Home |  Log In  
Forensics and eDiscovery technologies for Mac OS X, Microsoft Windows, and Linux

Recovering Email from Mac OS X Mail

Since the release of Mac OS X, Mail.app has been the default email application. Mail stored emails in .mbox files up until the release of Mac OS X Tiger 10.4, at which point Apple changed the default file type to .emlx. The instructions below outline the process used to recover and investigate the contents of these formats.

When looking for email on suspect Mac OS X drive, the standard location for the stored email is ~/Users/"USERNAME"/Library/Mail

You can use either the Analyze or Salvage functions of MacForensicsLab to examine Mail files.

  • To use the Analyze function, use search query of ".mbox" for systems from Mac OS X 10.0-10.3 and ".emlx" for Mac OS X 10.4 Tiger and 10.5 Leopard.
  • When using the Salvage function, direct the search to ~/Users/"USERNAME"/Library/Mail and do a Salvage of that location. Both .mbox and .emlx files will automatically be found.

 | Home | 

Copyright © 2006 - 2010 MacForensicsLab Inc.
Phone +1 (510) 870-7883 - Fax +1 (510) 868 3407
Mac and the Mac logo are trademarks of Apple Computer, Inc., registered in the U.S. and other countries.

Forensics Technologies - designed to perform investigations, for law enforcement and eDiscovery professionals.

MacForensicsLab - The only effective cross-platform weapon in the war on Cyber Crime and Digital Terrorism,
with unique tools designed to combat identity theft and child pornography.