIM, SPF and DMARC verification and analysis of the Received header chain (the delivery hops, with IPs and servers).

06 · PEC

PEC validation

For certified mail: validation of the transport envelope and daticert.xml and cryptographic verification of the provider's S/MIME signature (AgID-accredited), with the receipts.

07 · RENDER

Visual rendering

Each message is also rendered to PDF and PNG for a faithful, immediate review alongside the authoritative EML.

08 · HASH

Fingerprints

MD5 + SHA-1 + SHA-256 + SHA-512 (FIPS 180-4) cryptographic hashes of every file: the inventory that anchors the integrity of the whole bundle.

09 · SEAL

Signature & double timestamp

manifest.json signed with Ed25519 + double RFC 3161 timestamp, packaging into a BagIt 1.0 bundle with a CASE/UCO description and verify.sh / verify.bat verifiers.

Bundle contents

Everything that gets generated.

Each email/PEC acquisition produces a coordinated set of artefacts, each with a precise forensic role, organised into clearly-named folders inside data/.

Original EML

The message in its original RFC 822/MIME format — full headers, body and attachments — exactly as delivered by the server: it is the authoritative media of the bundle.

evidence/email/…/message.eml

PDF/PNG rendering

A faithful rendering of the message as PDF and PNG image, to review the content as it appears, alongside the technical EML.

evidence/email/…/message.pdf · message.png

Extracted attachments

Each attachment is extracted and kept with its own cryptographic hash, so its presence and integrity in the message can be proven.

evidence/email/…/attachments/

DKIM · SPF · DMARC

Verification of the sender's authenticity signatures and analysis of the Received header chain (the delivery hops), with a pass/fail outcome.

network/dkim-verification.json · header-analysis.json

IMAP & TLS certificates

The IMAP session log (server, port, capabilities, read-only mode) and the X.509 certificate chains of the mail server.

logs/imap-protocol.txt · tls/certificates/

Forensic report & hashes

The report in PDF and TXT with its own RFC 3161 timestamp and the complete hash inventory (MD5/SHA-1/SHA-256/SHA-512) of all artefacts.

reports/report.pdf · hashes/file-hashes.json

Certified mail

The structure of a PEC, proven.

When the mailbox contains PEC messages, C.E.R.T.O. recognises and validates their legal structure: transport envelope, daticert.xml, the provider's S/MIME signature and receipts.

Transport envelope + daticert.xml

The provider-signed envelope and the daticert.xml file (sender, recipients, subject, identifier, date) are validated against the mandatory AgID fields.

Provider S/MIME signature

The provider's S/MIME signature is cryptographically verified and the certificate is checked to be issued by an AgID-accredited CA: origin and integrity proven.

Acceptance & delivery receipts

The PEC receipts (acceptance, delivery, non-delivery) are recognised and acquired: they document the legal path of the message.

Self-validation

A bundle that proves itself.

The bundle does not need C.E.R.T.O. to be validated: anyone, even years from now, can verify its authenticity with standard tools. The BagIt 1.0 structure and the interactive dashboard make it self-explanatory.

  • interactive.html — the navigable offline dashboard: summary, acquired emails, PEC stamp, chain of custody, hash inventory, IMAP connection/protocol and client-side integrity check.
  • manifest.json signed with Ed25519 (RFC 8032), bound to the identity of the device registered at first launch.
  • Double RFC 3161 timestamp: inner anchor on data/tsa.tsr and outer seal on tagmanifest-sha256.txt.tsr. Free cascade Sectigo→DigiCert→GlobalSign; optional qualified eIDAS InfoCert.
  • manifest-sha256.txt and tagmanifest-sha256.txt (RFC 8493): fixity of the payload and of the control files; no file can be added or altered without the check failing.
  • metadata/evidence.case.jsonldCASE 1.3 / UCO 1.4 description of the evidence, and tsa-ca.pem for verifying the timestamp even offline.
  • verify.sh / verify.bat — standalone verifiers: they recompute the hashes, check the double timestamp and the signature, and declare “VALID BUNDLE”.
FAQ

Frequently asked questions

Forensic email and PEC acquisition, non-invasive read, evidence validity and bundle verification: the most common questions.

What is forensic email acquisition?
It is the capture of an email message from the IMAP server in read-only mode, preserving the original EML with all headers, body and attachments, and cryptographically sealing it so it can be used as digital evidence verifiable by third parties.
How is the acquisition “non-invasive”?
The IMAP connection uses EXAMINE (read-only) mode and messages are read with BODY.PEEK: flags are not modified and messages are not marked as “read”. The mailbox stays exactly as it was — an essential requirement for the genuineness of the evidence.
How is a PEC (certified mail) acquired?
For certified mail, besides the message, C.E.R.T.O. validates the transport envelope and the daticert.xml file and cryptographically verifies the provider's S/MIME signature (AgID-accredited): this proves the integrity and certified origin of the message, together with its acceptance and delivery receipts.
Are DKIM, SPF and DMARC verified?
Yes, for ordinary emails C.E.R.T.O. verifies DKIM, SPF and DMARC and analyses the Received header chain (the delivery hops). For PEC these checks do not apply: authenticity is guaranteed by daticert.xml and the provider's S/MIME signature.
Is the acquisition valid as evidence in court?
The bundle follows recognised standards (ISO/IEC 27037, BagIt RFC 8493, RFC 3161, CASE/UCO) with an Ed25519 signature and a double timestamp; authenticity and integrity can be verified by anyone, even offline. For PEC the legal value of certified mail is added. The final assessment rests with the adjudicating authority.
Can multiple messages or whole folders be acquired?
Yes. You can acquire the whole mailbox (all folders) or select individual messages from any folder (INBOX, Sent, etc.). Each message is saved as the original EML and also rendered to PDF/PNG for review.

Collect evidence with the Email & PEC module.

Register for free and download C.E.R.T.O. Desktop for Windows and macOS from your client area.