BG Beter Geregeld ICT
Security zonder IT-afdeling · 5 min leestijd · 13 August 2026

Email addresses of former employees: leave them, forward, or close?

An employee leaves and their email address stays open for years "just in case". That's riskier than it sounds. Here's how to handle it properly.

Someone leaves the company. The laptop gets handed in, the keys too — and then someone mentions the email address. "Let's just keep it open for a bit, a client might still write." Six months later, the address is still there. And so is the one belonging to the person before them. And the intern from 2023.

It sounds harmless, but leaving old mailboxes open is one of the most underestimated risks in any office. Time to take an honest look at what's actually happening — and how to sort it out properly.

Why "just leaving it open" is a bad idea

An active email address belonging to a former employee is attractive to an attacker. Nobody checks it every day anymore. If the password has been leaked somewhere (and that happens more often than you'd think), someone has all the time in the world to poke around. What might they find?

  • Old client correspondence, quotes, and invoices
  • Password-reset emails for services still linked to that address
  • Access to shared folders, calendars, or Teams channels
  • A credible sender address to target your clients with

That last one is arguably the worst. A phishing email from "jan@yourcompany.nl" — while Jan left a year ago — lands neatly in your client's inbox. They trust your domain.

The GDPR angle: you can't just keep data indefinitely

There's also a privacy dimension to this. A former employee's mailbox often contains personal messages, contacts, and sometimes even private correspondence. According to the Dutch Data Protection Authority, you can't simply leave such a mailbox open and read through it. The general guideline is: close it within four weeks of the employee's departure, with an auto-reply directing senders to a different address.

Four weeks is tight, but it's a good benchmark. And it forces you to think about what you actually need from that mailbox — and what you can simply archive.

Three scenarios, three approaches

1. The employee had a lot of client contact

Set up an auto-reply that redirects senders to a colleague or a general address (info@ or sales@). Make the reply sound personal: "Jan no longer works with us. For ongoing matters, please contact Marieke at marieke@…". After a maximum of three months, close the mailbox.

What you don't do: silently forward emails to a colleague. Clients will think they're still emailing Jan, which is misleading.

2. The employee had a mainly internal role

Close the mailbox within a few weeks. Set up a simple bounce message or a brief auto-reply. Internal colleagues will know the person has left anyway.

3. Important correspondence needs to be retained

Export the relevant emails to a shared folder or your CRM. That's storing things in the right place — not keeping an entire mailbox alive.

Don't forget the linked accounts

An email address is rarely just an email address. It's often also the login for dozens of services: the accounting package, the webshop, the email marketing tool, LinkedIn Ads, Google Analytics, the domain registrar. If you close the mailbox but the account at those services still exists, anyone trying to use a "forgot password" button will be locked out.

So before you offboard someone, go through the list of services. Where is this address listed as a contact? Where is it used as a login? Switch those over to a general address (for example, admin@ or a shared inbox) before you close the mailbox.

A simple process that works

This doesn't need to be complicated. A checklist on a single page is enough. At a minimum, it should cover:

  1. Day 1 after departure: change the password, sign out all active sessions on every device, disconnect the 2FA token
  2. Within one week: set up an auto-reply with a redirect
  3. Within two weeks: move linked services over to a different address
  4. Within four weeks: archive any relevant emails
  5. Within three months: permanently close the mailbox

Also schedule a quarterly moment to check whether any "ghost mailboxes" are still open. It takes ten minutes and prevents you from discovering two years down the line that you have twenty active addresses belonging to people who left long ago.

What about people who left ages ago?

There's a good chance that reading this has made you think: hang on, we've still got a few of those ourselves. That's not unusual — it happens almost everywhere. Start with a list: which email addresses exist, who do they belong to, and do those people still work here? Anything that scores a "no" gets dealt with using the steps above.

Want to make sure there are no other old accounts or stray logins floating around? Then a broader access check is a great next step. We'll go through together who has access to what, and clean up whatever no longer needs to be there. Usually done within an hour — and you'll know exactly where you stand.

Onderwerpen

#offboarding #toegangsbeheer #Mkb Security #Mailbeveiliging #Avg Privacy

Volledige gids: Security for SMBs without an IT department: what should you do this quarter?

Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →