Notebookcheck Logo

Your old work email keeps running, and Google recommends it

A hand putting an envelope into a row of letterboxes
ⓘ Element5 Digital / Pexels
Whoever reads the old work address can reset the password on private accounts.
Google tells administrators to hand a departing employee’s email address to a current colleague as an alias. Microsoft suggests forwarding or a shared mailbox. The data protection commissioner for Saxony-Anhalt calls that impermissible. Whoever reads the address can reset private accounts.

On your last day you hand back the laptop, the key and the badge. Nobody thinks about the email address, because there is nothing to hand back. It stays where it always was, on a server that somebody else now administers.

None of that would matter if the address had only ever meant work. For many people it also serves a second purpose. It is the recovery address on a private account. A shop, a streaming service, an account created back when the work address was the one used most often. And whoever reads that address can press "forgot password" on those accounts.

Google recommends this to administrators

The Workspace documentation for administrators covers this case. It describes deleting a departing employee’s account and then assigning the old email address as an alias to a current user. The point is that messages sent to the old address do not vanish. They land in the primary account’s inbox instead.

This is not a grey area. It is the documented vendor recommendation, last updated on Sept. 10 this year. From the company’s side it makes sense, because customer enquiries would otherwise disappear. Google also gives a window for the handover. The address leaves Workspace 20 days after the account is deleted, and until then it can be assigned to another managed user.

The same guide says something else. Google tells administrators to remove the departing employee’s recovery email address and phone number, so that person cannot use password recovery to get back into the company account. The company is protected against the former employee. The reverse direction does not appear in the guide.

Microsoft keeps the address alive too

The Microsoft 365 guide reads much the same. It says you can keep a former employee’s email address active, in case customers or partners still write to it. Forwarding then makes sure the messages reach whoever takes over the work.

The second route Microsoft describes is conversion to a shared mailbox. All existing mail and calendar entries stay, and several people can open them. The matching permission is called Full Access. It lets the assigned account read and manage the mail in someone else’s mailbox.

One aside in the same guide decides everything. With forwarding or a shared mailbox, the departing employee’s account must not be deleted, because it anchors the setup. The common belief that everything disappears after 30 days therefore only holds where deletion happens. With forwarding, the address runs indefinitely.

With an alias, forwarding or a shared mailbox the address keeps running with no end date.

What an email address alone can do

Whether access to the address is enough for an account takeover depends on the service. There is no blanket answer, and that is where it gets interesting.

Netflix describes two reset routes in its help, by email or by text message, and the text route needs a phone number on file. Without a number, only the email route remains. The link expires after 24 hours, and before that it is enough on its own. A Microsoft account sends a verification code to one of the stored options. If the work address is the only one stored, it does the job.

Other providers cannot be judged from their public help pages. PayPal only mentions a security check without naming the methods, and Amazon’s help page blocks automated requests. So the claim that email access is enough everywhere cannot be supported. A service that asks for a second confirmation in an app or with a hardware key is a different matter. There it is not enough.

German regulators see it differently

This is where vendor advice and German law collide. The data protection commissioner for Saxony-Anhalt published guidance on departing employees in August 2025. It states the opposite of what Google and Microsoft advise.

A mailbox with a person’s name in it loses its contractual basis once that person leaves, the guidance argues, which triggers the deletion duty under Article 17 of the General Data Protection Regulation. Forwarding mail to a deputy or successor is therefore not permissible, and neither is granting them access to the mailbox. As a rule, the commissioner writes, immediate deactivation is required.

The guidance even anticipates the case described here. Private messages will arrive even where private use of the work mailbox was forbidden, and those messages deserve protection. Employer access to them has no legal basis. Whether telecommunications secrecy applies on top of that is unsettled, because courts have ruled differently and no supreme court decision exists.

For a mailbox that carries a person’s name, Saxony-Anhalt sees a duty to erase it.

What is proven and what is not

No public case documents a takeover of a private account via a work address that kept running. That belongs in the record. What is proven is the mechanism, plus two cases beside it that show how close the scenario is.

Security researcher Dylan Ayrey of Truffle Security bought the domain of a dissolved startup in January 2025. He then recreated the email accounts of former employees on it. By his account that got him into their ChatGPT, Slack, Notion and Zoom accounts, and into HR systems holding Social Security numbers. A Crunchbase dataset gave him more than 100,000 domains of failed startups available for purchase. His point lands, because an individual has no way to protect that data after leaving. Google disputes the security-flaw framing and points developers to an immutable identifier they should use instead of the email address.

The second case comes from Microsoft’s own support forum. In April 2025 a user described being locked out of an Outlook account held for 15 years, because the recovery address had been switched off with the old job. Study records, immigration papers and a live job application were in that mailbox. The moderator’s reply was short, because alternative routes only work when a second address or phone number is on file.

How many people use a work address for private accounts is unknown. Figures circulate, but they do not survive checking, because the original sources have disappeared.

With forwarding or a shared mailbox there is no deadline that ever runs out.

10 minutes before the last day

Go through the important accounts and check which address is stored for recovery. Google keeps it in the security settings, Microsoft under security info, and shops and streaming services usually put it in the account itself.

Google’s own help on recovery addresses only says to pick one you use regularly, and not the one you sign in with. It does not warn about employer addresses. That step is yours to think of.

One detail makes it easier. After a change to the recovery details, Google keeps sending codes to the old entry for seven more days. Switching shortly after the move therefore leaves both routes open for a week. Switch before the move and the problem never starts.

Google LogoAdd as a preferred source on Google
Mail Logo

No comments for this article

Got questions or something to add to our article? Even without registering you can post in the comments!
No comments for this article / reply

static version load dynamic
Loading Comments
> Expert reviews and news on laptops, smartphones and tech innovations > News > News Archive > Newsarchive 2026 09 > Your old work email keeps running, and Google recommends it
Steffen Zahn, 2026-09-16 (Update: 2026-09-14)