For most businesses today, email is the primary channel for contracts, customer communication, financial transactions, and internal decision-making. That makes email archiving and a well-defined retention policy not just an IT concern, but a legal, operational, and risk management necessity. This guide covers everything from what email archiving actually is, to how to build a retention schedule, configure archiving on a mail server, and stay compliant with data protection law.

What Is Email Archiving and Why Does Your Business Need It?

Email archiving is the process of automatically capturing a copy of every email sent and received by an organization and storing it in a separate, searchable, and tamper-resistant repository — distinct from users' live mailboxes. Unlike a standard backup, an archive is built for long-term compliance retrieval, not just disaster recovery.

The key reasons businesses implement email archiving include:

Email Archiving vs. Email Backup vs. Journaling

These three concepts are often confused. Understanding the distinctions is essential before designing any solution:

Approach Primary Purpose Granular Search Tamper-Proof Typical Retention
Email Archive Compliance, Audit, Legal Hold Yes (full-text) Yes (immutable) Years (per policy)
Email Backup Disaster Recovery No (bulk restore) No 30–90 days
Email Journaling Real-time copy capture Depends on system Depends on system Used with archive

Journaling is the technical mechanism that intercepts a copy of every email at the transport layer — before it arrives in the recipient's mailbox — and forwards it to the archive. This is what makes an archive truly tamper-resistant: users can delete from their inbox, but the journaled copy in the archive remains unaffected.

Building an Email Retention Policy

A retention policy defines which emails must be kept, for how long, and what happens when the retention period expires — automatic deletion, migration to cold storage, or escalation for manual review. A well-designed policy reduces storage costs, limits legal exposure, and makes PDPA compliance far simpler.

Steps to build an effective policy:

Configuring Email Archiving on Postfix with BCC Journaling

For organizations running their own Linux mail server with Postfix, the quickest way to implement basic archiving is using the always_bcc or sender_bcc_maps / recipient_bcc_maps directives to forward a silent copy of every email to a dedicated archive mailbox.

Archive all outbound email

# /etc/postfix/main.cf
# Send a BCC of every outbound message to the archive mailbox
always_bcc = [email protected]

# Or use sender_bcc_maps for domain-level control
sender_bcc_maps = hash:/etc/postfix/sender_bcc

# /etc/postfix/sender_bcc
@yourdomain.com  [email protected]

# Rebuild hash table and reload
postmap /etc/postfix/sender_bcc
systemctl reload postfix

Archive all inbound email

# /etc/postfix/main.cf
recipient_bcc_maps = hash:/etc/postfix/recipient_bcc

# /etc/postfix/recipient_bcc
@yourdomain.com  [email protected]

postmap /etc/postfix/recipient_bcc
systemctl reload postfix

Once journaling is configured, the archive mailbox captures every message. You can then apply any IMAP-based archiving software (such as MailStore, imaparchive, or a custom Elasticsearch pipeline) to index, search, and manage retention on that mailbox.

Email Archiving in Microsoft 365 and Google Workspace

For organizations already on major cloud email platforms, built-in archiving tools are the most practical starting point.

Microsoft 365 — In-Place Archive and Litigation Hold

Microsoft 365 Business Premium and higher plans include In-Place Archive (an auto-expanding secondary mailbox) and Litigation Hold for legal preservation. These are managed via the Microsoft Purview Compliance portal or PowerShell:

# Enable In-Place Archive for a user
Enable-Mailbox -Identity [email protected] -Archive

# Verify archive status
Get-Mailbox -Identity [email protected] | Select ArchiveStatus, ArchiveQuota

# Enable Litigation Hold with a 5-year duration (1825 days)
Set-Mailbox -Identity [email protected] `
  -LitigationHoldEnabled $true `
  -LitigationHoldDuration 1825

# Create a Retention Policy with a 5-year deletion tag
New-RetentionPolicyTag "5 Year Permanent Delete" `
  -Type All `
  -AgeLimitForRetention 1825 `
  -RetentionAction PermanentlyDelete

New-RetentionPolicy "Company Email Retention Policy" `
  -RetentionPolicyTagLinks "5 Year Permanent Delete"

Google Workspace — Vault

Google Vault (included in Google Workspace Business Plus and higher) provides retention rules, holds, and export for Gmail, Drive, and Chat. Retention rules are configured in the Admin Console under Apps > Google Workspace > Vault, or via the Vault API:

# Google Vault API — Create a Retention Rule (Python, using google-auth)
from googleapiclient.discovery import build
from google.oauth2 import service_account

SCOPES = ['https://www.googleapis.com/auth/ediscovery']
credentials = service_account.Credentials.from_service_account_file(
    'vault-service-account.json', scopes=SCOPES)
vault = build('vault', 'v1', credentials=credentials)

# Create a 5-year retention rule for all Gmail
rule_body = {
    'corpus': 'MAIL',
    'defaultOperation': 'EXPUNGE',
    'retentionDuration': '157680000s',  # 5 years in seconds
    'scope': {'includeSharedDriveFiles': False}
}
response = vault.matters().holds().create(matterId='your-matter-id', body=rule_body).execute()

PDPA Considerations for Email Archiving

Thailand's Personal Data Protection Act (PDPA) creates a tension with email archiving that organizations must navigate carefully. Archived emails almost certainly contain personal data — customer names, addresses, email addresses, and potentially sensitive categories such as health or financial information.

Key PDPA principles to apply to your archive:

Practical tip: Before enabling email archiving, consult with your Data Protection Officer (DPO) to define the retention schedule first. Archiving emails without a defined maximum retention period is actually riskier under PDPA than having no archive at all — because you then hold personal data indefinitely with no legal justification for doing so.

Choosing the Right Archiving Solution

The right solution depends on your organization's size, IT capability, and compliance obligations:

On-Premises Archive Software

Suitable for mid-to-large organizations that want full data sovereignty and have in-house IT staff:

Cloud Archive Services

Pay-as-you-go cloud archiving is ideal for SMEs and organizations already on cloud email:

DIY with Open Source (Postfix + Elasticsearch)

# Minimal docker-compose.yml for a self-hosted email archive stack
version: '3.8'
services:
  elasticsearch:
    image: docker.elastic.co/elasticsearch/elasticsearch:8.12.0
    environment:
      - discovery.type=single-node
      - xpack.security.enabled=false
      - ES_JAVA_OPTS=-Xms512m -Xmx512m
    volumes:
      - esdata:/usr/share/elasticsearch/data

  kibana:
    image: docker.elastic.co/kibana/kibana:8.12.0
    ports:
      - "5601:5601"
    environment:
      - ELASTICSEARCH_HOSTS=http://elasticsearch:9200

  mailparser:
    image: python:3.11-slim
    volumes:
      - /var/spool/archive:/mail
      - ./scripts:/app
    command: python /app/mail_to_es.py

volumes:
  esdata:

With this stack, the mailparser container reads journaled emails from disk, parses headers and body text, and indexes them into Elasticsearch. Kibana provides a search interface for administrators. Add authentication and TLS before deploying to production.

Frequently Asked Questions

What is the difference between email archiving and email backup?

Email backup creates periodic snapshots of your mailbox data for disaster recovery purposes — restoring everything if a server fails. Email archiving captures every email in real time into a tamper-proof store that supports granular, full-text search for compliance and legal purposes. Archives are immutable; users cannot permanently delete archived emails even if they remove them from their inbox.

How long should a business retain emails?

Retention periods depend on the type of email and applicable law. General business correspondence should be kept for at least 5 years under Thai accounting law. Contract-related emails should be kept for 10 years matching the general statute of limitations. HR emails should be kept for the duration of employment plus 5 years. Emails containing personal data should have a defined maximum retention aligned with PDPA requirements and deleted when that period expires.

Does a small business need email archiving?

While Thai law does not explicitly require every business to operate a formal archive system, PDPA requires organizations to demonstrate how personal data was processed upon request. Any business that communicates with customers via email, or processes orders and quotations through email, should implement at least basic archiving — for example, enabling journaling on their mail server — to meet these accountability obligations.

If a user deletes an email, can it still be found in the archive?

Yes, and this is a core principle of email archiving. The archive stores a copy of every message captured at the point of transmission, before it reaches the user's mailbox. This means that even if a user permanently deletes an email from their Inbox or Sent Items, the archived copy remains intact and fully searchable by administrators.

Business Email Hosting on Your Own Domain

AsiaGB Email includes SPF, DKIM, DMARC, and high deliverability — starting from 200 THB/year

View Email Plans