When a scam or a harassment campaign unfolds over weeks, the details blur. A timeline fixes that: it turns a pile of screenshots and half-remembered events into a clear, ordered story that anyone can follow. It is the artifact lawyers and investigators ask for first, because it shows the pattern — and points to the proof behind every line.
Why a timeline matters
Individual messages rarely tell the story; the sequencedoes. A timeline shows escalation, repetition, and the link between events that look unrelated in isolation. It also keeps you honest: each entry has to point at a real piece of evidence, which stops a case from drifting into “I think” and “probably.”
How to structure each entry
- When: date and time, with the time zone. Use the original timestamp from the source where you can.
- What: one plain sentence describing the event.
- Who / where: the account, number, email, or platform involved.
- Evidence: a pointer to the underlying record — a file name, message, or screenshot reference — so the line can be verified.
Keep it credible
Pick one time zone and note it at the top. Preserve the originals your timeline references rather than relying on screenshots alone — original message metadata and headers carry the authoritative time. Stick to facts and leave conclusions out; the sequence makes the point on its own. For the underlying preservation step, see screenshots vs. forensic evidence.
Hand it off
Once the timeline is built, it is the spine of the case. SleuthX’s AI triage can help organize the events and the evidence behind them, with an examiner reviewing the result, and this guide covers how to package it for a lawyer or the police.

















