Somebody resigns, and their mailbox becomes an awkward object. It holds correspondence the business needs, credentials tied to services nobody has audited, and an address customers will keep writing to for months. Deciding what happens to a mailbox when someone leaves is usually done in a hurry on their last afternoon, which is how history gets lost.
This page covers the options, what each one costs you, and the sequence that avoids both losing mail and leaving access open.
Do It in This Order
Handling a mailbox when someone leaves is a sequence, and the order matters more than any individual step, because doing them the wrong way round creates a gap.
First, stop new access. Change the password and revoke any app passwords or connected devices. Do this at the point the relationship ends rather than the point their notice expires — those are frequently different days, and the gap between them is where trouble happens.
Second, decide where the mail goes next. Before touching anything else, know who is receiving correspondence sent to that address from tomorrow morning. Customers won't stop writing because somebody left.
Third, preserve what's there. The mailbox contents are business records, and they're needed for longer than the person was.
Only then, remove or repurpose the mailbox. Deletion is the last step and the irreversible one, so it should be the step you take once everything else is settled.
The Options, and What Each One Costs
There are four sensible dispositions for a mailbox when someone leaves, and the right one depends on whether the address had a public life.
Convert it to a shared mailbox. The address keeps working, colleagues get access by membership rather than by password, and the full history stays where it is. This is usually the best answer for anyone customer-facing, and it costs one shared mailbox slot against your plan's per-domain allowance.
Keep it as a dormant mailbox with forwarding. Mail continues to arrive and is redirected to whoever took over. Simple, but replies leave from a different address, which can confuse the counterparty.
Turn it into an alias. Once the flow of genuinely new correspondence has stopped, an alias on somebody else's mailbox keeps the address alive at almost no cost, and frees the mailbox slot entirely.
Delete it. Right for internal-only addresses that nobody outside ever knew, and for short-tenure staff who never corresponded externally. Wrong for anything customer-facing, and effectively irreversible once the retention window passes.
Preserving the History
Preserving the contents of a mailbox when someone leaves is the step that gets skipped and the one people regret, usually about eighteen months later when a dispute surfaces.
The cheapest approach is simply not deleting the mailbox. Storage is pooled rather than per-seat here, so a dormant mailbox consumes space but not money, and leaving it in place for a year costs nothing except a slot. Given that mailboxes aren't billed individually, the usual financial pressure to delete doesn't exist.
If you'd rather have the mail somewhere else, exporting over IMAP produces a copy you control, which can then go to storage. That's also the right move if the mailbox is large and you'd rather not carry it in the pool indefinitely.
What to avoid is the middle path where somebody forwards everything to their own inbox and the original is deleted. The history then lives inside one person's mailbox, and you've recreated the same problem you're currently solving, one step down the line.
The Credentials Nobody Thinks About
A mailbox when someone leaves is also an authentication factor for everything they ever signed up to with that address.
Every service where that address is the login, and every service where it's the password-reset route, is reachable by whoever controls the mailbox next. That's an argument for keeping it under your control rather than deleting it, because a deleted address on a domain you own can be recreated by anyone with domain access — including, later, someone you didn't intend.
The practical step is checking what the address was used for before deciding. Search the mailbox for signup confirmations and password resets; that inventory takes ten minutes and routinely surfaces two or three services nobody knew existed.
Where an alias-per-service scheme was in use, this job is much easier, because the addresses name their own services — the pattern described in an email alias per signup.
Making It Routine
The reason a mailbox when someone leaves gets handled badly is almost never ignorance. It's that the decision is made once per departure, under time pressure, by whoever is available.
Write it down once: which addresses convert to shared, which become aliases, how long dormant mailboxes are kept, and who does each step. A page of policy removes the improvisation, and the improvisation is where mail gets lost.
The structural fix is arranging things so that departures matter less. Where correspondence belongs to a project, a client or a role rather than to a person, a mailbox when someone leaves is just a membership change and nothing needs deciding at all — the approach covered in a mailbox per project. That won't cover personal addresses, which will always exist, but it shrinks the problem to the subset that genuinely is personal.
The Legal Side, Briefly
Two points worth knowing, neither of which is legal advice.
Business correspondence in a work mailbox is generally the employer's record, and retention obligations vary by jurisdiction and sector — often several years, sometimes longer for financial or regulated material — the ICO's guidance is a reasonable starting point in the UK. Deleting a mailbox promptly can therefore be the wrong move for reasons that have nothing to do with convenience.
Personal mail in a work mailbox is a more delicate question, and jurisdictions differ on how it should be treated. The clean approach is having said in advance what happens to a mailbox when someone leaves, so nobody is surprised, rather than deciding it during an exit that may not be amicable.