One message,
with the thread it belongs to.
The mail handler opens a container archive down to the individual message, and keeps what makes a message evidence: its headers, its place in the thread, and the attachments that travelled with it.
LLX-HANDLER-MSG · R3 · 6 formats
Four things an exported mailbox loses.
Full headers
Sender, recipients, dates and routing are read as fields — the part of a message that is hardest to dispute.
Thread position
A reply is read as a reply: the message it answers and the ones that follow stay attached to it.
Attachments in place
Each attachment is read by its own handler and stays bound to the message that carried it, with its own digest.
Duplicates and near-duplicates
The same message across several mailboxes is recognised as one, with every copy and its custody listed.
The questions correspondence usually decides.
When a party was actually notified
A notice is cited to its message, with the header dates rather than the date printed in the body.
ChronologyWhat was known, and by whom
Recipients and forwards are read as structure, so knowledge can be established rather than assumed.
KnowledgeWhether an attachment was ever sent
Attachments are indexed with their messages, so the absence of a document is itself a finding.
DisclosureRead in place, in the format it arrived in.
The file is never converted or re-saved. It is read where it lies, and the handler records a SHA-512 of the bytes it read — so a passage cited today can be replayed against the same file years from now.