A mailbox is a log of who talked to whom, when, and about what, but a mail client shows it one message at a time. When you need the shape of the whole archive, whether to size up a case, spot an off-hours pattern or decide which senders to unsubscribe from, you need charts rather than a list. This post walks through what mailin's analytics show and how different kinds of users read them.
What the email analytics dashboard shows
Once an archive is imported, mailin computes a set of interactive views over it, entirely on the device:
- An email volume timeline, split into sent and received.
- Top contacts and top communication pairs.
- An activity heatmap by day of week and hour of day.
- Attachment type and size breakdown, and an email size distribution.
- A contact network with relationship and entity graphs.
- Topic clusters and communication patterns.
Every view is derived from the archive on your Mac, iPhone or iPad. Nothing is uploaded to build them, and they are computed from the same messages you can open and read, so any number on a chart can be traced to the emails behind it.
When: the timeline and the heatmap
The volume timeline is the first thing to look at in an unfamiliar archive. It shows how much mail was sent and received over time, so gaps, spikes and the overall span of the collection are visible at once. A gap can mean a missing export; a spike often marks the event a case is about.
The heatmap breaks activity down by day and hour. For most people it confirms the obvious: weekdays, working hours. The interesting part is what does not fit. Mail sent consistently in the small hours, or a burst on a weekend, stands out immediately. mailin's anomaly detection looks for the same thing programmatically, flagging unusual sending patterns and suspicious off-hours timing, and Smart Alerts can notify you on senders, keywords, timing and thresholds you set.
Who: contacts, pairs and the network graph
Top contacts tells you who dominates the archive. Top communication pairs go one step further and show which two people exchanged the most mail with each other, which is a different and often more useful question. The address that received the most mail may be a distribution list; the pair that exchanged the most is a relationship.
The contact network draws those relationships as a graph, and the entity graph extends it to the organizations, places and other named entities that on-device named-entity recognition pulls out of message text. The Personal tier adds knowledge graph and entity resolution, meaning the matching of different names or addresses that refer to the same person or organization, which is what keeps the graph from showing one person as several nodes.
About what: topic clusters and attachments
Topic clusters group messages by what they are about, drawing on the same on-device topic and keyword extraction that runs on every email. They are a fast way to see what an archive contains before reading any of it, and to find the cluster that matters among the routine ones. Because the clustering is produced by AI, treat it as a guide rather than a finding: AI features can produce inaccurate or incomplete results, so verify anything important against the messages themselves.
The attachment breakdown shows which file types are in the archive and how much space they take, and the email size distribution shows where the bulk is. Both are practical for cleanup: large attachments and oversized messages are usually where an archive's storage goes, and the Duplicate Manager handles the other big source of bloat.
The Executive Dashboard and exported reports
The Executive Dashboard condenses the views above into a one-glance KPI overview: volumes, top contacts, activity and risk. It is intended for the moment when you have to brief someone in a few minutes rather than explore for an hour.
Analytics reports are exportable, so a chart you relied on can go into a case file or a write-up. If you are running one of mailin's guided workflows, you can also attach the exact files and emails each step relied on to the job's numbered document, so the report and its evidence stay together.
How different people use it
Lawyers and paralegals use the timeline and top contacts during early case assessment to see which custodians and date ranges hold the mail that matters, before anyone starts a first-pass review.
Investigators read the heatmap and anomaly flags together. The Insider Threat Review workflow in the Forensic set is the structured version of that review.
IT and SOC teams turn the same data into a Security Metrics Report, and use the sender and domain views when working a Phishing Campaign across many messages.
Journalists start with the entity graph. The Entity & Network Map workflow uses it to lay out the people and organizations in a leaked mailbox and how they connect.
Individuals use top contacts and the attachment breakdown to decide what to keep. The Unsubscribe & Declutter and Archive Cleanup workflows are the practical follow-through.
Analytics are included in the free tier for archives up to 500 emails. Advanced analytics and the knowledge graph are part of the Personal tier; see pricing for the current details.
FAQ
Are the analytics computed on my device?
Yes. Every view is built from the local archive and index. mailin has no account and no server, and the only default network use is App Store purchase verification.
Can I export a chart or report?
Analytics reports are exportable, and Documents & History entries from guided workflows can be exported to CSV.
Do the analytics work on a Gmail Takeout export?
Yes. Import the .mbox from your unzipped Takeout archive and the views are computed from it, with Gmail labels detected so you can filter by them.