When an employee leaves, their mailbox is one of the most sensitive assets your company still holds. It contains client conversations, contracts, approvals, and years of context that exists nowhere else. Handle it badly and you lose deals, frustrate customers, or leave an open door for attackers. Handle it well and the handover is almost invisible to the people on the other side of the inbox.
This guide gives you a repeatable offboarding process: what to prepare, what to do before and on the last day, how long to keep the mailbox, and when it's safe to delete. It works on any platform, and we'll point out where NevTan Mail fits in if you run business email on your own domain.
Never delete a departing employee's mailbox immediately; preserve it first. Before the last day, set up an auto-reply, route incoming mail to the right people, and reassign aliases and connected apps. On the last day, revoke access and lock the account. Keep the mailbox for a defined retention window (commonly 30–90 days, longer if law or litigation requires it), then archive or delete it and document the decision.
What You Need Before Starting
Offboarding an email account without preparation is how companies end up with lost threads and compliance headaches. Gather these first:
Admin access to your email platform, whether that's NevTan Mail, Google Workspace, or Microsoft 365.
The exact last day and time access should be cut off, confirmed with HR.
A list of aliases, shared mailboxes, and distribution lists the person belongs to (sales@, support@, billing@).
Manager sign-off on who takes over incoming mail and who, if anyone, may read the old mailbox.
Legal or HR guidance on retention for your industry and country.
A secure archive location with restricted access, such as encrypted cloud storage or a compliance archive.
Confirm these in writing. A short email thread with the manager and HR is enough, and it protects you if anyone later questions what was preserved or who had access.
Step 1: Inventory the Mailbox
Start with a record of what you're dealing with. Note the mailbox size, key folders, aliases routing to this person, shared calendars, contacts, and tasks. If your team keeps email, calendar, and tasks in one workspace, remember that recurring meetings and open to-dos need new owners too, not just messages.
Then check for connected apps: CRMs, helpdesks, billing tools, or scripts that sign in or send mail through this address over IMAP, SMTP, or an API. These break silently when you disable the account. If you're unsure how a tool connects, our guide to IMAP vs SMTP vs API integrations explains what to look for.
A simple spreadsheet works well here: mailbox address, aliases, connected apps, calendars, priority folders, new owner, and deadline. It becomes your offboarding checklist.
Pro tip: Flag folders belonging to high-value clients so they're reviewed and exported first.
Step 2: Set Up an Auto-Reply and Route Incoming Mail
Before the last day, configure an out-of-office style reply that tells senders the person has left and who to contact instead. Keep it brief and don't reveal anything about why they left:
"Thank you for your message. [Name] is no longer with [Company]. For assistance, please contact [Name] at [email], who will be happy to help."
For templates and timing tips, see our guide to out-of-office automation.
Next, decide where new mail goes. Routing everything to one manager creates a bottleneck and makes it easy to miss something. For client-facing roles, a shared team inbox that several people monitor is usually better.
One deliverability caution: forwarding mail to an external address can break SPF and DMARC checks, causing forwarded messages to be rejected or land in spam. Keep routing inside your own domain where possible. Our explainers on domain authentication and why emails go to spam cover the details.
Pro tip: Send a test message from an outside account to confirm both the auto-reply and the routing work. Don't assume.
Step 3: Hand Over Access Deliberately
Someone usually needs to look back through the old mailbox for open deals or unanswered questions. Whether you grant that through delegation, a shared mailbox, or an admin-led export depends on your platform, but the rules are the same everywhere:
Give access to as few people as possible, and only to what they need.
Record who has access and why.
Set calendar reminders at 30 and 90 days to review and remove it.
Access granted "temporarily" during offboarding is one of the most common permissions that lingers for years. Treat it like any other security exposure; stale accounts and forgotten permissions are exactly what attackers look for, as covered in our guide to phishing protection and TLS encryption.
It's also worth remembering that mailboxes often contain some personal messages. Limit review to business content, and follow your employment policies and applicable privacy law (for example GDPR in the EU or the DPDP Act in India).
Step 4: Export and Archive What Matters
Not everything needs preserving. Focus on client correspondence, contracts and proposals, financial records, and anything touching legal or compliance matters. Export contacts and calendars separately, since they're easy to overlook and critical for continuity.
For most small and mid-sized businesses, an export in a standard format (such as MBOX or PST) stored in an encrypted, access-restricted location is enough. Regulated industries like finance, healthcare, and legal usually need a dedicated archiving or eDiscovery tool. Encrypt archives at rest; our guide to email encryption for business explains your options.
Pro tip: Check export requirements before the account is disabled. On platforms with end-to-end or zero-access encryption, exporting may require steps that are harder or impossible once the user's credentials are gone.
Step 5: Revoke Access, Then Retain
On the last day, disable sign-in, reset the password, remove any 2FA devices or security keys tied to the person, and end active sessions. Reassign aliases so nothing points to a disabled account. Update connected apps to a service account or new owner.
Don't delete the mailbox yet. Keep it for a defined retention window, commonly 30 to 90 days, so you can recover anything you missed. During that window, keep an eye on the auto-reply and routing.
When the window closes, make a final decision: delete permanently, convert to a shared or archived mailbox, or move to long-term storage. Document the decision and the date. Before deleting, confirm critical data is exported and no legal hold applies.
Pro tip: Put the deletion date on a calendar right away. Without a reminder, old mailboxes linger for years and become compliance liabilities, and on per-seat plans they may keep costing you money. (Seat costs add up fast for small teams; see our business email guide for startups.)
Comparison: Offboarding Options at a Glance
Option | Best for | Cost | Retention | Main trade-off |
|---|---|---|---|---|
Route to manager | Small teams, short gaps | Free | Until removed | One person becomes a bottleneck |
Shared team inbox | Client-facing roles | Low | Indefinite | Needs clear ownership |
Delegated access | Temporary coverage | Free | Until revoked | Easy to forget to remove |
Export to MBOX/PST | Most SMBs, audits | Storage only | As long as stored | Must be stored securely |
Compliance archive / eDiscovery | Regulated industries | $$$ | 3–7+ years | Cost and setup |
Delete immediately | Almost never | Free | None | Irreversible data loss |
Example: Offboarding a Sales Director
The following is an illustrative scenario.
A 40-person agency's sales director leaves after four years. Her mailbox holds about 12,000 messages, three shared calendars, and connections to the CRM and a proposal tool.
IT exports the mailbox and her contacts, sets an auto-reply pointing to the sales manager, routes new mail to the sales team inbox, reassigns the sales@ alias, and reconnects the CRM to a service account, all before her last day. Two weeks later a major client writes about a renewal; the auto-reply sends them to the sales manager, who can find the original scope in the archive, and the renewal closes smoothly. After 90 days, with no legal hold, the mailbox is deleted and the decision logged.
Contrast that with deleting the mailbox on day one: the same renewal email would have bounced, and the original scope document would be gone.
How to Choose the Right Approach
Three factors drive the decision: how client-facing the role was, how sensitive the data is, and what your legal obligations are.
Client-facing roles (sales, support, account management): shared inbox plus an export of key threads. Continuity matters most.
Internal roles (engineering, operations): route to the manager for 30 days, export what's needed, then archive or delete.
Executives and finance: export everything, retain for the full legal period, and restrict access to HR and legal.
Contractors and temps: export project files, then close the account on a short timeline.
If you're in a regulated industry, default to the conservative path: full export, long retention, documented approval for deletion. When in doubt, retain longer. Storage is cheap; lost records and legal exposure are not.
Why This Process Works
Email is the system of record for most business relationships. Deleting a mailbox immediately destroys institutional knowledge; keeping it open indefinitely creates security and compliance risk. Preserve, hand over, retain, then delete gets you the benefit of both: nothing important is lost, and nothing sensitive stays exposed longer than necessary.
A short, defined retention window catches nearly all the "we forgot to ask them about X" moments. After that, the mailbox's value drops while its risk keeps growing.
Common Mistakes
Deleting on day one. The most expensive mistake. Always retain first.
Leaving access open. Temporary permissions become permanent unless you schedule reviews.
Forgetting contacts, calendars, and tasks. They're separate from mail and easy to miss.
Forwarding externally. It can break authentication and send mail to spam; keep routing on your domain.
Ignoring connected apps. Integrations quietly fail when the account is disabled, sometimes including transactional emails your customers rely on.
Ignoring legal holds. If litigation or an investigation is possible, preserve everything and check with legal before deleting.
FAQ
How long should I keep a departed employee's email?
Many companies keep it 30 to 90 days for ordinary roles. Regulated industries or specific record types may require several years. Confirm with your legal team and document your policy.
Should I forward the email or use a shared inbox?
For client-facing roles, a shared inbox is usually better because several people can respond and nothing depends on one person. Avoid forwarding to external addresses.
What happens to their contacts and calendar?
Export them before disabling the account, and reassign recurring meetings so clients aren't left waiting in an empty video call.
Can I delete the mailbox right away if the employee was terminated?
It's generally unwise. Terminations are exactly when disputes arise, so preserve the mailbox, restrict access, and get legal guidance before deleting.
How do I handle aliases like sales@ or support@?
Reassign them to a shared inbox or new owner before the last day. An alias pointing at a disabled account means lost mail.
Can I read a former employee's personal emails?
Limit review to business content and follow your written policies and local privacy law. When in doubt, involve HR or legal.
Do I need special software to archive email?
Most small businesses can use a standard export stored securely. Regulated industries should use a dedicated compliance archive.
Make Offboarding Part of a Secure Email Setup
Good offboarding is easier when your email platform gives admins clear control over who has access. With NevTan Mail, admins create and manage team mailboxes on your own domain, with role-based Admin and Super Admin access, 2FA and security keys, and security monitoring for suspicious account activity. Explore the full list on the features page, learn more about NevTan, or see why teams are switching to modern webmail.
For how we handle data, read our Privacy Policy and Terms of Service.
