BG Beter Geregeld ICT
Security zonder IT-afdeling · 5 min leestijd · 19 July 2026

Automatic out-of-office replies: how much are you actually giving away?

An out-of-office message seems harmless, but it's often packed with information you'd rather not hand to a stranger. What should you leave out — and what's fine to include?

It's July, the suitcases are packed, and at the last minute you switch on your automatic reply. Typed in a hurry, sent — done. But did you know that an out-of-office message often contains exactly the information fraudsters are waiting for? Every year in August we see a spike in fraud attempts that start with a perfectly formatted automatic reply from some holiday destination.

In this post we walk through what's usually too much information, what's perfectly fine to include, and how to write an out-of-office that's both friendly and secure.

Why an out-of-office is interesting for fraudsters

An automatic reply goes to everyone who emails you. That includes the person who bought a spam list last week, or someone pretending to work for one of your suppliers. From a single message they can often work out:

  • That you'll be away for the next two weeks.
  • Who is covering for you and how to reach them.
  • Your job title and which department you belong to.
  • Sometimes even your personal mobile number or your manager's name.

Combine that with a look-alike domain and an urgent email to your colleague ("Hi, I'm abroad right now — could you quickly process this invoice?") and you have the classic CEO fraud, summer edition.

What to leave out

1. The exact dates

"I'll be back on 5 August" is fine. "I'm on holiday with my family in Italy from 20 July to 4 August" is not. Your return date is enough — nobody needs to know how long your home will be empty.

2. The reason

Holiday, sick leave, sabbatical, honeymoon: it's none of the sender's business. "Out of office" is sufficient.

3. Personal mobile numbers

Never put your personal mobile in an out-of-office "for emergencies." If something is genuinely urgent, people can call the office. For everything else, it's an open invitation to callers you'd rather not hear from.

4. Detailed cover information

One name and one business email address is enough. Don't also include the direct phone number, the job title, and a note that this person "is fully authorised to make decisions on my behalf." That last part is precisely what a fraudster wants to read.

5. Internal details

No project names, no client names, no "I'm currently in the closing phase of the acquisition of X." Sounds obvious, but we see it more often than you'd think.

What's fine to include

A good out-of-office is short, friendly, and functional:

Thank you for your email. I'm currently out of the office with limited access to my inbox. From 5 August I'll be back and will respond as soon as possible.

For urgent matters, please contact my colleague Sanne at sanne@example.com.

Kind regards,
Your Name

That's it. No dates, no location, no mobile number, no reason.

Two versions: internal and external

In Microsoft 365 and Google Workspace you can set a different message for internal and external senders. Use that feature. Internally you can be a little more specific ("I'm back on 5 August — urgent quote requests go to Sanne, accounting questions to Peter"). Externally, keep it deliberately vague.

Don't forget: in Outlook this option is turned on by default, but in Gmail you need to explicitly tick the box under "Vacation responder" to send the message only to contacts or only internally. Worth double-checking before you leave.

Brief your colleagues

The risk often shifts to whoever is left behind. Your cover suddenly starts receiving emails like: "Hi Sanne, I saw from Mark's out-of-office that you're covering for him. Could you quickly approve this payment? Mark and I had already discussed it."

So before you go on holiday, agree on a few ground rules:

  • No payments or bank account changes without verbal confirmation.
  • When in doubt: wait. A genuine client can wait a day. A fraudster will push.
  • Don't forward suspicious emails — keep them and review them together after the holiday.

A few quick checks before you head off

  1. 2FA is enabled on your email, accounting software, and cloud storage — including accounts you rarely use.
  2. Your account recovery phone number is still up to date (see also our earlier post on outdated numbers in 2FA).
  3. Your password manager is accessible on your phone, in case you do need to log in while you're away.
  4. Someone has access to the shared inbox in case something goes wrong.
  5. Automatic payments and licences won't expire while you're away.

In short

An out-of-office isn't a personal note to a friend. It's a public message to everyone who knows your email address — including people with bad intentions. Keep it brief, don't include any dates beyond your return date, don't reveal your reason for being away, and agree with your cover that payments and address changes wait until you're back.

Want to make sure your email security is in good shape before you go? Our email security check (SPF, DKIM, DMARC) shows whether your domain can easily be exploited for look-alike messages to your colleagues. And if your 2FA is linked to an old number, that's something you can sort out in half an hour with our 2FA implementation service. Enjoy your holiday.

Onderwerpen

#security #phishing #Mail Beveiliging #Vakantie #Mkb Tips

Volledige gids: Security for SMBs without an IT department: what should you do this quarter?

Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →