How to produce emails in discovery
Most written guidance on email production is aimed at firms with a litigation-support department, a review platform and a vendor on retainer. This one is aimed at the case where the whole production is a paralegal, a partner who wants it done this week, and a couple of mailboxes.
The stages are the same at every scale. What changes is how much machinery each one needs, and the failure mode for a small firm is not skipping a stage — it is running a large production with small-production tools and discovering the problem at the numbering step.
Scope before anything else
Every expensive email production went wrong at the scope stage, usually by not having one. Three questions, answered in writing:
Whose mail? The custodians. Under-identify and you produce an incomplete set, which the other side discovers by noticing a message addressed to someone whose mailbox you never collected. Over-identify and you pay to review mailboxes that were never going to matter.
What period? A date range tied to the events in dispute, not to the life of the relationship.
Which terms? Search terms are where scope becomes concrete. Agreeing them with the other side converts a later argument about adequacy into an argument about an agreement you both signed.
None of this needs to be adversarial. Most opposing counsel would rather agree scope than litigate it, because the alternative costs them too.
Preserve first, collect second
The order matters and it is frequently reversed. A litigation hold and the suspension of automatic deletion should precede collection, because collection takes time and deletion policies do not pause out of politeness.
The recurring disaster is the departed employee. Offboarding routinely deletes mailboxes on a schedule, often within 30 days, and it runs automatically. If a likely custodian has left or is leaving, that is a day-one question.
Collect without damaging what you collect
The mechanics vary by mail client and are covered in exporting email as EML. The principles do not vary:
Export, do not forward. A forward is a new message. It carries your headers, today’s date, and the original buried in the body. It is fine for reading and poor for producing.
Take whole threads. Pulling individual hits and leaving the surrounding messages invites the accusation that context was stripped, and it is a tedious accusation to rebut.
Do not filter by reading first. Collect against the agreed scope, then review. Deciding what to collect based on what looks helpful is the shape of a spoliation problem.
Write down what you did. Who, when, from which mailbox, by what method. This is chain of custody and at this scale it is a paragraph, not a protocol.
Cull hard, and cull early
Reviewing is the expensive stage, so everything that reduces what reaches review pays for itself several times over.
The mechanical wins are duplicates and threads. The same message exists in the sender’s mailbox and every recipient’s, so a multi-custodian collection is substantially the same mail repeated. And a twelve-message thread quoted at each reply contains its own earlier messages twelve times — reviewing every message in full means reading the first one a dozen times.
Deduplication and thread-suppression are the two features that most justify a review platform. Without one, the manual substitute is sorting by subject line and by date and reviewing threads as units rather than as loose messages.
Review for both things at once
Responsiveness and privilege in a single pass. Two passes over the same material is twice the reading for no additional accuracy.
Record the basis for each privilege call at the moment you make it. The privilege log has to state a basis for every withheld document, and reconstructing your reasoning three weeks later — from a document you have now read once — is slower and less accurate than a half-sentence noted at the time.
Two traps worth naming. Copying a lawyer does not make a business email privileged; the question is whether the communication was for the purpose of giving or getting legal advice, and blanket assertions over everything a lawyer touched draw motions to compel. And an attachment is a separate document from the message that carried it — a privileged cover email can transmit an unprivileged attachment.
Convert once, through one pipeline
This is the stage where small productions create work for themselves.
An email’s page count is not inherent the way a scanned page’s is. It is produced by whatever rendered the message, and two tools will paginate the same message differently. A set assembled from messages printed by three people through three different clients has three header layouts and inconsistent pagination, and it will not reconcile cleanly after stamping.
Rendering the whole responsive set in one pass, with one tool, fixes it. That
is the specific job EML Exhibit does: a folder of .eml
files becomes paginated PDFs with From, To, CC, Date and Subject
above each body, attachments extracted as unmodified originals, filenames
carrying a matter prefix.
Number everything, then pull
Stamp the complete reviewed set, including the documents you intend to withhold. Then remove the privileged documents and log them by the numbers they were assigned.
Doing it in the other order leaves withheld documents with no stable identifier, which makes the log harder to write, harder for the other side to assess, and awkward to amend if a privilege claim is later dropped. Gaps in the produced sequence are expected — the log is what accounts for them. See how to Bates stamp emails.
Deliver what was actually agreed
Two broad shapes. PDF for exhibits, motions, and small productions going to humans. Imaged TIFF with a load file where the receiving party is ingesting into a review platform — see PDF vs TIFF productions.
Confirm which before formatting. Producing in the wrong format means re-imaging and re-stamping the entire set, and it is the most avoidable rework in the whole process.
Keep more than you produce
When it is over, retain the natives, the produced set, the load file, the privilege log, and the record of who did what. The produced PDFs are the least valuable of these and the ones most often kept alone. The natives are what answer any later question about what was produced and whether it was complete.
None of this is legal advice. Discovery obligations, proportionality, privilege and the consequences of getting them wrong vary by jurisdiction and by the order governing your matter. Confirm what applies to you.
Doing it in EML Exhibit
-
Fix the scope in writing
Custodians, date range, and search terms. Get them agreed with the other side where you can, and record what was agreed. Scope you can point to later is worth more than scope you can defend cleverly.
-
Preserve before you collect
Issue the litigation hold and suspend auto-deletion first. Collection can be redone; a mailbox that was purged on an offboarding policy cannot.
-
Collect from the mailbox, not from forwards
Export messages as .eml files from the client that will give them to you. Forwarding messages to yourself creates new messages with new headers and is the most common way a small production quietly damages its own evidence.
-
Cull to what is actually responsive
Filter by custodian, date range and terms before review, not after. Reviewing material that was never in scope is the single largest avoidable cost in a small production.
-
Review for responsiveness and privilege in one pass
Read what survives the cull. Mark responsive, mark privileged, and note the basis for each privilege call as you go — reconstructing that basis later takes longer than recording it now.
-
Convert the whole set in one pass
Render every message through the same pipeline so pagination and header presentation are identical across the production. Mixed-source PDFs are the usual reason a numbered set will not reconcile.
-
Number everything, then pull
Bates stamp the complete set including documents you intend to withhold, then remove the privileged documents and log them by their assigned numbers.
-
Deliver in the agreed format
PDF for exhibits and small productions, imaged TIFF with a load file where the other side is loading into a platform. Confirm which before you format, not after.
How small is small enough to do this in-house?
A useful rule of thumb: one or two cooperative custodians, a few hundred responsive messages after culling, and no serious prospect that the collection method itself gets litigated. Past that — multiple custodians, thousands of documents, an adverse custodian, or a spoliation allegation in the air — the cost of a vendor is smaller than the cost of doing it twice.
What is the most common mistake?
Collecting by forwarding. It feels efficient and it creates a new message
every time: new headers, new date, new Message-ID, with the original
nested in the body. The evidence is still there but the envelope is
yours, not the sender’s. See
email metadata and admissibility.
Do we have to produce native files?
It depends on what was requested, what was agreed, and what governs your matter. The common compromise is imaged documents with selected natives — spreadsheets especially, because an imaged spreadsheet loses its formulas and is often unreadable. Settle it at meet-and-confer rather than unilaterally; format disputes discovered after production mean re-formatting and re-numbering.
How long does a small production actually take?
The conversion and numbering is an afternoon. The review is the schedule. Reading and privilege-calling several hundred messages carefully is measured in days, and it is the stage that cannot be compressed by better tooling, only by a tighter cull upstream.
What do we keep afterwards?
The natives, the produced set, the load file if there was one, the privilege log, and a record of who collected what and when. The produced PDFs are the least important item on that list and the one people are most likely to keep in isolation.