Email Is a Record Too: Capturing and Keeping Official Email

When a town or a company calls me about email, the trouble usually traces back to one assumption: that email is a way of talking, not a way of keeping. Nobody would let a department head shred the signed contract file because it was cluttering a drawer. Yet the email in which that same department head approved the change order often vanishes in a mailbox cleanup without a second thought. Records law in most states doesn't care what a record is written on. It cares what the record is about.
Below is a model memo. I've written versions of it for clerks, county administrators and a few corporate legal departments, and the structure holds up in all of them. Swap in your state's citations and your own retention schedule, have your attorney read it, and adopt it with an effective date and a review date. My commentary sits in the notes between sections.
TO: Elected officials, department heads, all staff, IT
FROM: Records management
RE: Managing official email and electronic messages as records
1. Purpose
This memo sets out how [Organization] identifies, captures, retains, produces and disposes of email and other electronic messages that document official business. It applies to every account used to conduct that business, whatever device or service carries it.
2. What makes a message a record
A message is a record when its content documents the organization's functions, decisions, policies, transactions or obligations. Format does not decide record status. An email approving a payment, answering a permit applicant, setting a deadline or explaining a policy is a record, exactly as a letter or a memo would be. Attachments are judged on their own content.
Messages fall into three groups:
- Records with a scheduled retention period, kept for as long as the retention schedule requires for that kind of record.
- Transitory records: messages with short-term value, such as meeting logistics, "FYI" forwards, reminders and superseded drafts. Keep these until they are no longer needed, then delete them.
- Non-records: spam, vendor marketing, personal messages unrelated to work, and extra copies kept only for convenience.
Note: Staff will ask for a list of which emails are records. Give them the three groups and five examples from their own department instead. A list of every possibility is never finished, and nobody reads past page two.
3. How email is captured
[Organization] manages email at the account level rather than relying on each employee to sort every message. The email system keeps a protected copy of all messages sent and received, through journaling or an archive with retention policies applied, which users cannot alter or delete. Retention is assigned to each account according to the role of the person who holds it (Section 4).
Records that belong to a case, project or contract file are also saved to that file in the appropriate system, so the file is complete without anyone having to search a mailbox.
Note: This is the logic of the Capstone approach the National Archives developed for federal agencies: decide retention by the role of the account holder, not message by message. The accounts of designated senior officials are kept permanently, and everyone else's are kept for a set period and then destroyed. Federal rules don't bind a town, but several state archives have adapted the idea for state and local governments, so ask yours whether it has. On the technical side, the major platforms can do this with tools they already include: retention policies and archive mailboxes in Microsoft 365, Vault in Google Workspace, or a third-party archiving service. The hard part is the role list, not the software.
4. Retention by role
| Role category | Examples | Mailbox retention (example only) | At end of retention |
|---|---|---|---|
| Senior officials | Elected officials, chief executive or administrator, clerk, department heads, legal counsel, principal deputies | Permanent | Transfer to the archives under state guidance |
| Program and professional staff | Planners, engineers, assessors, finance, inspectors, HR | Fixed period from the schedule, e.g. 7 years after the message date | Destroy with documented approval |
| Administrative and support | Reception, scheduling, general clerical support | Shorter fixed period from the schedule, e.g. 3 years | Destroy with documented approval |
| Shared and functional mailboxes | permits@, info@, billing@ | Same as the longest-lived record series the mailbox handles | Review, then destroy or transfer |
| Departing employees | Anyone leaving the organization | Account kept for the period of the role held; never deleted at offboarding | As for the role |
| Transitory messages, any role | Logistics, reminders, superseded drafts | Until no longer needed | Routine deletion by the user |
The periods shown are examples only. The controlling periods are those in [retention schedule and citation].
Note: Role-based retention keeps some messages longer than strictly necessary. That is the price of not asking hundreds of people to classify every message correctly, forever, and in my experience it is worth paying. If your schedule is out of date or nobody follows it, fix that first; our piece on writing a retention schedule departments will actually follow covers how.
5. Personal accounts, texts and messaging apps
Official business is conducted on official accounts. When an official or employee sends or receives a message about official business on a personal email account, a personal phone or a messaging app, that message is a record. The sender must copy or forward it to their official account within [X] days so that it is captured.
- Text messages about official business on organization-issued phones are captured through [mobile device management or archiving tool]. Messages on personal phones must be forwarded or exported to the official account.
- Chat in Teams, Slack or similar tools follows the same retention as email for the same role.
- Apps with disappearing or self-deleting messages may not be used for official business.
Note: Courts in a number of states have held that public business done on a private account is still public business, reachable by a records request, and federal employees face a statutory deadline to copy such messages to an official account. A policy that pretends personal phones don't exist protects no one. Telling people plainly what to do with that one stray text actually works.
6. Public records requests
When a request includes email:
- The records officer, not the employee whose mail is involved, runs the search in the archive.
- The search is documented: accounts searched, date range, search terms and the date it was run.
- Results are de-duplicated and reviewed for exemptions. Each redaction is logged with its legal basis.
- Records are produced in the format agreed with the requester, or in the standard format in Section 8.
- The request file keeps the search record, the produced set and the redaction log for the period the schedule sets for request files.
Note: Step 1 matters more than it looks. Asking someone to search their own mailbox for the messages a resident is complaining about is unfair to them and looks bad for the organization, even when everyone is acting in good faith.
7. Legal holds
When litigation, an audit or an investigation is pending or reasonably anticipated, legal counsel issues a written hold. IT places a preservation hold on the mailboxes and message accounts of the named custodians, which suspends deletion for those accounts regardless of retention settings. Custodians receive written notice and acknowledge it. A hold stays in effect until counsel releases it in writing, after which normal retention resumes.
Accounts of departing employees who are under a hold are preserved intact.
Note: The common mistake is the opposite of the one people fear. Organizations nervous about holds switch off all deletion everywhere "to be safe" and end up with fifteen years of everything, all of it discoverable. Targeted holds, with normal retention for everyone else, is the defensible position.
8. Export and long-term formats
| Format | What it is | Use it for |
|---|---|---|
| EML | One message per file in the standard internet message format, headers and attachments included | Producing individual messages; transfer to an archive |
| MBOX | Many messages in one text-based file | Exporting whole mailboxes or folders; a common input for archival email tools |
| PST | Microsoft Outlook's proprietary data file | Short-term moves between Microsoft systems; not a preservation format |
| PDF/A | ISO 19005 archival PDF of a rendered message | Print-style copies for requesters and case files; PDF/A-3 can carry the original EML embedded inside it |
Permanent mailboxes are transferred to the archives as EML or MBOX files with an inventory and checksums, not as a stack of PDFs.
Note: A PDF of an email looks complete, but it drops much of the header information that shows when and how a message traveled. Produce PDFs for convenience and keep the native messages as the record. If what you have is older, such as a retired mail server, an export in a format nobody recognizes or a closet of backup tapes, check our field reference to legacy formats and media and the overview of legacy data and media conversion before assuming anything is recoverable.
9. Responsibilities
- Records management maintains this policy and the role list, approves disposition and runs records request searches.
- IT configures retention and holds, keeps the archive working and reports any failure that could cause loss.
- Department heads tell records management when a role changes, so each account's retention category follows the person.
- Legal counsel issues and releases holds and advises on exemptions.
- Every employee uses official accounts for official business, forwards anything that lands on a personal device, and deletes transitory messages.
This policy is reviewed every [two] years and whenever the email platform changes.
One last piece of advice from outside the memo: test it. Once a year, invent a request ("all messages about the transfer station contract, two named staff, a six-month window") and run it from start to finish. The first time you do, you will probably find a shared mailbox that never got a retention category and a former department head whose account was wiped the week she left. Better to find them in a drill than in a deposition.


