ATTORNEY ON CALL · 24/7
212 300 5196
FROM THE DEFENSE DESK / CRIMINAL DEFENSE
2 AUG 2026 · 14 MIN READ · BY TODD A. SPODEK
THE BRIEF · FILED UNDER: CRIMINAL DEFENSE
DOCKET NO. 608 · THE DEFENSE DESK

Can Federal Agents Read Your Email Without a Warrant? The SCA, Explained.

★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
SUPER LAWYERS · 2020-25AVVO · “SUPERB”SECOND GENERATION · SINCE 1976
AS SEEN ON NETFLIX · CNN · FOX NEWS · NY POST

The stored email protections provided by the Fourth Amendment, as they have long been interpreted, are replaced under the Stored Communications Act (SCA), which is part of the broader Electronic Communications Privacy Act passed by Congress in 1986. For some time after the statute was enacted, the FBI’s guidance to its agents provided a clear, bright-line rule based on the SCA: emails stored for more than 180 days do not require a warrant to be obtained. But is that consistent with the laws that passed through Congress in 1986?

The answer to that question is complex. In 2010, the U.S. Court of Appeals for the Sixth Circuit ruled in United States v. Warshak that a “probable-cause warrant is required to compel an ISP to disclose the contents of any email message,” regardless of whether it is stored for more or less than 180 days. The court held that, to the extent the SCA purports to permit the government to obtain such emails without a warrant, the SCA is unconstitutional.

Unfortunately, because Warshak is a decision from a circuit court, its only binding authority is within the states of the Sixth Circuit (Ohio, Kentucky, Michigan, and Tennessee), unless the U.S. Supreme Court ultimately decides a case with similar implications.

This raises several questions. For example, does providing the FBI with email contents constitute a “public release” (i.e., loss of privacy interest)? The U.S. Supreme Court has already answered this question with respect to traditional mail. The government has needed warrants to open letters since the Court held in Ex parte Jackson (1877) that “Letters and sealed packages of this kind in the mail are as fully guarded from examination and inspection, except as to their outward form and weight, as if they were retained by the parties forwarding them in their own domiciles.”

Does the 180-Day Rule Still Let Agents Read Old Email Without a Warrant?

The SCA applies only to stored communications, not to the interception of communications in transit. For federal law enforcement agents, this means that if they are seeking access to someone’s stored email, they must adhere to a different set of procedures than those they must follow to intercept an email that hasn’t yet been sent or that they intercept in transit.

The FBI’s 2012 guide to the SCA and the “180-day rule” makes clear (and confirms) that:

  • Obtaining stored, unopened email that is less than 180 days old requires a probable cause warrant.
  • Obtaining stored, opened email requires no warrant at all.
  • Obtaining extremely old unopened stored email requires only a “court order” or subpoena.

The 2012 FBI guide’s explanation of the rule, and its reasoning, reflects the interpretation of the SCA that was adopted years prior. The FBI’s explanation boils down to this simple observation:

“The 180-day time limit in §2703(a)(1) reflects the fact that messages residing on an Internet service provider’s (ISP’s) system beyond that time period are no longer in ‘electronic storage’ under §2703(a)(1). They become records under §2703(a)(1), and an ISP is thus just a third party. Thus, the same procedures that apply to compelling third parties to disclose records apply to compelling the disclosure of electronic messages stored beyond 180 days.”

The 2012 FBI guide also says this about opened emails:

“If the electronic communication has been opened, it is no longer in electronic storage. It is a record. This applies regardless of how long the opened communication has been stored.”

Wait, this raises a question. The 2012 guide says that you need a warrant to read unread email under 180 days old, but not read email. This doesn’t seem right. Does it make sense that unread email deserves Fourth Amendment protections, but a single read email loses its protection? Is this how the SCA was intended?

While a federal court likely hasn’t fully addressed these specific questions, these appear to be the type of questions that, when answered, could potentially prove the SCA’s 180-day rule to be constitutional or otherwise unconstitutional. Of course, a U.S. District Court will need to find that an agent relied on §2703’s authorizations in good faith before that would insulate the agent from Fourth Amendment liability.

Nevertheless, in the practical world, many major providers, such as Google and Microsoft, will refuse to disclose the contents of stored email without a warrant. This is true even when the request is compliant with §2703.

Do Federal Agents in My State Need a Warrant to Read My Email?

The Sixth Circuit’s decision in Warshak in 2010 is six years old. During that time, the ACLU has obtained various records by the Freedom of Information Act (FOIA) that offer a snapshot of how the FBI and DOJ have applied its decision nationally. As the ACLU notes, it appears that the U.S. government is still inconsistent about the standards it enforces with respect to email-content access. For example, the ACLU presents materials from the Southern District of New York’s United States Attorney’s Office that seem to allow for warrantless access to “previously-read” stored email. Conversely, the ACLU presents materials from the Northern District of Illinois’s Office of the U.S. Attorney’s that require warrants for the acquisition of all stored email.

The ACLU also presents communications with six U.S. Attorneys’ offices and one FBI field office stating that they “would not authorize a warrantless request for content under the stored communications statute based on the purported authority in section 2703.” Again, the ACLU notes that this is in direct conflict with what it has been hearing from the government nationwide.

The ACLU has reached out to the DOJ and the FBI to ask about their official policies and to request the release of any relevant policy memoranda. The ACLU’s latest request, which it claims the DOJ has ignored, is based on its continued efforts to seek clarity on the issue with the government. So, as of late 2016, federal officials’ internal procedures, or their lack of procedures, regarding stored email access remain unclear.

When the U.S. Supreme Court decided Carpenter v. United States in 2018, the Court considered whether the Fourth Amendment applies to the government’s compelled acquisition of historical cell-site location data from a telecommunications company. This was a new question. And the Supreme Court declined to extend the third-party doctrine to cell-site location data, holding that the fact that the information is held by a third party does not by itself overcome the user’s claim to Fourth Amendment protection. The Supreme Court does not yet have a decided standard for stored email, as the Supreme Court decided Carpenter on cell-site location data alone. The U.S. Supreme Court did not address stored emails.

The FBI’s 2012 Domestic Investigations Operations Guide (DIOG) is also silent on Warshak. It discusses the SCA in detail, but it does not mention Warshak. This reinforces the U.S. government’s continued lack of guidance regarding the warrant requirements for the acquisition of stored email.

What is the Difference Between Email Content and Metadata Under the SCA?

1. Communications Content

Under the SCA, “communications content” includes the body of the email, its subject line, and any files that were sent as attachments.

2. Non-Content Records

Email has “non-content” records (often referred to as metadata) as well. These records include:

  • Subscriber identities;
  • Billing data;
  • Connection logs;
  • Email addressing data (i.e., whom an email message was addressed to and from, but not the contents of the email message itself);

For instance, while the subject line of an email is “content,” the fact that an email message was sent from sender to recipient is not “content.” For stored email, there are three categories of access.

A. The Warrant (Probable Cause Standard)

Under section 2703 of the SCA, federal agents can compel the disclosure of stored emails from an ISP using a warrant. They can also compel a warrant in other situations, although the relevant statute’s specifics vary based on what types of stored email are sought. If a warrant is not required, the government must use either a subpoena or a court order.

B. The Subpoena (Lowest Standard)

A “subpoena under § 2703(c)(2) is an administrative subpoena that is sufficient to compel the disclosure of:

  • Subscriber identity and other information that identifies the user;
  • Payment records pertaining to the user’s account;
  • Connection logs (or “session data”) which shows when the user is active on their device;

All of these are, again, forms of non-content metadata.

C. The Court Order (Specific and Articulable Facts Standard)

For any non-content stored email records not described in section 2703(c)(2), federal law enforcement agents generally need to use a section 2703(d) court order or a warrant.

Under section 2703(d) of the SCA, federal law enforcement agents may, upon showing that “specific and articulable facts show that there are reasonable grounds to believe that the records or other information sought are relevant and material to an ongoing criminal investigation,” apply for and obtain a section 2703(d) court order. So, with respect to this type of non-content stored email record access, there are no Fourth Amendment probable-cause warrant requirements.

While this may seem unexpected, a section 2703(d) court order is considered a lesser process than a probable-cause warrant under the Fourth Amendment. However, as long as it is not a probable-cause warrant, federal agents who rely on it are not subject to “exclusionary rule” Fourth Amendment sanctions.

Todd Spodek and the attorneys at Spodek Law Group handle federal cases of this kind from New York, Brooklyn, Queens and Los Angeles.

How Do Federal Agents Get My Emails from Google Without Telling Me?

Under section 2703 of the SCA, federal law enforcement agents are not required to seek disclosure of stored communications from users. Instead, they are required to seek disclosure of stored communications from the provider that stores the communications on behalf of the user. By compelling disclosure through providers, federal law enforcement agents can avoid informing the targets of their investigations of their efforts to obtain their users’ emails.

Moreover, section 2703(f) of the SCA provides federal agents with an avenue to seek preservation of stored email records. Specifically, under section 2703(f), the government may “request that a provider of wire or electronic communication services or remote computing services preserve in its possession or control certain records.” This preservation of records is often a necessary step for federal law enforcement agents seeking to obtain the data, because an FBI or DOJ agent must, in most cases, present a provider with appropriate legal process in order to compel stored-data disclosure following a preservation request. Importantly, while a preservation request initiates the process of data collection, it does not itself compel the provider to disclose the records that are subject to the request.

With respect to notice, section 2705(a) permits delayed notice of the government’s stored-data request in circumstances involving witness intimidation, evidence destruction, and dangerous persons, among others. Section 2705(b) allows courts to expressly prohibit providers from notifying their customers about the government’s stored-email access. Warrants issued to providers under section 2703 generally do not require contemporaneous notice to account holders either. While account holders may never find out when a warrant is issued, this also occurs because the target user does not hold physical possession of the records the government is demanding.

Congress updated the SCA in 2018 by enacting the CLOUD Act. This legislation added section 2713 and allowed providers to store data on servers located outside the United States while still remaining subject to the disclosure requirements of section 2703. Under section 2713, a provider must comply with its obligations to preserve, back up, or disclose the contents of a communication, and any record or other information pertaining to a customer or subscriber, that is within the provider’s possession, custody, or control, regardless of whether that material is located within or outside the United States.

When Can My Email Be Read Without Any Warrant at All?

When federal law enforcement agents do not have warrant authority, they can still seek consent. Consent allows agents to search your property, and, in recent times, courts have acknowledged that consent can allow warrantless searches of individuals’ personal digital devices as well. Under section 2702(b)(3) of the SCA, stored emails and metadata can also be obtained without a warrant, provided that “lawfully obtained consent exists from the originator, addressee, or intended recipient of the stored electronic communication.”

Additionally, section 2702(b)(8) of the SCA permits voluntary disclosure of communication content in order to “protect the life or safety of an individual or address an imminent risk of physical injury,” while section 2702(b)(7) permits voluntary disclosure of communication content to a law enforcement agency if the contents were inadvertently obtained by the service provider and appear to pertain to the commission of a crime. Additionally, under section 2258A of Title 18 of the U.S. Code, “qualifying providers of electronic communication services” must disclose and refer “any information obtained, or reports from a customer, relating to any apparent violation of section 2251, 2251A, 2252, 2252A, 2252B, or 2260 that involves child pornography [i.e., dissemination of material containing child sexual abuse]” to the National Center for Missing & Exploited Children.

2. A Federal Search Warrant or a Warrant Obtained Pursuant to the Computer Abuse Act

Without a warrant, FBI and DOJ agents can read stored emails on your device, whether stored locally or on a cloud server, if they are publicly accessible. This includes publicly posted content on your Instagram and Facebook pages, and any email contents you have shared publicly.

Federal law enforcement agents can also read stored emails that you have sent to Google, Microsoft, and others (i.e., emails that are accessible on a server owned and operated by an ISP) through a warrant. A warrant issued to a provider under section 2703 will compel disclosure of stored content if the search is deemed reasonable and the federal agent’s warrant is valid under the Fourth Amendment. A warrant issued to a user under the Computer Abuse Act (also known as the Computer Fraud and Abuse Act) can, also, compel stored email access. But in these scenarios, the government must present a probable-cause warrant showing the specific and relevant emails sought.

3. Email Disclosures Provided Voluntarily Under Section 2702(b)(8)

Under section 2702(b)(8) of the SCA, “providers may disclose the contents of communications voluntarily to any government entity.” This is also permissive, rather than compulsory, giving providers no duty to disclose stored email, but giving the federal government another method for obtaining information.

Can Intelligence Agencies Read My Email Under FISA or Section 702?

The ECPA provides for various forms of warrantless government access to electronic communications. For example, the ECPA allows law enforcement agents to search electronic communications if “the owner or a user of the electronic communications gives prior consent,” “the person whose communication is sought has died,” or, “there is an imminent threat of death or serious physical injury to a person.”

Beyond the ECPA, FISA also provides the government with warrantless authority in a national-security context. Specifically, FISA provides the United States government with national-security authorities that are separate from the criminal process outlined in section 2703 of the SCA.

Section 702 of FISA allows the United States government to target “non-U.S. persons reasonably believed to be located outside the United States” and obtain “foreign intelligence information” without the need for an individualized probable-cause warrant. This includes communications content collected through foreign intelligence surveillance. However, since a communications-surveillance target will routinely exchange messages with Americans, this means that the United States government will routinely gather communications from U.S. citizens as well. These stored messages are called “incidental collections,” and law enforcement agencies can review these emails and communications without obtaining a warrant first.

Similarly, in some circumstances, U.S. border patrol agents will conduct warrantless device searches at the border. While generally the government must present a search warrant in these scenarios, this often occurs with a government-issued warrant rather than a court-issued one. This is also a form of warrantless access to personal electronic communications that exists outside the scope of the SCA.

Can My Emails Be Suppressed if the Warrant Was Defective?

If a federal agent unlawfully searches or seizes a defendant’s stored electronic communication, the evidence obtained from that unlawful search should be excluded in a criminal case. Similar challenges can be made if the search’s scope exceeded the scope of a warrant.

In addition to these challenges, a defendant can challenge stored-email access that was authorized under the SCA. However, unlike a Fourth Amendment challenge, a challenge based on an alleged violation of the SCA will not result in the exclusionary remedy. Section 2708 of the SCA expressly states: “ a violation of this chapter shall not be a ground for exclusion of evidence.” Thus, to use the exclusionary rule, a defendant must demonstrate that federal law enforcement agent’s email access was unconstitutional.

Even if a federal judge issues a warrant, this does not necessarily mean a federal agent has established probable cause to search. A judge’s signature cannot cure a search warrant that was deficient at the time of issuance. Even if a judge authorizes the federal agents’ search, the warrant is still void if there is no probable cause to support issuance.

Many of these challenges will be based on a variety of factors. For example, while digital warrants are often a few sentences in length, broad warrants that do not specific targets can violate the particularity requirement of the Fourth Amendment. Similar challenges can be made with respect to the timeliness of the information cited in the affidavit supporting the search warrant. If the information used to establish probable cause is too stale, it may no longer establish probable cause for a search at issuance.

Under Franks v. Delaware (1978), a defendant can also challenge the probable cause supporting a search warrant when “the defendant, upon making a substantial preliminary showing, is entitled to a hearing on the truthfulness of the affidavit in a warrant application.” The U.S. Supreme Court in Franks v. Delaware explained that if the affidavit contains “intentional or reckless” material falsehoods which are necessary to establish probable cause, the warrant is void.

To obtain a search warrant, federal law enforcement agents must present probable cause to the presiding judge. The judge then must determine that the federal agent’s affidavit sufficiently established probable cause, providing the warrant’s authorization and validity.

Get Advice on Your Situation

If you want someone to look at the specifics of your case, Spodek Law Group handles federal criminal defense nationwide from New York and Los Angeles. The firm has been practicing since 1976 and its motto is simple: we owe loyalty to only you. Call 212-300-5196.

LEGAL INFORMATION, NOT LEGAL ADVICE · STATUTES CHANGE - VERIFY CURRENT LAW · ATTORNEY ADVERTISING
THE AUTHOR'S RECORD · PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME
Acquitted.
$26M MONEY LAUNDERING
Dismissed.
RICO · 10-YEAR MINIMUM FACED
Six months.
$12M PONZI · YEARS ASKED
ALL RESULTS →
★★★★★VERIFIED CLIENT · FEDERAL CASE · 2022 · VIA GOOGLE REVIEWS
"By the time our free consultation was over, we left at ease."
1,100+ FIVE-STAR GOOGLE REVIEWS →
RISK FREE · CONFIDENTIAL · 24/7

Reading is good. Calling is better.

Answered within 24 hours, guaranteed. Some stories are better told out loud -

212 300 5196
AFTER YOU REACH OUT
01A person answers - not a service. Day or night. 02Free, confidential consultation - ask us anything, regardless of how long it takes. 03Strategy starts the same day - and you hold the senior partner's cell number.
★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
READ THEM →
INTAKE · PRIVILEGED & CONFIDENTIAL
24/7
01
02
03
04
05
ANSWERED WITHIN 24 HOURS, GUARANTEED OR CALL 212 300 5196
EVERYTHING YOU SHARE IS PROTECTED BY ATTORNEY-CLIENT PRIVILEGE FROM THE FIRST WORD.