This is general orientation, not legal advice — retention requirements vary by industry, jurisdiction, and the specific regulations that apply to your organization. Confirm requirements with your legal or compliance team before setting policy.

There’s no single answer to how long you should keep email — it depends heavily on what the email contains and what industry you’re in. That said, some common patterns show up across most retention frameworks.

How Long Should You Keep Email Records?
How Long Should You Keep Email Records?

Why retention policy matters

Keeping records too briefly can create compliance risk if a regulator or court later asks for something you no longer have. Keeping everything indefinitely creates its own problems — storage costs, discovery burden in litigation, and difficulty finding what actually matters. A deliberate policy solves both.

Commonly cited retention ranges by record type

These are general patterns often referenced in retention guidance, not universal rules — confirm the specifics that apply to you:

What triggers longer retention

Active litigation, a regulatory investigation, or a pending audit generally overrides your normal retention schedule — records relevant to an ongoing matter need to be preserved under a legal hold, regardless of what your standard policy says.

Why format matters for long-term storage

Email stored in a proprietary format — like MSG — depends on having compatible software available years later. PDF is a stable, widely supported format that doesn’t carry that same risk, which is part of why converting archived email to PDF is common practice for long-term retention. See bulk conversion for archiving many emails at once, or legal use cases for document production specifically.

The practical takeaway

Set a retention policy based on your actual regulatory obligations, not a generic default — then use a durable format like PDF so the records remain accessible for however long you’re required to keep them.