For most businesses today, email is the primary channel for contracts, customer communication, financial transactions, and internal decision-making. That makes email archiving and a well-defined retention policy not just an IT concern, but a legal, operational, and risk management necessity. This guide covers everything from what email archiving actually is, to how to build a retention schedule, configure archiving on a mail server, and stay compliant with data protection law.
What Is Email Archiving and Why Does Your Business Need It?
Email archiving is the process of automatically capturing a copy of every email sent and received by an organization and storing it in a separate, searchable, and tamper-resistant repository — distinct from users' live mailboxes. Unlike a standard backup, an archive is built for long-term compliance retrieval, not just disaster recovery.
The key reasons businesses implement email archiving include:
- Legal Compliance — Various laws require businesses to retain business records for defined periods. Emails often qualify as business records, especially when they document transactions, agreements, or decisions.
- Internal and External Audit Support — Auditors can search archived email instantly, reducing the time and effort needed to produce evidence during financial or operational audits.
- Litigation and Dispute Resolution — In legal proceedings, properly archived emails are admissible as evidence and can protect the business by proving what was or was not communicated.
- eDiscovery and Data Recovery — If an employee leaves or accidentally deletes important messages, the archive preserves those communications regardless of what happens to the mailbox.
- Business Continuity — Critical communication history remains accessible even during mail server outages or migrations.
Email Archiving vs. Email Backup vs. Journaling
These three concepts are often confused. Understanding the distinctions is essential before designing any solution:
| Approach | Primary Purpose | Granular Search | Tamper-Proof | Typical Retention |
|---|---|---|---|---|
| Email Archive | Compliance, Audit, Legal Hold | Yes (full-text) | Yes (immutable) | Years (per policy) |
| Email Backup | Disaster Recovery | No (bulk restore) | No | 30–90 days |
| Email Journaling | Real-time copy capture | Depends on system | Depends on system | Used with archive |
Journaling is the technical mechanism that intercepts a copy of every email at the transport layer — before it arrives in the recipient's mailbox — and forwards it to the archive. This is what makes an archive truly tamper-resistant: users can delete from their inbox, but the journaled copy in the archive remains unaffected.
Building an Email Retention Policy
A retention policy defines which emails must be kept, for how long, and what happens when the retention period expires — automatic deletion, migration to cold storage, or escalation for manual review. A well-designed policy reduces storage costs, limits legal exposure, and makes PDPA compliance far simpler.
Steps to build an effective policy:
- Classify email by type — Define categories such as commercial correspondence, contracts, HR communications, customer support, internal general, and financial. Each category may have different legal requirements.
- Map applicable laws — Thai Accounting Act requires 5-year document retention. PDPA requires personal data not be kept longer than necessary. Contract-related emails should align with the 10-year general limitation period under the Civil and Commercial Code. Industry-specific regulations (finance, healthcare) may add further requirements.
- Set a sensible default — For uncategorized emails, a default of 3–5 years is common and covers most general business needs.
- Define a Legal Hold process — When litigation or investigation begins, relevant emails must be placed on hold to suspend normal deletion until the matter concludes.
- Communicate the policy internally — Employees must understand that business email is subject to archiving and retention. This is both a PDPA transparency requirement and a practical necessity to prevent shadow deletion.
- Review the policy annually — Laws change, and your business operations change. Schedule a yearly review of retention periods and categories.
Configuring Email Archiving on Postfix with BCC Journaling
For organizations running their own Linux mail server with Postfix, the quickest way to implement basic archiving is using the always_bcc or sender_bcc_maps / recipient_bcc_maps directives to forward a silent copy of every email to a dedicated archive mailbox.
Archive all outbound email
# /etc/postfix/main.cf # Send a BCC of every outbound message to the archive mailbox always_bcc = [email protected] # Or use sender_bcc_maps for domain-level control sender_bcc_maps = hash:/etc/postfix/sender_bcc # /etc/postfix/sender_bcc @yourdomain.com [email protected] # Rebuild hash table and reload postmap /etc/postfix/sender_bcc systemctl reload postfix
Archive all inbound email
# /etc/postfix/main.cf recipient_bcc_maps = hash:/etc/postfix/recipient_bcc # /etc/postfix/recipient_bcc @yourdomain.com [email protected] postmap /etc/postfix/recipient_bcc systemctl reload postfix
Once journaling is configured, the archive mailbox captures every message. You can then apply any IMAP-based archiving software (such as MailStore, imaparchive, or a custom Elasticsearch pipeline) to index, search, and manage retention on that mailbox.
Email Archiving in Microsoft 365 and Google Workspace
For organizations already on major cloud email platforms, built-in archiving tools are the most practical starting point.
Microsoft 365 — In-Place Archive and Litigation Hold
Microsoft 365 Business Premium and higher plans include In-Place Archive (an auto-expanding secondary mailbox) and Litigation Hold for legal preservation. These are managed via the Microsoft Purview Compliance portal or PowerShell:
# Enable In-Place Archive for a user Enable-Mailbox -Identity [email protected] -Archive # Verify archive status Get-Mailbox -Identity [email protected] | Select ArchiveStatus, ArchiveQuota # Enable Litigation Hold with a 5-year duration (1825 days) Set-Mailbox -Identity [email protected] ` -LitigationHoldEnabled $true ` -LitigationHoldDuration 1825 # Create a Retention Policy with a 5-year deletion tag New-RetentionPolicyTag "5 Year Permanent Delete" ` -Type All ` -AgeLimitForRetention 1825 ` -RetentionAction PermanentlyDelete New-RetentionPolicy "Company Email Retention Policy" ` -RetentionPolicyTagLinks "5 Year Permanent Delete"
Google Workspace — Vault
Google Vault (included in Google Workspace Business Plus and higher) provides retention rules, holds, and export for Gmail, Drive, and Chat. Retention rules are configured in the Admin Console under Apps > Google Workspace > Vault, or via the Vault API:
# Google Vault API — Create a Retention Rule (Python, using google-auth)
from googleapiclient.discovery import build
from google.oauth2 import service_account
SCOPES = ['https://www.googleapis.com/auth/ediscovery']
credentials = service_account.Credentials.from_service_account_file(
'vault-service-account.json', scopes=SCOPES)
vault = build('vault', 'v1', credentials=credentials)
# Create a 5-year retention rule for all Gmail
rule_body = {
'corpus': 'MAIL',
'defaultOperation': 'EXPUNGE',
'retentionDuration': '157680000s', # 5 years in seconds
'scope': {'includeSharedDriveFiles': False}
}
response = vault.matters().holds().create(matterId='your-matter-id', body=rule_body).execute()
PDPA Considerations for Email Archiving
Thailand's Personal Data Protection Act (PDPA) creates a tension with email archiving that organizations must navigate carefully. Archived emails almost certainly contain personal data — customer names, addresses, email addresses, and potentially sensitive categories such as health or financial information.
Key PDPA principles to apply to your archive:
- Establish a lawful basis — The most defensible basis for archiving is usually Legitimate Interest (for operational continuity and dispute resolution) or Legal Obligation (where specific laws require document retention). Document your basis in writing.
- Disclose archiving in your privacy notice — Inform employees, customers, and other data subjects that email communications may be retained for compliance purposes and for how long.
- Restrict access to the archive — Only designated administrators or compliance officers should be able to search the archive. Log every access.
- Handle Subject Access Requests (SAR) — You must be able to locate, extract, and if requested, delete personal data held in your archive. This requires a well-designed search interface and a clear deletion workflow.
- Set maximum retention periods — Do not archive personal data indefinitely. Configure automatic deletion once your defined retention period expires, and document this in your Record of Processing Activities (RoPA).
- Secure the archive — Apply encryption at rest and in transit. Restrict network access to archive infrastructure. Include the archive in your regular security and data breach response procedures.
Practical tip: Before enabling email archiving, consult with your Data Protection Officer (DPO) to define the retention schedule first. Archiving emails without a defined maximum retention period is actually riskier under PDPA than having no archive at all — because you then hold personal data indefinitely with no legal justification for doing so.
Choosing the Right Archiving Solution
The right solution depends on your organization's size, IT capability, and compliance obligations:
On-Premises Archive Software
Suitable for mid-to-large organizations that want full data sovereignty and have in-house IT staff:
- MailStore Server — Popular SME-focused archive with a clean web UI, full-text search, and connectors for Exchange, Microsoft 365, and IMAP servers.
- Barracuda Message Archiver — Appliance-based solution for organizations that need integrated Compliance and eDiscovery workflows.
- OpenMailArchive — Open-source option for IT teams with budget constraints who are comfortable with Linux administration.
Cloud Archive Services
Pay-as-you-go cloud archiving is ideal for SMEs and organizations already on cloud email:
- Mimecast Archive — Combines cloud email security, continuity, and archiving in a single platform.
- Proofpoint Essentials Archive — Cost-effective compliance archiving for SMBs.
- Microsoft Purview Compliance — Best option for organizations fully committed to the Microsoft 365 ecosystem; includes archive, eDiscovery, Legal Hold, and data loss prevention.
DIY with Open Source (Postfix + Elasticsearch)
# Minimal docker-compose.yml for a self-hosted email archive stack
version: '3.8'
services:
elasticsearch:
image: docker.elastic.co/elasticsearch/elasticsearch:8.12.0
environment:
- discovery.type=single-node
- xpack.security.enabled=false
- ES_JAVA_OPTS=-Xms512m -Xmx512m
volumes:
- esdata:/usr/share/elasticsearch/data
kibana:
image: docker.elastic.co/kibana/kibana:8.12.0
ports:
- "5601:5601"
environment:
- ELASTICSEARCH_HOSTS=http://elasticsearch:9200
mailparser:
image: python:3.11-slim
volumes:
- /var/spool/archive:/mail
- ./scripts:/app
command: python /app/mail_to_es.py
volumes:
esdata:
With this stack, the mailparser container reads journaled emails from disk, parses headers and body text, and indexes them into Elasticsearch. Kibana provides a search interface for administrators. Add authentication and TLS before deploying to production.
Frequently Asked Questions
What is the difference between email archiving and email backup?
Email backup creates periodic snapshots of your mailbox data for disaster recovery purposes — restoring everything if a server fails. Email archiving captures every email in real time into a tamper-proof store that supports granular, full-text search for compliance and legal purposes. Archives are immutable; users cannot permanently delete archived emails even if they remove them from their inbox.
How long should a business retain emails?
Retention periods depend on the type of email and applicable law. General business correspondence should be kept for at least 5 years under Thai accounting law. Contract-related emails should be kept for 10 years matching the general statute of limitations. HR emails should be kept for the duration of employment plus 5 years. Emails containing personal data should have a defined maximum retention aligned with PDPA requirements and deleted when that period expires.
Does a small business need email archiving?
While Thai law does not explicitly require every business to operate a formal archive system, PDPA requires organizations to demonstrate how personal data was processed upon request. Any business that communicates with customers via email, or processes orders and quotations through email, should implement at least basic archiving — for example, enabling journaling on their mail server — to meet these accountability obligations.
If a user deletes an email, can it still be found in the archive?
Yes, and this is a core principle of email archiving. The archive stores a copy of every message captured at the point of transmission, before it reaches the user's mailbox. This means that even if a user permanently deletes an email from their Inbox or Sent Items, the archived copy remains intact and fully searchable by administrators.
Business Email Hosting on Your Own Domain
AsiaGB Email includes SPF, DKIM, DMARC, and high deliverability — starting from 200 THB/year
View Email Plans