Guides

Employee Offboarding Checklist for Email: Reset, Forward, Revoke

Employee offboarding checklist for email: reset the password, revoke devices and app passwords, forward or auto-reply, retain the mailbox, and revoke API keys.

When someone leaves, their mailbox keeps receiving customer replies, password resets for tools they set up, and invoices. If nobody handles it on their last day, you either lose that mail or, worse, the leaver keeps reading it from a phone you forgot about. This checklist takes under an hour, works whether the departure is friendly or not, and covers the two things people most often miss: forwarding rules and API keys.

Quick answer

On the last day, in this order: change the password, sign out every session and revoke app passwords, check the mailbox for forwarding rules and filters, remove the address from groups and aliases, revoke any API keys the person created, decide between forward and auto-reply, and keep the mailbox for a defined retention period before deleting it. Update the onboarding record as you go.

The checklist

  1. Time it. For a friendly departure, do this after their final handover; for anything else, do it before they are told. Either way, complete it the same day.
  2. Reset the mailbox password to a new generated value stored in the password manager, accessible to the manager who inherits the mailbox.
  3. End existing sessions and revoke every app password or device token. A password change alone does not always disconnect a phone that is already signed in over IMAP.
  4. Open the mailbox and inspect rules and filters. Delete any automatic forward to an external address, any rule that moves mail to unusual folders, and any auto-reply pointing customers to a personal address.
  5. Check the Reply-To and signature settings for anything that redirects future replies outside the company.
  6. Remove the address from every group, distribution list, and role alias (support@, sales@). Add the successor at the same time so customers see no gap.
  7. Revoke API keys. Search every system the person administered for keys named after them or created on their dates, including your mail provider's send API keys, and issue replacements to the successor.
  8. Remove them as a recovery contact or second factor anywhere their phone number or address was registered: the domain registrar, the mail admin account, the bank, social media.
  9. Decide on forwarding versus auto-reply (below) and set it up.
  10. Record the retention end date and put a calendar reminder to delete or archive the mailbox then.

Forward or auto-reply?

Forwarding to a successor keeps customer conversations moving but means someone reads everything that arrives, including personal mail. An auto-reply that says the person has left and gives a new contact is more transparent and is often the right choice for a role that has been filled. Many businesses do both for the first 30 days, then auto-reply only, then close. Whatever you choose, never forward to the leaver's personal address.

Retain, do not delete

Keep the mailbox in a disabled or password-changed state for the period your retention policy requires, commonly 90 days to a year, and longer if there is a dispute or legal hold. The mailbox holds evidence of what was agreed with customers and suppliers. If your mail host counts a retained mailbox against a limit, export it over IMAP to an archive file before deletion. OquMail mailboxes work with any IMAP client, so a standard export from a desktop mail app produces an archive you can store offline.

Contractors and shared credentials

  • If the leaver knew a shared password (a role mailbox, the Wi-Fi, a social account), change it. This is the strongest argument for never sharing passwords in the first place.
  • If they had access to DNS or the registrar, remove it and review recent DNS changes.
  • If they managed a website contact form or a system that sends mail through your domain, rotate the credentials or API key that system uses.

Mistakes to avoid

  • Deleting the mailbox on day one. Mail bounces, customers assume you closed, and the history is gone.
  • Leaving a forward to the leaver "so they can wrap things up". Set a defined handover instead.
  • Forgetting the mobile phone. A signed-in mail app keeps syncing until the session is revoked.
  • Not checking rules. An attacker who compromised the account months ago may have left a silent forward that survives the password change.

Common questions

Can I read a former employee's mailbox?

In most jurisdictions a company mailbox belongs to the company, but privacy rules on personal content vary. Tell staff in writing, at onboarding, that work mailboxes may be accessed after departure, and limit access to what the business needs.

How long should the auto-reply stay on?

Long enough for regular contacts to update their records; 60 to 90 days is common. After that, close the mailbox and let the role alias catch anything that matters.

What if the person left on bad terms and I suspect they still have access?

Complete the checklist immediately, review the mailbox's sent items and rules, check your mail provider's delivery logs for sends you did not make, and change any shared credential they knew.

Free business email on your own domain

OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.

Get started free

Ready for business email on your domain?

Up to 15 free mailboxes, guided DNS, webmail, and a transactional API — start in minutes.

Create your free workspace