Keeping Your Own Copy of Your Mail
Time: one evening to set up, half an hour a year after that. Repeat: and always before you move providers.
Back up against losing the account, not against losing a message
Make the copy because the account can go away, not because you might delete something by accident. That distinction decides everything else on this page.
A single deleted message usually comes back from the bin within a month. What does not come back is the account itself, and accounts end for reasons that have nothing to do with you being careless: an automated system decides your activity looks wrong and suspends you, a payment fails on a paid plan, a free service is discontinued with six months of notice, or a policy changes in a country you happen to live in. In every one of those cases the appeal process is a form, and the answer is often a single line that explains nothing.
The copy is what turns that from a catastrophe into an annoyance. Ten years of receipts, contracts, warranties and correspondence stay yours regardless of who decides what about the account.
Pick one of three routes and know where it stops
Choose the provider's own export if you want it done tonight, a mail program over IMAP if you want it to keep itself current, or a dedicated sync tool if you have several mailboxes to look after.
The provider's export produces an archive you download, usually as one large file or several. It is complete and it is the least work. It is also a snapshot: it knows nothing about the mail that arrives tomorrow, so it has to be repeated, and on a big mailbox the archive can take hours or days to be prepared.
A mail program configured over IMAP keeps a local copy on your computer and updates it whenever it runs. Make sure it is set to download everything including attachments, and not just headers, which is the default in more programs than you would expect. The catch is that it copies what the server shows it, so a folder you excluded is a folder you do not have.
A dedicated synchronisation tool sits between the two: it talks IMAP, runs on a schedule and leaves plain files on disk. It costs an hour of setup and some comfort with a command line.
Whichever you pick, the connection it uses is an app password or a granted authorisation, so it will appear in the list of things with access to your mail, and it should be the one entry there you are pleased to see.
Choose a format you can still open in ten years
Aim for a copy made of ordinary files: individual messages, or folder-shaped containers holding them, that any mail program can import.
The formats that survive are the boring ones. A single file per folder holding messages one after another, or a directory of one file per message, are both older than most of the software you use and both are readable by anything. A proprietary database belonging to one mail program works perfectly until that program is discontinued, and then your archive needs an archaeologist.
Check that attachments are inside the copy rather than referenced from the server. The invoice is the thing you will need; the message saying please find attached is not.
Keep the folder structure if you can. Ten years of mail in one undifferentiated heap is technically a backup and practically a haystack, which is a reason to have your folders in order before you export rather than after, and one more argument for not letting the mailbox fill up in the first place.
Store the copy where losing one account cannot take it
Put the copy on a disk you own, then put a second copy somewhere physically apart from the first, and encrypt both.
Two copies, because a single external drive is one drop away from being no copies. Encrypted, because this is now a portable, searchable file containing every code, contract and private conversation you have received, sitting outside all of your provider's protections. Disk encryption on the machine plus a passphrase on the archive itself is enough; the passphrase goes in the password manager and on the same paper as your backup codes.
Do not put the only second copy in the cloud storage attached to the mailbox you are backing up. They are usually the same account, and the suspension you are insuring against takes both at once. Any other provider, or a drive at a relative's house, breaks that link.
Test the copy before you call it a backup
Open the archive and read three messages from three different years, plus one with an attachment, and open the attachment.
An untested backup is not a backup. The usual failures are quiet: the export stopped early and the last two years are missing, one folder was never selected, attachments were skipped to save space, or the file needs a program you no longer have. Every one of those looks like success from the outside, because the file exists and has a plausible size.
The test takes five minutes. Do it the day you make the copy, while you still remember which settings you chose and can fix them.
Know what the copy does not give back
Understand the limit clearly: a backup preserves your correspondence, not your identity.
It does not restore the address. Mail arriving at an account you have lost keeps arriving there, or bounces, and nothing on your disk changes that. It does not restore access to the accounts that used the address to recover, which is why an inventory of those and the routes back into them matters more than the archive does, and why recovery routes are set up in advance.
If keeping the address through any of this matters to you, the copy is not the mechanism. An address on a domain you own is, since the domain moves with you and the provider is replaceable, which is the whole case for having your own.
Refresh it on a schedule and before you move
Repeat the copy once a year, and always immediately before changing providers.
Once a year is the right interval for most people: the mail that matters accumulates slowly, and a year of gap is an inconvenience rather than a loss. If you run a mail program over IMAP, the refresh happens by itself and the annual job shrinks to opening it, letting it finish syncing, and running the same five-minute test.
Before a move, the copy is not optional. Import between providers goes wrong in predictable ways, folders arrive as labels or the other way round, duplicates appear, and transfers hit rate limits and stop halfway. Having your own complete archive on disk means none of that is fatal, and it lets you switch off the old account when you are ready instead of leaving it running for years as an unofficial backup, which is the usual pattern described in how a provider move actually goes.
Write down where the copies are and how to open them, in the same place as the rest of the instructions somebody might need without you, since an archive nobody can find is an archive that does not exist.
None of this applies to the temporary inbox on our front page, which is designed to be forgotten and deletes itself on schedule. Anything you would want to keep for ten years should never have arrived there.
The checklist
- Pick one route: the provider's export tonight, or a mail program over IMAP that keeps itself current.
- Confirm it downloads attachments and every folder, not just headers.
- Keep two copies, one of them physically elsewhere, both encrypted.
- Never store the second copy in the cloud account attached to the mailbox.
- Open three messages from different years and one attachment before you trust the copy.
- Refresh once a year, and always before switching providers.
Read next
Changing Your Email Address
Moving to a new address is a project with an order. Which accounts go first, how long to forward, and what breaks in month three.
Moving to a Different Email Provider
You can take the mail with you. You cannot take the address unless you own the domain. The move, in the order that avoids a gap.
Email on a Domain You Own
A domain makes your address portable between providers and makes it your responsibility. What it costs, and what happens if it lapses.