Proovik
Back to blog
Legal

How to certify an email, a WhatsApp chat or a screenshot as evidence

Equipo Proovik · Sep 9, 2026 · 9 min read

To certify an email, a WhatsApp conversation or a screenshot as evidence, keep the most complete file you can obtain (the message with its headers, the exported chat with attachments, the original screenshot) and seal its SHA-256 hash in a record nobody can alter, as soon as possible. The seal proves that the file existed on that date and has not changed since; the authenticity of the content is established by other means.

Why a lone screenshot is weak evidence

A screenshot is an image. It can be edited with any free program, fabricated from scratch with a web page that imitates the WhatsApp interface, and the time it displays is whatever the device clock said, which can be changed in seconds. If the other side challenges it, you have to prove it is genuine, and an image contains nothing you can use to do so.

The same goes for an email printed to PDF. What gives digital evidence its strength is not what you see but what can be checked: the technical headers of the message, the original chat database, the device it was received on and, above all, being able to show that the file you present is the same one that existed when the events took place.

What to keep in each case

Email

Save the complete message, not a printout. In most mail clients the option is called "Save as" or "Download original" and produces an .eml file (or .msg in Outlook). That file contains the technical headers: which servers the message passed through, when each of them received it, and the DKIM signatures added by the sender's server. A forensic expert can read them; from a PDF there is nothing to extract.

Attachments stay inside the .eml. Do not forward the message to another account "to keep it": forwarding creates a new message with new headers.

WhatsApp conversation

Use the app's own "Export chat" function and choose "Include media". You get a compressed file with the text of the whole conversation, the date and time of every message, and the photos, voice notes and documents exchanged. Do it as early as possible, from the phone that received the messages, and keep that phone without deleting the chat: the app's original database is what an expert will examine if the evidence is challenged.

If the conversation is still ongoing, export again every time relevant material is added and seal each export separately.

Screenshot

If a screenshot is all you can get (a post that may disappear, an app with no export), take it and seal the file immediately, without cropping or recompressing it. Keep the original exactly as it came off the device and, if you can, a separate document with the URL, the date and the context, sealed as well. The less time passes between the event and the seal, the more the priority it establishes is worth.

What the seal adds to each type of evidence

A timestamp does not turn weak evidence into strong evidence: it fixes in time the evidence you have.

Type of evidenceWhat it containsWhat is easy to manipulateWhat the seal adds
Email saved as .emlText, attachments and full technical headers (servers, timestamps, DKIM signatures)Editing the text; headers are harder to forge consistentlyProves that this file, headers included, existed on the seal date and has not changed
Email printed to PDFOnly what is visible: text, sender and date as displayed by the clientAny field, with a text editorProves the PDF existed on that date; adds nothing about its authenticity
WhatsApp export with mediaText of every message with date and time, plus photos, voice notes and documentsEditing the text file before sealing; detectable by comparing with the phoneProves the export existed on that date and has not changed; stronger if the phone is kept
ScreenshotAn image of what the screen displayedEverything: editing, compositing, fake chat generatorsProves the image existed on that date; sealed at the time, it establishes priority over later events

What the seal proves and what it does not

A cryptographic timestamp proves three things about a file: that it existed on the seal date, that it existed before any later event, and that the file you present today is identical to the one sealed back then. It is proof of existence and prior date, not of authorship or truthfulness.

It does not prove that the conversation took place as shown, that the sender is who they claim to be, or that the content is true. If you seal a fake screenshot, the seal proves that the fake screenshot existed on that date, nothing more. That is why you should seal the most complete file and do it early: the strength of the evidence comes from combining its quality with the priority of the seal.

When you need more: if the stakes are high, a notarial deed of display (the notary records what appears on your screen) or a digital forensics report provide what a seal cannot. The three complement each other, and the court weighs them freely. The five methods for fixing a date are compared in how to prove that a document existed on a date.

What the law says

In summary, in Spanish civil proceedings:

  • Article 299 of the Civil Procedure Act (LEC) lists the means of evidence, private documents among them, and its paragraph 2 also admits means of reproducing words, sound and images, and instruments that allow data relevant to the proceedings to be stored, accessed or reproduced. An email, a chat or a screenshot comes in through one of those two doors.
  • Articles 382 to 384 LEC govern how those instruments are submitted, allow them to be accompanied by transcripts and expert reports, and provide that the court assesses them according to the rules of sound judgement.
  • Article 326 LEC governs the evidential weight of private documents: if they are not challenged, they have the same effect as public documents, and if they are challenged, the party relying on them may request expert comparison or other evidence (paragraph 2). Since Law 6/2020 of 11 November, paragraph 3 provides that, where the authenticity, integrity or accuracy of date and time of an electronic document backed by a non-qualified trust service is challenged, evidence is taken under paragraph 2 and Regulation (EU) 910/2014; paragraph 4 reserves the presumption for qualified services on the trusted list.

On the timestamp itself, Regulation (EU) No 910/2014 (eIDAS) is clear in Article 41(1): "An electronic time stamp shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements of the qualified electronic time stamp." Article 41(2) limits the presumption to qualified ones: "A qualified electronic time stamp shall enjoy the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound." A non-qualified timestamp such as Proovik's is admissible; if the date is disputed, the party relying on it proves it through the mathematical check of the proof, and the court weighs it. The difference between the two kinds of timestamp is explained in qualified versus non-qualified electronic time stamps.

This is general information, not legal advice; rules differ outside Spain.

How to do it with Proovik

An example. You have exported a conversation with a supplier and you have supplier-chat-2026-09.zip. You open the certification page and drop the file. Your browser computes its SHA-256; the ZIP is not uploaded anywhere, only that 32-byte fingerprint travels, and it is written into a transaction on the Kaspa network. The seal is normally confirmed within seconds and you download a PDF certificate with the block timestamp and the PVK-PROOF/1 proof package. You can start without an account.

Keep the ZIP and the PDF together. If you ever have to produce them, anyone (the other party, an expert, the court) can check on the verification page that the file produces exactly that hash and that the hash was on the chain on that date, without relying on Proovik. The seal proves the existence, prior date and integrity of the file; it does not prove who wrote the messages or that they are true, and it is a non-qualified electronic time stamp without the presumption of Article 41(2). How the anchoring works is explained in what a blockchain timestamp is. For contracts and supplier agreements there is a specific guide on protecting an NDA or a supplier contract and another on giving a digital contract a provable date.

Frequently asked questions

Is sealing just the screenshot enough?

It is better than nothing, especially if you seal it at the time, but it is the weakest of the four types of evidence because an image contains nothing checkable. Whenever you can, seal the complete file: the email in .eml format or the chat export with media.

What if I delete the chat after sealing the export?

The seal still proves that the export existed on that date and has not changed. What you lose is the possibility of an expert comparing the export with the original database on the phone, which is the strongest reinforcement if the other side challenges it.

Can I seal an email I received years ago?

Yes, but the seal will prove that the file existed on the date you seal it, not on the date of the email. The priority it establishes starts from the seal. The message headers keep their own timestamps, which an expert can analyse; the seal guarantees those headers have not been modified since you sealed the file.

Does the seal prove that the other person wrote the message?

No. The seal proves that the file existed on a date and has not changed. Who wrote the message is established by other means: the email headers and signatures, ownership of the phone number, forensic examination of the device, or the other party's acknowledgement.

Sources

Share article

Link copied
Reference guides

From reading to proof

The three guides that explain where proof of existence and prior date comes from, and the two actions to check it yourself.

How to prove a document existed on a date

The methods that fix a document’s date, compared side by side, and how far each one goes.

Blockchain time stamping

What a non-qualified electronic time stamp is (Art. 3(16) EU Reg. 910/2014) and how anyone can check it without us.

Traceability with EPCIS 2.0

Supply-chain events stamped one by one, with GS1 Digital Link and public verification.