Metadata for Recalled Messages
Based on a comment - I dug a little deeper
Last week, I did some testing to recall a message from within my tenant because the recent announcement that cross-tenant recall would be available later this Summer had me curious.
Alex rightly pointed out that some metadata indicating that a message sitting in the Purges folder was recalled, not deleted by the user, would be helpful. A
Alas, a quick look at the metadata for the recalled message didn’t show me anything.
This week, I dug a little deeper.
I not only analyzed the available data in the review set for the copy of the message that was recalled, but also the one that was sent. The hope was that somewhere in this exchange there would be some metadata to show that a message was recalled.
The news was not good on that front.
As mentioned last week, the recalled message was collected from the Purges folder, so it was not visible to the recipient in Outlook at all, which is what you’d want from a message recall. That was also the ony hint that it had been recalled.
The sent one was worse. It was still showing in the Sent Items folder of the sender. There was no metadata to suggest that it had been recalled. In fact, the metadata was not updated on the sent item at all.
What’s even worse was that my keyword search based on the email subject did also collect the email sent to the sender about the recall, but whether it was sucessful or not did not show in the email. There’s a link to get the report from Exchange:
In case you can’t read it, that last line is also very important:
Access to this report will expire after 7 days.
Let’s break this down. One week after a message is recalled, there will be evidence that an attempt was made to recall it, but not proof.
The recipient’s copy will go through the purge process, or remail in that hidden Exchange folder if there’s a retention policy or hold places.
The senders copy will sit in the Sent Items folder - as any sent item would.
The email with the link to the recall report will remain subject to being deleted by the user.
The report will have expired and be unavailable.
As I said last week, for an internal situation where the sender and recipents are all inisde your tenant, maybe none of this matters. If you’re recalling emails across tenants, that may be a different question. Or, maybe it will never matter that you can’t prove a message was recalled.
It’s not like I can point to a single case where this was an issue, maybe it never will be. It made for some interesting testing, though, and that’s what this newsletter is all about.
What do you think, will it ever matter? Are there indicators of a message being recalled with other forensic tools that exposed more metadata than Purview eDiscovery does?


