Your Mailbox After You Are Gone

Time: one hour once, twenty minutes a year afterwards. Repeat: annually, and after any major change in your life.

Start from the mailbox, because it opens everything else

Plan the mailbox before you plan anything else digital, because it is the key that the rest of your accounts hand their locks to. Photos, documents, subscriptions, the bank, the domain your family's addresses run on: every one of them can be reset by whoever reads your mail.

That is also why it is the hardest thing to pass on. Providers know exactly how much power the mailbox holds, so they protect it harder than anything else they run, and a death certificate does not usually produce a login.

An hour of preparation is the whole job. Almost all of the pain in this area comes from that hour never happening.

Use the provider's own mechanism and know what it does not do

Set up whatever inheritance feature your provider offers, today, because it is the only route that works without a legal process. There are three common shapes and they are not equivalent.

An inactive account mechanism, which watches for a long period of no sign-ins, then notifies people you nominated and optionally shares selected data with them. It is the strongest of the three because it runs automatically, and its weakness is that it fires only after the inactivity period has elapsed, which can be months after it was needed.

A legacy contact, where you nominate a person in advance who can then request access after your death, usually with limits on what they can see and what they can do. Better than nothing and much better than the third option.

Closure on request, where the family can have the account shut with evidence, but not opened. That is what you get by default if you nominated nobody, and it is the outcome most people are unknowingly heading for.

Go into each of your accounts and check which of these exists there. Set it up while you are reading this, since it is a settings page and five minutes, and then write down that you did it, because a nominated contact who does not know they were nominated is a wasted setting.

Do not leave a password in an envelope

Skip the sealed envelope with the password in it. It fails on both sides: legally it proves nothing about who you meant to have access, and technically it stops at the second factor.

Every account worth inheriting has a second step on it, and that step is a code on a phone, an app, or a physical key. A password alone gets your family to the same screen a stranger would reach. Meanwhile the envelope has been sitting somewhere for years, unversioned, going stale each time you changed the password, and nobody can tell whether it is current until the moment it needs to work.

Give one person a real route to the password manager

Set up emergency access in your password manager, since that is the mechanism designed for exactly this. Most of them offer it: you nominate a person, they request access, you have a waiting period in which to decline, and if you do not respond, they receive it.

This solves the problem the envelope cannot. It stays current automatically because it grants access to the live vault rather than a snapshot. It is revocable. And it covers not just the mailbox but every account inside the vault, which is the real inheritance.

Make sure two things are actually in there: the mailbox itself, and the second factor. A vault holding the password but not the recovery codes is the envelope problem again in a better container. If you are unsure what a complete set looks like, recovery options that hold up covers the pieces and how each of them fails.

Write one page that says what exists

Write a single page listing what exists, and keep it free of passwords. This is the document families actually need, and it is nearly always missing.

What belongs on it: which mailboxes you have and which is the important one; where the password manager is and who has emergency access to it; the accounts that hold money or property, including any subscriptions billing a card; any domain you own, with the registrar's name and the renewal date; where the photos live; and who to notify. Names and locations, not credentials.

Passwords are what makes a document dangerous to store and impossible to keep current. A list of what exists stays true for years, is harmless if someone reads it early, and turns an impossible search into a set of phone calls. Consider whether a copy belongs with whoever handles the household's paperwork already, which pairs naturally with the shared arrangements in family and household mailboxes.

Understand what doing nothing actually causes

Look at the specific outcomes rather than the general idea of untidiness, because each of them has happened to somebody this year.

Subscriptions keep charging the card, sometimes for years, and cancelling them requires access to the accounts that nobody has. A domain goes unrenewed, and every address on it stops working, which takes the mail of anyone else in the family who used it; that failure is described in full in email on a domain you own. Photos and documents in the provider's cloud are deleted under the inactivity policy, on a schedule the family only learns about afterwards, and the mailbox goes with them, as set out in what happens to an abandoned mailbox.

The pattern is that the losses are irreversible and each one is caused by an account nobody could open. None of them requires bad luck. They are the default.

Tell your family not to sign in as you

Say plainly, in the document, that nobody should log into your accounts using your credentials after your death. This protects them, not the provider.

In several countries, using another person's account credentials is unlawful regardless of intent and regardless of family relationship, and terms of service almost universally prohibit account sharing and transfer. A family that quietly logs in usually gets away with it and occasionally does not, and the ones who do not are dealing with it while grieving. It also destroys the evidence trail that a provider's legitimate process would rely on.

The correct route is the mechanism you set up, or failing that the provider's official process for a deceased user's account, which exists on every major service and which they will describe if asked. It is slower. It is also the only version that cannot go wrong afterwards.

Leave a copy where it will actually be found

Store the page in two places: with the person who would handle your affairs, and with whatever documents your family already knows how to find. A perfect list in a drawer nobody opens is the same as no list.

Do not put the only copy inside the mailbox it describes, which is a circular arrangement that fails precisely when it is needed. The same logic applies to your own archive: if there is mail you want kept, keep a copy outside the provider, because the family will find a folder on a drive long before they get into an account. How to make that copy and confirm it opens is in keeping your own copy of your mail.

Reread the page after anything significant: a move, a marriage, a separation, a new domain, a new provider. Twenty minutes a year keeps it true, and a document that is out of date is only slightly better than none.

One small habit reduces the size of the list itself. Every signup you never intend to return to is another entry someone will eventually have to work out; sending those to an address that expires by itself means they never become accounts at all, and what you leave behind is only the things that mattered.

The checklist

  • Set up the inheritance mechanism your provider offers, and tell the person you nominated.
  • Turn on emergency access in your password manager, with the mailbox and its recovery codes inside.
  • Write one page listing what exists and where, with no passwords on it.
  • Include every domain you own, its registrar and its renewal date.
  • Keep a copy of important mail outside the provider.
  • State clearly that nobody should sign in as you, and review the page once a year.

Read next

All guides