Step-by-step guide · IT & HR

Employee Email Offboarding: How to Archive and Keep Access to a Departing Employee's Mailbox

An employee is leaving. Their mailbox contains client conversations, project history, contracts, and institutional knowledge that the company needs to keep. Deleting the account means losing that data. Keeping the licence active means paying for a seat nobody uses. This guide covers how to properly archive a departing employee's email so your team retains access without ongoing costs.

Why employee email archiving matters

Legal and compliance requirements

Many industries require email retention for specific periods:

  • Financial services: SEC Rule 17a-4 requires broker-dealers to retain business communications for 3–6 years.
  • Healthcare: HIPAA requires retention of communications containing protected health information for 6 years.
  • EU/GDPR: Employee communications may contain personal data subject to retention and deletion requirements.
  • Legal hold: If your company is involved in litigation, you may be legally required to preserve all relevant email.

Deleting an employee's mailbox without checking retention requirements can create serious legal exposure.

Business continuity

Departing employees take institutional knowledge with them. Their email contains client communication history and relationship context, vendor agreements and contract negotiations, project decisions and technical discussions, and passwords, API keys, and account details shared via email (flag these for rotation).

Cost management

Most email platforms charge per user per month. Microsoft 365 Business Basic costs €5.60/user/month. Google Workspace Business Starter costs €5.75/user/month. Keeping a departed employee's licence active "just in case" costs €67–69/year per person. For a company with 10% annual turnover and 50 employees, that's 5 unused licences costing €335–345/year — and growing every year.

Step-by-step process

How to archive a departing employee's email

1

Check retention requirements

Before exporting anything, confirm your company's email retention policy. Talk to legal or compliance if you're unsure. Document the retention period for the export.

2

Export the mailbox

The export method depends on your email platform.

Microsoft 365 / Exchange Online:

  1. Go to the Microsoft 365 Admin Centre.
  2. Navigate to Users → Active Users and select the departing employee.
  3. Under Mail, click Manage email forwarding to forward incoming mail to a colleague (optional).
  4. Use eDiscovery or the Content Search tool to export the mailbox to PST format.
  5. Alternatively, use the Exchange Admin Centre → Recipients → Mailboxes → select user → Export to PST.

Google Workspace:

  1. Go to the Google Admin Console.
  2. Navigate to Directory → Users and select the departing employee.
  3. Use Google Vault (if available) to create an export, or use the Data Export tool to export the user's Gmail data.
  4. The export will be in MBOX format inside a ZIP file.

On-premises Exchange: Use New-MailboxExportRequest in Exchange Management Shell to export to PST. Store the PST on a network share accessible to IT.

3

Store the archive securely

Raw PST or MBOX files on a shared drive create problems: no access control, no search, no audit trail.

Better options:

  • Upload to a cloud email archive like Evermail. This gives you searchable access, role-based permissions, and encryption. Multiple team members can search the archive without needing Outlook or the original email platform.
  • Compliance archiving platform if your industry requires specific retention features (legal hold, chain of custody, tamper-proof storage).
4

Set access permissions

Decide who should have access to the archived mailbox: the departing employee's manager (usually), the team that will handle the employee's clients or projects, legal or compliance (if required), and HR (for specific cases, not blanket access).

In a cloud archive tool, you can grant access per archive, so the sales team can search a departed sales rep's emails without seeing HR correspondence.

5

Delete or reassign the original account

Once the archive is confirmed and accessible:

  1. Set up auto-reply on the departing employee's account for 30–90 days, redirecting contacts.
  2. Forward incoming mail to the appropriate team member.
  3. After the forwarding period, disable or delete the account.
  4. Cancel the email licence to stop recurring charges.
6

Document the offboarding

Record what was archived, where it's stored, who has access, and the retention period. This protects you during audits and legal discovery.

Common offboarding mistakes

Mistake 1: Keeping the licence active indefinitely.

"Just in case" becomes "forever." Set a calendar reminder to review and delete the licence after forwarding expires.

Mistake 2: Storing PST files on a shared drive with no search.

Six months later, nobody can find anything. Use a searchable archive tool.

Mistake 3: Giving the manager full mailbox access in the live email system.

This creates privacy concerns and doesn't scale. Export, archive, and grant controlled access.

Mistake 4: Forgetting to check for auto-forwarding rules.

Departing employees sometimes set up forwarding rules to personal accounts. Check and remove these during offboarding.

Mistake 5: Not rotating shared credentials.

Search the mailbox for passwords, API keys, and shared account credentials. Rotate anything found.

Offboarding checklist

  • ☐ Confirm email retention requirements with legal/compliance.
  • ☐ Export the mailbox (PST for Microsoft, MBOX/ZIP for Google).
  • ☐ Upload to a searchable archive with access controls.
  • ☐ Grant access to the appropriate team members.
  • ☐ Set auto-reply and mail forwarding.
  • ☐ Check for and remove auto-forwarding rules to external accounts.
  • ☐ Search for and rotate shared credentials found in email.
  • ☐ Schedule licence cancellation after forwarding period.
  • ☐ Document the archive location, access list, and retention period.

Platform comparison for archived mailbox access

Approach Searchable Team Access Cost Retention Controls
Keep licence active Yes Yes (shared mailbox) €5–7/user/month ongoing Platform-dependent
PST/MBOX on shared drive No (manual only) Uncontrolled Storage cost only None
Cloud email archive (Evermail) Full-text search Role-based From €0 (free tier) Configurable
Compliance platform Yes Yes €10–50/user/month Full audit trail

Archive the departing employee's mailbox today

Upload the exported mailbox to Evermail — your whole team can search it, no email licence required. Free to start.

Get started free →
FAQ

Common questions

How long do I legally need to keep an employee's email?
It depends on your industry and jurisdiction. Financial services: 3–6 years (SEC Rule 17a-4). Healthcare: 6 years (HIPAA). EU: varies by data type and purpose under GDPR. When in doubt, consult your legal or compliance team before deleting anything.
Can the departing employee see that I exported their mailbox?
In Microsoft 365, eDiscovery and export operations are typically visible to global admins only and not shown to the user. In Google Workspace, data exports from the Admin Console are an admin-level operation. Check your platform's audit log documentation for specifics.
Do I need special permissions to export a Microsoft 365 mailbox?
Yes. You need to be a global admin or have the eDiscovery Manager role in Microsoft 365. Standard users and even most IT helpdesk roles cannot initiate mailbox exports by default.
What's the fastest way to give the manager access to the archive?
Upload the exported PST or MBOX to a cloud archive tool like Evermail and share the archive with the manager's email address. They can search it from any browser immediately — no Outlook, no shared drives, no VPN required.
We're a Google Workspace team. Does Evermail support Google Takeout exports?
Yes. Upload the Google Takeout ZIP directly — Evermail extracts the MBOX files automatically. The full Gmail label structure is preserved so the manager can browse by folder just like in Gmail.