Evidence Search in EMLX File Format Using Digital Forensic Tool

MailXaminer | December 5th, 2020 | Forensics

EMLX is a mail message file format used to store a single email message in Mac operating system. It is also known as the Apple Mail email file because it is typically created by Apple/Mac Mail. EMLX consists of data files rather than documents or media because it just contains plain text. So, it can be viewed using any text editor and it can be opened in the Windows operating system.

Mac OS X Apple Mail use standard MBOX file format to store email messages. MBOX contains Apple Mail emails using a single EMLX file per email message format, that is, .emlx file extension. It is easy to edit and manage the email messages but exporting these message files becomes harder.

View EMLX File in Apple Mailbox

In Apple Mail, each message is stored individually in an EMLX file format instead of storing the email messages in a mailbox. To locate the mailbox in your Mac system, go to the “menu bar” then, go to the folder and enter –

“ ~user/Library/Mail/Mailboxes/

Here, you will get the mailbox. Click on the mailbox > message, and you will see all the emails with .emlx file extension.

Local folders of each mailbox contain two directories. For example, if a folder is named as “Draft” then there will be two directories Draft.mbox and Draft.sbd. The directory with .sbd extension is the subdirectory which contains only subfolders without messages. And .mbox file contains the messages. The individual EMLX files are stored within each mailbox folder. In which each email message is saved separately with .emlx file extension.

Evidence Extraction from EMLX File Format in Digital Forensics

In digital forensics, email data is a great source to extract evidence. But the examination of email data is a difficult process because there are numerous email clients along with their supported email file formats. Analysis of EMLX file extension is useful in the case of Apple Mail message data. EMLX files can access using any text editor. Evidence extraction during the investigation cannot be done properly using text editors. MailXaminer provides an efficient solution to analyze and extract evidence from the EMLX file.

MailXaminer is an Email Forensics Tool that provides a wide variety of advanced features to analyze email data. Tool supports 20+ file formats used by different email clients. This forensic software is designed in such a way that it can be easily used by a layman as well as a forensic examiner. User just needs to create a case, add the data source, and then start the examination process in a systematic way using its amazing features.

Add EMLX File in MailXaminer

The tool provides the option to add the email files with various different file formats which is supported by different email clients. To add the EMLX file into the MailXaminer tool to examine the email data and extract the evidence. Click on the tab “Add Evidence”, then choose the EML/EMLX (*.eml,*.emlx) from the add file window and add the data file with EMLX file format by clicking on “Browse”.

Add EMLX File

Preview Email Data from EMLX File

EMLX file format is supported by the text editors. So, it can be accessed with the help of text editors like Notepad, MS Word, Notepad++, etc. But during the forensic investigation, sometimes investigators need to extract evidence in different aspects. For that, this forensic tool provides the option to preview EMLX file format in different views such as “Mail, Hex, Properties, Message Header, MIME, Email Hop, HTML, RTF, Attachments, and Word Cloud”. Each view gives different information related to the email message which helps to analyze emails with different aspects.

Preview Email Data

View and Analyze Attachments

Email forensic tool MailXaminer provides the option to view and analyze all attachments of data files within a list. Users can select and view the attachments one by one without opening the whole email message. It saves time of the examiner while examining the images and attachments of the emails.

Analyze Attachments

Find Evidence with Powerful Search Mechanism

MailXaminer provides an advanced search algorithm that helps to fetch out the required data just by entering some related keywords. While examining the large data files, examiners face issues to find some specific data. The email forensic tool provides a powerful search mechanism that helps examiners to analyze and extract evidence systematically. It provides various search options with different search algorithms such as General Search, Proximity Search, Regular Expression, Stem Search, Fuzzy Search, and Wildcard Search.

Powerful Search Mechanism

Export EMLX Evidence Report

With MailXaminer, after the examination process, user can export and download evidential reports in the desired file format. It provides different file format options such as EML, MSG, HTML, PDF, etc. Users can save the report in any of the file formats at the desired destination. The PRINT option is also available which can be used to print the evidence report directly.

Export EMLX File Format

Conclusion

EMLX file format is generated by Apple Mail in Mac operating system. This file format is used to store the single mail message of Apple Mail rather than the entire mailbox data. EMLX can also be accessed using any text editor because it is a data file, which contains textual data. MailXaminer is a remarkable Digital Forensic Tool which helps the investigators to examine the EMLX files in different views and extract all information related to the email data.