Your old email address can belong to a stranger in 12 months

Nobody uses the address from 2011 any more. It is still on file in a form somewhere, at a shop you open once a year, or as the contact address on an account you rarely think about. The mailbox itself has not been opened in years.
A deadline runs at the German providers GMX and WEB.DE. Section 5.3 of the terms says the same thing at both. After 6 months without a login, the stored messages and files can be deleted without asking. After 12 months the provider may release the registered email addresses and make them available to other users. The German wording has no official English version, so that is a translation rather than a quote.
The address does not disappear. It changes owner.
What counts as a login
One misunderstanding about that deadline is stubborn. Forums claim that only signing in through a browser resets the counter. The terms name three routes: a web browser, a mail app and an email client. Anyone whose old mailbox is set up in Thunderbird or in a phone app, and who still fetches mail there, keeps it alive.
That only counts while the client is actually fetching. An account set up three phones ago has usually stopped collecting anything, even if it still appears in some app.
There are six months between the two deadlines, and that gap is a chance. GMX states in its own help pages that signing in remains possible after the mailbox contents have been deleted. Noticing the warning mail inside that window costs you the old messages but keeps the address. Noticing only after 12 months can cost you both.
What depends on that address
The damage does not happen in the empty mailbox. It happens at the services still pointing to it. Almost every sign-in screen has a link marked "forgot password". In most cases it leads to exactly one route, a mail sent to the address on file. Whoever controls that address controls the account.
Google calls the field "recovery email address" and puts it under Security in the account. Microsoft files the same details under "security info". Shops, forums and smaller services often have no separate recovery address at all, so the contact address is the way back in.
Apple is the exception. A forgotten password sends you to a trusted device first, an iPhone or a Mac that is already signed in and has a device passcode. The email address is not the main route there. The same mechanism applies one level down to an old mobile number. The devices still signed in to your accounts show up in the device lists.
The address from your old employer
A second case hits people who never had a free mailbox. Anyone who used a work address for private business during an apprenticeship or an old job hands it back when they leave. The IT department decides what happens to it next.
Microsoft describes the standard route in its own admin documentation. When somebody leaves the organisation, an administrator can "assign the former employee's email address to another employee, or convert the former employee's mailbox to a shared mailbox". Both are ordinary and sensible from the company's side, because work in progress should not be lost.
The private route back in is another matter. The successor now receives the mail a shop sends to reset a password. They need no bad intent for that. It is enough that the message arrives with them.
Google and Microsoft clear out private accounts too, more slowly. Both allow two years without a sign-in. Google may then delete the account and its contents, and it announces that by mail to the account itself and to the recovery address. A dead address means the warning arrives nowhere. Deleted Gmail addresses are at least never handed out again.
What you can do in 10 minutes
Sign in once to every old mailbox that still exists. The clock starts over, and you get to see which services still write there. The subject lines of the past few months are a fairly complete list of your forgotten accounts, and it costs you no research.
Then switch those services to an address you read every day. Google keeps it under Security, Microsoft under security info, shops usually in the profile. Where a separate recovery address exists, it should be with a different provider than the main account, otherwise one outage takes out both.
That leaves the awkward question of whether the mailbox itself is protected. An account that only serves as a way back in still needs its own password and two-factor authentication, because it opens all the others. Where the backup codes for that belong, without handing them to an infostealer, is covered in our piece on backup codes.
If the address is long gone and somebody else has it now, the way through is the services themselves. Most providers let you change the contact address while you can still sign in with the password, and that is the first thing to do at every account affected. Missing the password as well turns the cleanup into a support case with an uncertain outcome.
Anyone who no longer needs the old mailbox at all should switch every service pointing to it first and delete it afterwards. The address is then just as free as it would be after the deadline, only at a moment you choose.








