eDiscovery
legal hold · disclosureThe legal process of identifying, preserving, reviewing and handing over electronic records — email above all. It is the reason most people ever need to cut a mailbox down to a specific set of messages.
When a dispute, an investigation or a public-records request arrives, the parties must produce the relevant electronic communications. A legal hold usually comes first, freezing deletion so nothing disappears while the matter is live. Then comes the narrowing: from an entire mailbox down to the messages that fall within the agreed date range, custodians and topics.
For email this is a practical, unglamorous job. The archive has to be searched, the relevant messages selected, and a new file produced holding only those — because handing over an entire mailbox usually discloses far more than the request asked for. Message counts, date ranges and deduplication all have to hold up, since the other side may check them.
It is the workflow behind Mbox Viewer's export of a selection as a new MBOX: filter a large archive, select what belongs in the response, and write a mailbox containing exactly that, with the source file never modified. (Nothing here is legal advice — the standards that apply to a given matter are for the lawyers on it.)
Related terms
Google Workspace's retention and eDiscovery tool. An administrator can hold, search and export the mail of accounts across an organisation — and the export is MBOX.
The three mechanisms that establish whether a message really came from the domain it claims: SPF authorises sending servers, DKIM signs the message cryptographically, and DMARC ties the two to a published policy.
The process of detecting and removing duplicate email messages from an archive, typically by comparing Message-ID values, to avoid redundancy when merging multiple MBOX files.