Free PST Viewer · Version 1.6.23

Built in Rust

Open PST Files Without Outlook. Free.

A PST file viewer and OST viewer for Windows and macOS. Drop a PST or OST file and read your emails. Search, browse folders, view attachments. No Outlook, no Office 365.

Free, no signup· EV code-signed· SHA-256 verified· Windows and macOS· Since 2006

Runs entirely on your machine, including the AI. Nothing, not even the AI analysis, is sent to a cloud.

The license check runs at startup, before any evidence is opened. While a case is loaded PST Viewer touches the network for nothing at all.

Also opens modern OST, MSG and EML files. See our dedicated OST Viewer page.

Sherlock Forensics PST Viewer opens PST, OST (including modern Outlook 2013+ OST), MSG and EML email files on Windows and macOS without Outlook. Browse folders, search messages, view attachments and export emails. Starting with version 1.4.0, the free tier previews 50 messages per folder with 3 file opens per day; the Forensic Edition ($67) removes both limits. Version 1.4.0 also introduces damaged-PST salvage: the viewer diagnoses truncated and corrupt PSTs that Outlook cannot open and reconstructs surviving messages from the header and data pages.

One Forensic Edition license activates on Windows and macOS. Your existing key activates on Mac using one seat, like any machine, so there is no second purchase.

You are reading your emails in seconds.

1.6.23 installs with a quick per-user installer that needs no admin prompt, so it suits locked-down examiner workstations. It bundles the Microsoft runtime it needs, so it runs on a clean machine with nothing preinstalled. Every engine is included. The AI models download on first run for licensed users. Decline them and you still have a complete, working viewer. Prefer everything in one file? A full offline version is available below.

Per-user install, no admin· No signup· SHA-256 verified· Since 2006

New in 1.6.5

Activate on a machine that never touches the network.

An evidence workstation is often not allowed to reach the internet, which until now meant it could not be licensed at all. In 1.6.5 it can. The examiner exports a small request file that names the machine and nothing else, carries it out on removable media, and at sherlockforensics.com/activate uploads it and pastes the licence key from their email. The activation that comes back unlocks the tool with no network call on the evidence machine.

  • The licence key never enters the secure area. It is pasted on the internet side, so the examiner carries a file out rather than carrying a key in.
  • The request file names one machine and nothing else. No licence key, no case data, no evidence. It is plain text and can be read before it leaves the enclave.
  • An activation binds to one machine and works on no other. Verified in testing: a token issued for one machine was refused on a second.
  • Two routes: upload the request file or type the machine id with the six-character check code shown beside it.

Also in 1.6.5, clearer activation error messages:

  • An unrecognised licence key is now reported as a bad key, not a network failure, so a customer with a wrong key is no longer sent to check an internet connection that was fine.
  • A genuinely unreachable licence server now names what failed and the commonest cause on a managed network: activation goes out through the system curl, which does not inherit the browser's proxy, so a working browser tells you nothing.
  • An activation damaged in transit is now named as damaged with advice to have it reissued, instead of being misreported as a paste error.
  • A key issued for different hardware now says so and names the customer it was issued to, instead of a bare "licence is not active".

New to PST files? See our step-by-step guide to opening PST files. Or see how we compare to other PST viewers.

New in v1.6.19

Produce everything except privileged, across every custodian PST

Version 1.6.23 adds privilege withholding for eDiscovery. Import the client review spreadsheet once and match it in a single pass against all of a custodian's PST archives, so each privileged email is marked in the PST that actually holds it. Then export everything except the marked messages to a new PST, EML, MSG or mbox. Every withholding export writes a CSV of exactly what was held back: source archive, folder, date, sender, recipients, subject, attachment flag and item id, the starting point for a privilege log. The list is SHA-256 hashed into the export report and the chain of custody log, exported + withheld counts are reconciled against the folder total with any gap reported, and the export fails closed if the withheld list cannot be written. One combined match report flags any row that matched no PST as Unmatched, so the reviewer can show every privileged row was caught. Nothing is marked blindly: every match is previewed and a subject line alone never marks a message.

New in v1.6.16

Localized interface and reports, evidence left untouched

Version 1.6.23 adds a localized interface and PDF reports in 11 languages. Pick your language from the flag menu in Settings and the whole interface switches instantly, and reports export in the language you chose. Your evidence is never translated. Subjects, senders, bodies and folder names stay exactly as found, and custody logs, manifests, exports and hash files stay in English so they verify identically from one lab to the next.

Available in 11 languages: English, Polish, Spanish, Chinese (Simplified), French, Portuguese (BR), Russian, German, Japanese, Indonesian and Turkish.

Reports now render Cyrillic, Chinese, Japanese, Polish and Turkish evidence exactly as stored. Earlier versions could misprint those characters, so if you reported on international mail before 1.6.16 it is worth re-running those reports.

New in v1.5.6

Loose .msg and .eml folders are now first-class

Work directly from exported messages. Point the viewer at a folder of loose .msg or .eml files and run YARA sensitive-data scanning, attachment threat scanning, media inventory, timeline and communication map, with report and export of the messages you mark. Large folders stay responsive and hold in a fraction of the memory they once did. Data Recovery and Find in Archive still need a PST or OST container.

New in v1.5.0

On-device AI, deleted recovery on encrypted stores, four threat scanners

  • On-device AI (Windows and macOS). Transcribe voicemail and audio attachments into full-text-searchable text. Describe images and video frames while pulling out the text inside them, so a photographed document or a screenshot becomes searchable. It all runs on your own machine.
  • Four threat scanners. Four threat scanners run over the whole archive: malicious Office files, spoofing and authentication failures, tracking and active HTML content, PDF threats. Results are a sortable severity table you can filter and export.
  • Deleted-item recovery on encrypted stores. Most Outlook PST and OST files are encrypted by default, where older carving found nothing. 1.5.0 recovers over 50,000 deleted items from a real encrypted archive, resumable mid-scan, exported as a hashed CSV.
  • Modern OST accuracy. Sender attribution, BCC recipients and real SMTP addresses now resolve correctly where 1.4.0 dropped or mislabeled them. The tool now tells there is nothing here apart from this could not be read.
  • Sensitive-data scan by jurisdiction. Tabs by jurisdiction (Canada, the United States, Australia, the United Kingdom) and a common tab, with real checksum validation instead of pattern matching for far fewer false positives.
  • Chain of custody that survives a sealed log. A sealed log now continues in a cryptographically chained segment instead of refusing new entries, so returning to a case stays append-only and tamper-evident. Its signature is verifiable from the panel.
  • Export, rebuilt. One panel. Select multiple folders at once. Export individual messages as MSG and EML alongside whole-archive PST and MBOX.
  • Faster and smoother. Large folders stream in instead of freezing a 90,000-message inbox. Every table takes keyboard navigation and sorting. A fixed bug surfaced 2,516 attachments that had been hidden.

New in v1.4.0

Recovers Truncated and Corrupt PSTs That Outlook Cannot Open

Version 1.4.0 introduces damaged-PST salvage. When a PST has a valid header but a truncated body or a corrupt or missing internal index, Outlook refuses to open the file. Sherlock Forensics PST Viewer diagnoses the specific failure and reconstructs surviving messages from the intact data pages. The reconstruction runs read-only on the evidence file so the source is never modified.

What the Diagnostic Shows

The viewer inspects the PST header and reports the exact mismatch in plain language. Example: "Header declares 9 GB. File on disk is 5 GB. Internal index missing." The diagnosis surfaces before any reconstruction attempt so the examiner knows what condition the file is in.

How the Reconstruction Works

Sherlock walks the data pages that remain intact and rebuilds the folder tree and the message set from surviving MAPI records. Messages that carved successfully carry their original headers, metadata and attachments. Messages whose data pages were lost in the truncation are documented in the diagnostic report but cannot be reconstructed.

Why This Is a Real Differentiator

Sherlock accepts and reconstructs a PST that fails initial header and index validation, where EnCase, Cellebrite and AXIOM typically decline it. For investigators handling PST evidence with damaged sources this is the difference between "no evidence available" and "here is what survived."

Free tier: receives the diagnostic and a Forensic Edition upgrade prompt. Forensic Edition ($67): performs the full reconstruction and exports the recovered messages to PST, MSG, EML or court-ready PDF report.

New in v1.2.0

Native Modern OST Support

Sherlock Forensics PST Viewer opens modern Outlook OST files used by Outlook 2013 and newer, Microsoft 365 desktop and cached-Exchange profiles. This is the 4 KB-page PFF-variant format that standard PST parsers reject. Also adds whole-archive keyword search, one-click document export, per-folder PDF reports and a unified findings catalog.

Modern OST

Native Modern OST

Opens 4 KB-page PFF-variant OST files (wMagicClient=0x4F53, wVer=36) used by Outlook 2013+, Microsoft 365 and cached-Exchange profiles. Full folder tree, message list and body preview. Free to use.

Modern OST Diagnostics

Authoritative counts derived from the NBT index: total messages, expected attachments, contents-table rows, orphan list. Verify extraction completeness against ground truth.

Orphan Detection

NIDs present in the NBT but absent from any folder are still enumerated. zlib DEFLATE decompression for compressed blocks. System-folder hiding for empty Outlook-internal folders.

Search and Export

Find in Archive

Whole-PST/OST keyword search across subject, body, from, to and attachment filenames. Background worker with streaming results. Session history lets you replay past searches instantly. Markable hits feed into report scope.

Export Documents

One-click extraction of all attached PDFs, Word, Excel, PowerPoint, OpenDocument, RTF, TXT and CSV files. Flat directory output with manifest.csv and SHA-256 per file. Scope picker and type filter.

Expanded Reports

Whole-archive PDF report (single searchable PDF of every email), per-folder reports and marked-only reports. Streaming PDF generator prevents OOM on multi-GB archives. Works on both PST and modern OST.

Forensic Improvements

Findings Catalog

Unified sidebar showing every accumulated result: current and historic searches, pattern-scan matches and Data Recovery item counts. Click any row to jump back to that result set.

Data Recovery Sidebar

Dedicated sidebar item running all 4 carving methods. Quality filter hides low-signal fragments by default. Click any recovered item for inline detail with Save raw bytes and educational forensic notes.

Crash Diagnostics

Structured crash logs with panic message, file:line, backtrace and version. Auto-detected on startup with one-click submission to Sherlock. Per-message crash isolation in search and extract workers.

v1.1.0

Full Forensic Workstation

Sherlock Forensics PST Viewer transforms the viewer into a full forensic workstation with deleted-item recovery, pattern-based sensitive-data scanning, activity timelines, communication mapping, cross-archive search and multi-monitor support. Every new capability operates in read-only mode preserving evidence integrity.

Analysis Tools

Activity Timeline

Interactive histogram of all mailbox activity. Group by day, week, month or hour-of-day. Mouse-wheel zoom from full-archive down to single-day. Anomaly bars (volume > mean + 2 stddev) highlighted in yellow so off-hours bursts pop at a glance.

Communication Map

Force-directed graph of every sender/recipient relationship. PST owner pinned at center. Node sizes scale to message volume. Click any node for a sortable per-contact message list. Find collusion and unusual contact patterns at a glance.

Cross-PST Search

Load multiple custodians' archives into one search modal. Live substring matching across subjects, senders and recipients. Per-archive hit counts. Double-click any hit to jump straight into that PST, that folder, that message.

Sensitive Data Scanning

Pattern-scan every message body and attachment. Built-in rules for SSNs, credit cards (Luhn validated), AWS keys, Bitcoin (Base58Check), IBANs, phone numbers and IPv4. Format-validated to minimize false positives.

Forensic Recovery

Deleted-Item Recovery

Four independent carving methods scan unallocated PST space: regex scrape for RFC-822 headers, heap-on-node carving, compressed-RTF body recovery and B-tree zombie hunt. Per-method panic isolation. Confidence ratings on every recovered item.

MAPI Property Explorer

Every property the PST stores on a message in one filterable table. Hex IDs, named properties, raw value types. Read the Received hop chain, conversation index, message flags and internal Exchange properties.

Attachment Safe View

Preview attachments without opening them in the OS default handler. Type detection, hex header inspection, plain-text rendering of safe formats. Avoid drive-by exploits in adversarial archives.

Workflow

Multi-Monitor Analysis

Undock the Activity Timeline, Communication Map and Generate Report panes to their own OS-level windows. Drag to a second monitor, resize independently. The main app stays free for folder browsing.

Mark-and-Report

Marks persist across restarts (SHA-256 keyed). Shift+click range-mark. Show marked only filter. Per-folder badge counts. Report modal with per-row remove, PDF/CSV/JSON picker and auto-open on generation.

Verifiable Export

Every bulk export produces an Ed25519-signed manifest. Any third party can verify the export has not been altered using just a hash and a public key. No Sherlock install required to verify.

In-Message Search

Ctrl+F inside any message body. Every match highlights in place with next/previous navigation. Digit-aware mode: searching 1625941771559000 finds 1625 9417 7155 9000 with separators ignored.

New in v0.1.6

MSG + EML Support

Sherlock Forensics PST Viewer reads individual Outlook .msg and RFC-822 .eml messages with the same forensic rigor as the PST path. Open a single file or point it at an entire folder for batch analysis with optional recursive scanning.

What Examiners Can Now Do

  • Single file analysis - drop a .msg or .eml on the viewer for full subject/from/to/body/attachments preview in under a second
  • Folder mode - point it at a folder of messages and every .msg and .eml becomes a browsable list with optional recursive scanning
  • Visual triage - sort, filter and check off messages that matter, then generate a court-ready PDF covering just those
  • Attachment extraction - one click per file or bulk "Save all" with per-attachment SHA-256 logging (Forensic Edition)

Forensic-Grade Analysis

Every MSG/EML opened gets an automatic forensic readout alongside the normal preview:

Message Class Translation

Meeting requests, delivery reports, S/MIME signed messages and internal Exchange messages translated into plain language.

MSG Encoding Detection

Unicode vs ANSI encoding surfaced clearly. Critical for non-Latin character evidence.

MAPI Timestamps Side-by-Side

Created, Modified, Submit and Delivery timestamps shown together so divergences jump out immediately.

SMTP Transport Chain

Every Received header parsed into a visual hop-by-hop trail. Single-line origin-to-destination summary answers "where did this message come from" at a glance.

Authentication Results

SPF, DKIM and DMARC results as recorded by the receiving mail server, in plain English. Reported from the message headers, not re-verified by the tool.

Anomaly Flags

Missing sender, auth failures, internal Exchange messages, unverifiable signatures, Message-ID/sender domain mismatches. All flagged automatically.

Chain of Custody

  • Every file opened gets its own SHA-256 computed locally (never uploaded)
  • Folder mode produces a manifest hash - SHA-256 over every file's path + hash, reproducible by any third party
  • Every operator action (open, view, mark, save attachment, generate report) is appended to the per-evidence chain-of-custody log

Compare

Free vs Pro

FeatureFreePro ($67)
Messages previewed per folder (v1.4.0+)50 (per folder)Unlimited
File opens per day (v1.4.0+)3 distinct files (resets at midnight)Unlimited
Damaged-PST salvage reconstruction (v1.4.0+)Diagnosis onlyFull reconstruction
Open PST/OST files (including modern Outlook OST)YesYes
Open MSG/EML filesYesYes
Folder mode (batch MSG/EML scan)YesYes
View emails, contacts, calendarYesYes
SHA256 hash verificationYesYes
SMTP transport chain visualizationYesYes
SPF/DKIM/DMARC authentication resultsYesYes
Modern OST diagnostics (NBT counts)YesYes
Anomaly detection flagsYesYes
MSG encoding detection (Unicode/ANSI)YesYes
Chain of custody loggingYesYes
Crash diagnostics + submissionYesYes
Individual attachment saveYesYes
Multi-monitor detachable windowsYesYes
In-message Ctrl+F search (digit-aware)YesYes
Mark persistence across restartsYesYes
Find in Archive (whole-archive keyword search)-Yes
Cross-PST/OST search-Yes
Communication map (force-directed graph)-Yes
Activity timeline with anomaly detection-Yes
Sensitive data scanning (pattern-based)-Yes
Export Documents (bulk attachment extraction)-Yes
Reports (whole-archive / per-folder / marked-only)-Yes
Data Recovery (4 carving methods)-Yes
Findings catalog-Yes
Deleted-item recovery-Yes
Attachment safe view-Yes
Verifiable export container (Ed25519)-Yes
Export to EML/MSG-Yes
Mbox export-Yes
PST export (Outlook-mountable)-Yes
Court-ready PDF reports-Yes
Per-message SHA-256 hashing-Yes
Sender IP attribution-Yes
Priority support-Yes

Forensic Reports

Court-Ready Forensic Reports

Sherlock Forensics PST Viewer Forensic Edition generates multi-page PDF forensic reports with SHA-256 hash verification per message, sender IP attribution from RFC-822 Received headers, SPF, DKIM and DMARC results as recorded by the receiving mail server (reported, not re-verified by the tool) and chain of custody documentation. Reports are produced from read-only analysis with reproducible results.

Why Courts Accept Sherlock Reports

Every report produced by Sherlock Forensics PST Viewer Forensic Edition is built on six pillars of forensic integrity that courts require for digital evidence admission.

SHA-256 Per Message

Each email in the report carries its own SHA-256 hash. Verify individual messages independently without needing access to the full PST archive.

Sender IP Attribution

Originating IP address and hostname extracted from the RFC-822 Received header chain. Establishes where each message actually came from.

SPF/DKIM/DMARC Per Message

Authentication-Results headers parsed for each message, showing the SPF, DKIM and DMARC verdicts the receiving mail server recorded at delivery time. Reported from the headers, not re-verified by the tool.

Chain of Custody

Examiner ID, tool version, session ID, timestamp and source file SHA-256 documented. Every action from file open to report generation is logged.

Read-Only Analysis

The source file is never written to. Your original evidence remains byte-for-byte identical before and after examination.

Reproducible Results

Any qualified examiner can open the same PST file and produce identical hash values and attribution data. Results do not depend on the examiner or machine.

What the PDF Report Contains

Each generated report is a multi-page PDF structured for court submission.

  • Title page with case metadata including tool version, license holder, session ID, timestamp and source file SHA-256
  • Per-email evidence cards with sender attribution (name, email address, source IP and hostname from Received headers) and Authentication-Results
  • Recipient tables documenting To, Cc and Bcc fields with display names
  • Body content with HTML converted to readable text
  • SHA-256 hash computed individually for each message in the report

Mark Emails. Generate Report.

The workflow is straightforward. Browse or search the PST archive to locate relevant messages. Check the box next to each email you want included. Click Generate Report. Sherlock Forensics PST Viewer Forensic Edition produces the court-ready PDF with all forensic metadata included automatically. Marks are stored separately from the evidence file, preserving source integrity.

Deleted-email recovery

Recover Deleted Emails from PST Files

When emails get deleted in Outlook, they do not always vanish from the PST file. Outlook moves them to the Deleted Items folder (soft delete). When you empty Deleted Items, the items go to a Recoverable Items dumpster retained for 14 to 30 days depending on retention policy (hard delete). Even after that window, the binary record often remains in the PST file as deallocated B-tree pages, invisible to Outlook but recoverable by a forensic-grade parser.

Sherlock Forensics PST Viewer delivers forensic-grade deleted item recovery using four carving methods to recover deleted emails:

  1. Deleted Items folder enumeration. Surfaces soft-deleted messages still sitting in the user's Deleted Items folder.
  2. Recoverable Items dumpster scan. Surfaces hard-deleted messages in the 14 to 30 day retention dumpster, the same store Outlook's "Recover Deleted Items From Server" relies on.
  3. B-tree page scan. Surfaces messages whose folder reference was deleted but whose binary message body remains in deallocated PST node pages, including emails that have aged out of the Recoverable Items dumpster.
  4. Slack-space carving. Surfaces fragments of permanently purged emails in the file's slack space between allocated B-tree pages, recovering message body fragments after Outlook's auto-compact has run.

The result: you can recover deleted emails and undelete the messages Outlook claims are gone, including permanently deleted items that have aged past the Recoverable Items dumpster window. The four carving methods run in a single scan against the PST file with full chain-of-custody logging. This is the same deleted item recovery surface that the Forensic Edition exports to court-ready PDF reports below.

Recovery matrix

Soft Delete vs Hard Delete vs Permanently Purged: What Is Actually Recoverable

Delete TypeWhat Outlook ShowsWhat Is In the PSTRecoverable by Sherlock?
Soft delete (Delete key)Item in Deleted Items folderFull message body in Deleted ItemsYes - trivial enumeration
Hard delete (Shift+Delete)Item gone from Deleted ItemsFull message body in Recoverable Items dumpster, 14 to 30 day retentionYes - dumpster scan
Permanently deleted (past dumpster window)Item completely gone from Outlook UIFolder reference deleted, body may remain in deallocated B-tree pagesYes - B-tree page scan recovers most
Compacted PST (Outlook auto-compact)Item gone, file size reducedSlack space may contain fragmentsPartial - slack carving recovers fragments
Securely wiped PSTItem gone, file size reduced, sectors overwrittenNothing recoverableNo - secure erase prevents forensic recovery

The deleted item recovery in Sherlock Forensics PST Viewer covers rows 1 through 4 in the matrix above. Row 5 (secure wipe) is not recoverable by any forensic tool because the binary content has been overwritten at the storage layer. For deleted emails that fall in rows 1 through 4, the deleted item recovery happens in a single Sherlock scan with chain-of-custody output. The same deleted item recovery feature handles permanently deleted Outlook items, hard-deleted messages past the dumpster window and slack-space fragments after auto-compact.

Pricing

One-Time Purchase.

One-time purchase. Your license is perpetual, yours for life. No subscription, no renewals.

Single License

$67 USD
1 machine. One-time purchase, yours for life.
  • All free features included
  • Deleted-item recovery (4 carving methods)
  • pattern-based sensitive-data scanning
  • Attachment safe view (sandboxed)
  • Verifiable export container (Ed25519)
  • Byte-level attachment extraction (single + bulk)
  • Export to EML/MSG formats
  • Mbox export
  • PST export (Outlook-mountable production)
  • Batch export entire PST archives
  • Court-ready PDF forensic reports
  • Chain of custody logging
  • Priority email support

Team License

$335 USD
5 machines. One-time purchase, yours for life. Ideal for small forensic teams.
  • All Single License features
  • Activate on up to 5 machines under one license key
  • One license covers the whole team, yours for life.
  • Priority email support

Need more than 5 seats? Contact us for larger team pricing.

Use Cases

Who Uses Sherlock Forensics PST Viewer

Legal and eDiscovery

Law firms and litigation support teams use Sherlock Forensics PST Viewer to review email archives during discovery. SHA256 hashing preserves evidentiary integrity. The Forensic Edition generates forensic reports suitable for court filing. Pairs with our expert witness services for testimony support.

IT Administrators

Recover and review emails from departed employees without reactivating Exchange or Microsoft 365 licenses. Search archived PST files for specific communications during internal audits. No Outlook installation required on review workstations.

Forensic Examiners

Purpose-built for forensic workflows. SHA256 hash verification on every message establishes chain of custody. Export individual messages or entire folders for inclusion in forensic investigation reports. Used alongside our full forensic tool suite.

HR and Compliance

Review archived employee email for policy violations, harassment investigations or regulatory compliance. Search across entire PST archives by keyword, date range or sender without involving IT. Chain of custody logging in Pro maintains investigation integrity.

Personal Use

Access old email backups without an active Outlook license. Search years of archived correspondence. View contacts and calendar entries stored in PST format. The free edition previews 50 messages per folder with 3 file opens per day. The Forensic Edition ($67) removes both limits.

Guide

How to Open a PST File Without Outlook

  1. Download Sherlock Forensics PST ViewerDownload the free installer from this page. 46.3 MB. SHA256 verified for integrity.
  2. Install and LaunchRun the installer on Windows 10 or 11. No admin privileges required. Launch from the Start menu.
  3. Open Your PST or OST FileClick Open File and browse to your .pst or .ost file. The viewer loads the folder structure and message list automatically.
  4. Search and BrowseUse the search bar to find emails by sender, subject or keyword. Browse Inbox, Sent Items, Contacts and Calendar folders.
  5. Verify and ExportView SHA256 hashes to confirm data integrity. Pro users can export to EML/MSG, generate forensic reports and log chain of custody.

Compare

Why Sherlock Forensics PST Viewer

Forensic Pedigree at a Fraction of the Cost

SysTools PST Viewer Forensic Edition costs $299 USD. Kernel PST Viewer charges $79 USD. Sherlock Forensics PST Viewer Forensic Edition is $67 USD with capabilities neither competitor offers: SHA256 hash verification per message, forensic report generation and chain of custody logging built by CISSP, ISSAP and ISSMP certified examiners with 20 years of courtroom experience.

Most PST viewers are built by software companies. Sherlock Forensics PST Viewer is built by forensic investigators who use it in active casework. The difference shows in the details: hash verification, evidence integrity and documentation that courts accept. Read our full 2026 PST viewer comparison or see our side-by-side PST viewer comparison table.

Changelog

Release History

v1.6.23 (2026-09-30) - Offline self-service seat release

Sherlock Forensics PST Viewer 1.6.23 adds offline self-service seat release. On an offline-activated machine, open About then Release seat to remove the activation and show a release code like 233-723; enter it with your license key under Manage your seats on the website to free the seat, so a license moves between air-gapped machines without support. Online machines release directly as before. Offline activations now last 12 months, and renewal uses the same request file without taking a seat. Released for Windows, macOS and Linux with the auto-updater payload live.

v1.6.22 (2026-09-30) - Machine ID + check code in About

Sherlock Forensics PST Viewer 1.6.22 is a small support release. The About panel (the PRO or FREE chip) now shows this machine's ID and a check code with a copy button on every install, the code an air-gapped customer quotes on the activation portal to free that machine's seat online without the offline box reaching the network. No new features, pricing unchanged. Released for Windows, macOS and Linux with the auto-updater payload live.

v1.6.21 (2026-09-30) - PST export reliability + self-service seat release

Sherlock Forensics PST Viewer 1.6.21 is a reliability + self-service release (including the 1.6.20 changes). It hardens PST export against large distribution-list mail: a long To or Cc line or messages with 200 or more recipients or attachments could previously stop a folder exporting or produce a PST that would not reopen, now fixed with the recipient line kept whole. A message that cannot be exported whole is kept as a flagged placeholder with the reason in the report + a sidecar CSV so the rest completes, and failures show in red + in chain of custody. It also adds self-service seat release: click the PRO chip then Release seat to free your own seat when moving machines. If you exported large distribution-list PSTs on an earlier version, re-export with 1.6.21. Released for Windows, macOS and Linux with the auto-updater payload live.

v1.6.19 (2026-09-29) - Privilege withholding for eDiscovery

Sherlock Forensics PST Viewer 1.6.19 adds privilege withholding across a custodian's PST archives. Import the client review spreadsheet once, match it in one pass against all of the custodian's PSTs so each privileged email is marked in the PST that holds it, then export all except marked to a new PST, EML, MSG or mbox. Every withholding export writes a SHA-256 hashed CSV of exactly what was withheld, exported + withheld counts are reconciled against the folder total, and the export fails closed if the list cannot be written. Also fixes a crash searching damaged archives and a window that reopened as a tiny square. Released for Windows, macOS and Linux with the auto-updater payload live.

v1.6.17 (2026-09-27) - More robust on damaged archives

Sherlock Forensics PST Viewer 1.6.17 is a maintenance release that hardens Find in Archive against damaged PST and OST files. A corrupt size field that could make the reader try to reserve tens of gigabytes and close is now checked against the data actually present, so a damaged item is flagged as unreadable and the rest of the archive is still searched. Normal archives read exactly as before, no new features, pricing unchanged. Released for Windows, macOS and Linux with the auto-updater payload live.

Full changelog and download verification for all versions →

Questions

PST Viewer FAQ

Is Sherlock Forensics PST Viewer really free?
Yes. The free edition opens PST and OST files, previews 50 messages per folder with 3 file opens per day, includes search and verifies SHA256 hashes. The Forensic Edition at $67 USD removes both limits and adds export, forensic reporting and chain of custody logging.
Do I need Microsoft Outlook to open a PST file?
No. Sherlock Forensics PST Viewer opens PST and OST files without Outlook installed. It reads the PST format directly using its own parser. No Microsoft Office license required.
What is the difference between PST and OST files?
PST (Personal Storage Table) files are offline copies of mailbox data that can be moved between machines. OST (Offline Storage Table) files are local cached copies tied to an Exchange or Microsoft 365 account. Sherlock Forensics PST Viewer opens both formats.
Can I use this for forensic investigations?
Yes. The tool computes SHA256 hashes for every message, which establishes data integrity for legal proceedings. The Forensic Edition adds forensic report generation and chain of custody logging suitable for court submission.
What operating systems are supported?
Windows 10 and Windows 11 (64-bit). Apple Silicon and Intel Macs on macOS 11 Big Sur or later. Linux as a Debian package for Ubuntu 22.04 or newer, Debian 12 or newer and Kali on 64-bit Intel or AMD. The macOS build is signed, notarized and stapled by Apple, so it opens with no Gatekeeper warning and needs no network check. All three platforms read PST, OST and Outlook for Mac (OLM) archives.
Does the Mac version read Outlook for Mac email?
Yes. Version 1.6.2 reads Outlook for Mac (OLM) archives on all three platforms: messages, folder tree, attachments, search, export and reports. It also salvages a damaged OLM archive whose index is gone, recovering messages a normal reader refuses outright. It still reads the PST and OST formats Windows Outlook and Exchange produce. Note that OLM is the Outlook for Mac format. Apple Mail uses a different format and is not read.
How large of a PST file can it handle?
Sherlock Forensics PST Viewer handles PST files up to 50 GB. Files over 20 GB may take longer to index on initial load. Performance depends on available system memory.
Is the $67 price a subscription?
No. The Forensic Edition is a one-time purchase of $67 USD. Your license is perpetual, it never expires, there is nothing to renew and there is no recurring charge. Buy it once and it is yours for life.
What is the difference between the free and Forensic editions?
Nothing is ever locked and no evidence is held hostage. The free edition opens, browses, searches and previews your PST and OST archives. The Forensic Edition ($67 one-time) adds the examiner tools: export, reports, timeline, recovery, cross-archive search and threat scanning. Everything you export is yours to keep.
Does an air-gapped or offline machine need an internet connection?
A normal install validates occasionally to stay current. For a sealed lab that never touches the network, sign in on the website, copy your key and paste it into the app. No connection on the examiner's machine is required.
How do I verify the download is safe?
Every download displays a SHA256 hash on the download page. After downloading, compute the SHA256 of the file and compare it to the published hash. If the values match, the file has not been tampered with. Use our Sherlock Forensics Hash tool or any SHA256 calculator.
Can I export emails from a PST file?
The Forensic Edition ($67 USD) supports exporting individual emails or batch exports to EML, MSG and Mbox, and can write marked or search-hit messages to an Outlook-mountable PST production with a manifest and per-message SHA-256. The free edition is view-only with search and hash verification.
Do you offer volume licensing?
Yes. For 5 or more machines, contact Sherlock Forensics at 888.883.4550 or [email protected] for volume pricing.
Are Sherlock Forensics PST Viewer reports admissible in court?
Sherlock Forensics PST Viewer Forensic Edition generates forensic PDF reports with SHA-256 hashing per message, sender IP attribution extracted from Received headers, chain of custody documentation and read-only analysis verification. The tool is built by CISSP, ISSAP, ISSMP certified examiners with 20 years of courtroom experience. Admissibility depends on jurisdiction and proper evidence handling, but the reports document everything courts typically require for digital evidence admission.
How does per-message SHA-256 hashing work?
Each email in the PST archive is individually hashed using SHA-256 when included in a forensic report. This creates a unique cryptographic fingerprint for every message. Any modification to a single email would produce a completely different hash value, allowing independent verification of each message without needing to re-examine the entire archive.
Can I use Sherlock Forensics PST Viewer reports in civil litigation?
Admissibility depends on your jurisdiction and how evidence was handled throughout the investigation. Sherlock Forensics PST Viewer Forensic Edition reports document SHA-256 per-message hashes, sender IP attribution from RFC-822 Received headers, SPF, DKIM and DMARC results as recorded by the receiving mail server (reported, not re-verified), chain of custody and examiner identification. These are the elements courts typically require when evaluating digital evidence in civil proceedings.
Can Sherlock Forensics PST Viewer withhold privileged email across multiple custodian PSTs?
Yes. Import the client review spreadsheet once and it matches against all of a custodian's PST archives in one pass, marking each privileged message in the PST that holds it. Export all except marked to a new PST, EML, MSG or mbox, and every withholding export writes a SHA-256 hashed CSV of exactly what was withheld with its source archive, folder, date, sender, recipients, subject, attachment flag and item id. Exported and withheld counts are reconciled against the folder total, and the export fails closed if the withheld list cannot be written. This lists what was withheld as the basis for a privilege log; the privilege basis and descriptions stay with the reviewer.
Will Sherlock find emails the user deleted?
Yes. Sherlock Forensics PST Viewer includes deleted-item recovery with four carving methods. It scans unallocated space in the PST file and recovers messages that were emptied from the Deleted Items folder. Recovered messages appear in a dedicated Recovered Items view with metadata intact where available.
Can I scan a PST for credit cards, SSNs and other sensitive data?
Yes. The pattern-based sensitive-data scanner detects credit card numbers, Social Security numbers, passport numbers and other PII patterns across every message in the archive. Each match is validated with format-specific checks such as Luhn for credit cards to reduce false positives.
Can I work on two monitors?
Yes. Sherlock Forensics PST Viewer supports multi-monitor workflows. You can detach the message detail panel, the activity timeline, the communication map or any analysis window and move it to a second monitor. This lets you keep the message list on one screen and evidence detail on another.
Will my marks survive a restart?
Yes. Marks are persisted to a sidecar file stored alongside your evidence. When you reopen the same PST file your previous marks are restored automatically. The sidecar file never modifies the original evidence.
How do I search inside a long email body?
Press Ctrl+F while viewing a message to open the in-message search bar. The search is digit-aware so queries like 1234 will match 1,234 and 1234.00 as well as the literal string. Matches are highlighted with next/previous navigation.
Can I search across multiple custodians' PSTs at once?
Yes. Cross-PST search lets you open multiple PST files and run a single query across all of them. Results are grouped by source file with hit counts per archive. This is useful for multi-custodian eDiscovery where you need to find a keyword across several mailboxes simultaneously.
Does Sherlock Forensics PST Viewer work on Linux?
Yes. Version 1.6.2 is the first ever Linux release, as a Debian package (.deb) for Ubuntu 22.04 or newer, Debian 12 or newer and Kali on 64-bit Intel or AMD. It reads the same PST, OST and OLM evidence as the Windows and macOS builds, with the same search, recovery, reports and chain of custody. The on-device AI features are Windows and macOS only. The package is unsigned per Linux convention, with a published SHA-256 to verify the download.
Can I recover deleted emails from a PST file?
Yes. Sherlock Forensics PST Viewer recovers deleted emails using four carving methods: Deleted Items folder enumeration, Recoverable Items dumpster scan, B-tree page scan for deallocated message bodies and slack-space carving for fragmented remains. The recovery works on soft-deleted, hard-deleted and permanently deleted items, including emails Outlook claims are gone.
How long are deleted emails recoverable from a PST file?
Deleted Items folder retains soft-deleted emails until manually purged (indefinite). The Recoverable Items dumpster retains hard-deleted emails for 14 to 30 days depending on retention policy. After the dumpster window expires, the B-tree page scan still recovers most messages from deallocated pages until Outlook auto-compact runs. Sherlock surfaces all four recovery layers in a single scan.
Can I recover permanently deleted emails from Outlook?
Yes in most cases. Even after the Recoverable Items dumpster expires, the binary message body often remains in the PST file's deallocated B-tree pages until Outlook auto-compact runs. Sherlock Forensics PST Viewer's B-tree page scan surfaces these permanently deleted items by reading deallocated index pages directly.
What is the difference between soft delete and hard delete in Outlook?
Soft delete (Delete key) moves the email to the Deleted Items folder. The email is fully recoverable by enumeration. Hard delete (Shift+Delete or empty Deleted Items) bypasses Deleted Items and moves the message to the Recoverable Items dumpster for 14 to 30 days. After the dumpster window, the message becomes permanently deleted from Outlook's UI but the binary body often remains in the PST file's deallocated B-tree pages.
Does Outlook actually delete emails from the PST file?
No. Outlook flags messages as deleted in the PST's B-tree index but the binary body remains in deallocated pages until Outlook auto-compact runs or the PST is securely wiped. This is why forensic-grade PST viewers can recover messages Outlook has marked as permanently deleted: the data is still there, just no longer referenced by the active index.
Can I recover emails after emptying the Recycle Bin in Outlook?
Yes for the Recoverable Items dumpster window (14 to 30 days). After the dumpster expires, Sherlock's B-tree page scan recovers most messages from deallocated pages. The Recycle Bin in Outlook is the Deleted Items folder; emptying it triggers the hard-delete path to the Recoverable Items dumpster, not a true wipe.
How do I undelete emails from Outlook without restoring a backup?
Open the PST file in Sherlock Forensics PST Viewer. The viewer surfaces Deleted Items, Recoverable Items and permanently deleted messages via the four carving methods in a single scan. Export recovered messages to EML or MSG for re-import to Outlook or any other email client. No backup restoration required.
Can deleted emails be recovered from a corrupt PST file?
Yes in most cases. Sherlock's bounds-checked parser handles malformed B-tree pages, fresh-template garbage and partially-corrupted records silently rather than crashing. Even corrupted PSTs typically contain recoverable deleted-item data; Sherlock surfaces what is recoverable without modifying the source file.

Get Started

Download Sherlock Forensics PST Viewer Today

Free for viewing, searching and hash verification. Pro at $67 USD for export, forensic reports and chain of custody logging. Built by the same team that delivers expert witness testimony and forensic investigations in Canadian courts. Read our launch story. See also: how to open a PST file forensically, recover deleted emails from PST files, why PST files matter for eDiscovery, chain of custody software, forensic report generator and email preservation for litigation, workplace investigation evidence, free PST viewer comparison 2026, private investigator forensic tools and MSG + EML support in v1.2.0, MSG Viewer and EML Viewer.

Since 2006CISSP, ISSAP, ISSMP certified888.883.4550

Used for: eDiscovery, HR investigations, compliance audits, insurance claims, litigation support and data migration

Try the free version before you buy. Free tier previews 50 messages per folder with 3 file opens per day starting version 1.4.0. Forensic Edition removes both limits.

b61a26ecf56406fdd88ed0d232662b66a5cf069ffe3eccc51e72dbf1c70a2b85

How to verify:
1. Open PowerShell (right-click Start menu, click Terminal)
2. Run: Get-FileHash .\sherlock-pst-viewer-1.6.23-quick-setup.exe
3. Compare the output with the hash above. If they match, the file has not been tampered with.

On macOS:
1. Open Terminal
2. Run: shasum -a 256 SherlockPSTViewer-1.6.23.dmg
3. Compare with the macOS SHA-256: 1750ca95708d16832531befdcddb33416da3903453188f7542f76792ae0ac253

Offline or full-version install

Download the full version

The quick installer downloads the AI models through the app on first run. The full version puts everything in one download instead, with no in-app fetch. Use it for a machine that will never be online. It also suits anyone who would rather grab one complete file up front. Pick the version that matches the machine's hardware, not a quality level. Each includes a single AI model. Most people should choose Standard.

Full version, Standard (1.73 GB)
Runs on a CPU or a modest GPU. Recommended for most machines. Download Standard
SHA-256: 8f89d638d7fadc085877a26fd252f6138f93369af26cd5b2c5a48b1356d6e818
Full version, High accuracy (3.51 GB)
More accurate, but it wants several gigabytes of spare video memory and is slower on a machine with no discrete GPU. Download High accuracy
SHA-256: e90462a23c6c7aecaddefbcfcdeecc4ef54cd69da03afa41120635a1d863ad7f

Sherlock Forensics PST Viewer is provided for lawful use. Terms of Service

Related Sherlock Tool

For mobile mail-analysis complement to PST Viewer, see the new Sherlock Forensics iPhone and iPad Analyzer. Windows forensic workstation for iOS logical MobileBackup2 acquisition. Parses iMessage, WhatsApp and SMS alongside 70+ additional iOS artifact views. Encrypted-backup offline decryption. Court-ready HTML report. Forensic Edition $599 one-time payment.

Download

Your email is optional. If you provide it, we send 3 product introduction emails over the next 2 weeks. No long-term marketing. No data sharing. Skip the field and download directly.

While you are here, make us your preferred source in Google:

Checkout - PST Viewer Forensic Edition

$67.00 USD, one-time purchase. License key delivered to your email.

Secure via Stripe One-time purchase Perpetual license
Sherlock Forensics PST Viewer - $67