Blog/ Gmail how-tos

How Google Vault Retention Works for Gmail

Nafiul HasanNafiul Hasan· 11 min read
Diagram showing how Google Vault retention rules and legal holds preserve Gmail messages for compliance and eDiscovery

The short answer

Google Vault cannot restore deleted Gmail messages to a user's inbox. It preserves copies of messages — including deleted ones — under retention rules or holds, and lets admins export them as mbox or PST. Returning mail to a live mailbox requires Google Workspace's restore-data feature, not Vault.

Google Vault preserves and exports Gmail messages under retention rules and holds — but it cannot restore deleted mail to a user's inbox.

On this page
  1. 01What Google Vault actually does with Gmail
  2. 02Which Workspace editions include Vault — and what to confirm first
  3. 03How to set a Gmail retention rule in Vault
  4. 04Retention rule versus hold — when each applies
  5. 05When Vault is not finding what you expect
  6. 06A faster way to manage Gmail volume while Vault handles compliance

Google Vault is not a backup system. It is an archiving, eDiscovery, and compliance service built into Google Workspace — and for organizations that rely on Gmail, setting up a Google Vault retention policy for Gmail is one of the most consequential admin decisions you will make. Get it right and you have a defensible archive of every message that matters; get it wrong and you discover the gap when a legal hold arrives or an audit asks for mail that no longer exists.

The most persistent misconception about Vault is that it restores deleted email. It does not. Vault preserves, searches, and exports — but it cannot push a message back into a user's inbox. That distinction shapes everything else: what Vault is for, when to use it, and what to do when you actually need mail returned to a live account. This guide covers the mechanism, the configuration steps, and the precise difference between retention rules and holds.

What Google Vault actually does with Gmail#

Vault has three jobs: preserve, search, and export. When a retention rule or legal hold covers a Gmail account, Vault keeps a copy of every message in a separate compliance store that is invisible to the user. That copy persists even after the user deletes the message, empties the Trash, or leaves the organization. The message is gone from Gmail's interface — it is not gone from the compliance record.

This matters when someone asks whether a deleted email can be retrieved. If the question is whether a user can see it in their Gmail again, Vault is not the answer. Returning a message to a live inbox requires Google Workspace's Restore data function — a separate admin feature available within a defined window after deletion. Vault finds the message, exports it to mbox or PST, and hands it to a lawyer or auditor. It does not write back to mailboxes.

There is a second condition that catches most admins by surprise: Vault only holds messages that were covered at the time of deletion. If a user permanently deleted a message before any retention rule or hold applied to their account, Vault has no copy of it. The coverage must exist before the deletion occurs. This cannot be fixed retroactively for data that was already gone before the rule went live.

Export formats determine how Vault data flows into downstream review. Gmail exports from Vault produce mbox files — the open standard supported by most mail clients and legal review platforms. PST export is also available for workflows that require Microsoft Outlook compatibility. Both formats are generated at the matter level and expire from the download page after a set period, so retrieval should happen promptly after an export completes.

Vault only preserves messages covered before deletion

A retention rule or hold must be active on an account before a message is deleted for Vault to retain a copy. Rules applied after the fact cannot recover messages that were already permanently deleted. When setting up Vault for the first time, apply rules as early as possible — the compliance window you miss today is data you cannot get back later.

Which Workspace editions include Vault — and what to confirm first#

Not every Google Workspace subscription includes Vault. Before configuring anything, confirm your edition supports it. As of mid-2026, Vault is included at no additional cost in Business Plus, Enterprise Starter, Enterprise Standard, Enterprise Plus, and the Education editions listed in the table below. Business Starter and Business Standard do not include Vault by default; organizations on those plans can purchase it as a paid add-on. Verify against support.google.com/vault — edition packaging can change, and the Admin console billing page is the authoritative check.

Three things must be confirmed before you begin the retention rule setup. First, your account needs the Super Admin or Vault Admin role in the Google Admin console. Second, the users you want to cover must be on Google Workspace accounts — consumer Gmail accounts are not covered by Vault. Third, the Vault service must be enabled for your domain under Admin console > Apps > Google Workspace > Google Vault > Service status. If any of these are missing, the retention rule will exist in name but cover nothing.

Workspace editionVault included?
Business StarterAdd-on (paid)
Business StandardAdd-on (paid)
Business PlusIncluded
Enterprise StarterIncluded
Enterprise StandardIncluded
Enterprise PlusIncluded
Education FundamentalsIncluded
Education StandardIncluded
Teaching and Learning UpgradeIncluded
Education PlusIncluded
Frontline editionsVerify with Google

How to set a Gmail retention rule in Vault#

Setting a retention rule takes about five minutes once Vault is activated for your domain. The steps below apply to Gmail. The same flow works for Drive and Chat by selecting a different service in step three.

  1. 1

    Open Google Vault

    Navigate to vault.google.com and sign in with a Super Admin or Vault Admin account. If you see a prompt to activate rather than the Vault dashboard, the service has not been turned on for your domain — enable it first under Admin console > Apps > Google Workspace > Google Vault > Service status, then return here.

  2. 2

    Go to Retention

    In the left navigation, select Retention. You will see two options: Default retention rules and Custom retention rules. A default rule applies to all covered accounts in the domain for a given service. A custom rule narrows scope by organizational unit, group, or search-query conditions such as date range or specific message terms.

  3. 3

    Create a rule for Gmail

    Click Create rule. Under Service, select Gmail. Set the Scope — all accounts in the domain, or narrow by OU or group. Under Retention period, enter the number of days (for example, 2555 for approximately seven years). Choose the expiry behavior: expunge all messages after the period ends, or expunge only messages the user has already deleted. Click Save.

  4. 4

    Confirm the rule is active

    Return to the Retention screen. Confirm the new rule appears with status Active and note the effective date. Rules apply going forward — they do not recover messages already permanently deleted before the rule existed. If you need coverage to begin on a specific date, verify the rule is active before that date passes.

  5. 5

    Verify with a Vault search

    In the left navigation, select Matters and create or open a matter. Run a Gmail search scoped to a test account. Confirm that expected messages appear in results. If the search returns nothing for a user you expected to be covered, check that their account sits in the correct OU and that Vault is enabled as a service for the domain.

Retention rule versus hold — when each applies#

Retention rules and holds address different problems. Confusing them leads to configurations that look correct but leave data exposed at the exact moment it matters most.

A retention rule sets the default message lifespan across your covered accounts. It answers the standing question: how long do we normally keep Gmail? The rule runs automatically in the background with no per-message management. Once the retention period expires, covered messages become eligible for expungement according to the rule's configured behavior.

A hold overrides the retention rule for specific accounts. Holds exist at the matter level in Vault — under Matters, select a matter, then navigate to Holds. When an admin places a hold on an account because of active or anticipated litigation, all messages in that account are frozen regardless of what the retention rule would otherwise allow. Neither the expiration timer nor the user can remove those messages from the vault store. The hold persists until an admin explicitly releases it.

Conceptual illustration comparing a Gmail account without Vault coverage — where deleted messages are permanently gone after 30 days — versus one with a retention rule or hold applied, where a protected copy persists in the vault store even after user deletion
Without Vault coverage, permanent deletion ends the record. With a retention rule or hold active at deletion time, the vault store retains a copy that neither the user nor the retention clock can remove.
FactorRetention ruleHold
PurposeDefault message lifespan policy for the domainLitigation or investigation — indefinite preservation
ScopeDomain-wide, or by OU / groupIndividual accounts within a specific matter
DurationSet number of days, then eligible for expungementIndefinite — until admin releases the hold
Overrides the other?Sets the baseline — is the defaultYes — a hold always beats a retention rule
Effect on Gmail viewNone — user mailbox unchangedNone — user mailbox unchanged
Where to configureVault > RetentionVault > Matters > [matter name] > Holds

When Vault is not finding what you expect#

Vault returns no results for a user you expected to be covered. Check three things: the user's account sits in an OU included by the retention rule, the Vault service is enabled for the domain, and the rule was active before the targeted messages were deleted. If the rule was applied after those messages were permanently deleted, the data is gone — Vault has nothing to show. There is no retroactive fix.

The retention rule does not appear to be expunging old mail. Expungement is not instantaneous. Google's infrastructure processes expungement in batches, and it can take several days after a retention period ends for messages to be removed from the vault store. Run a Vault search scoped to messages older than the retention period; if they do not appear in results, the rule is working correctly and the batch is still pending.

A user under a hold is still able to delete email from Gmail. This is by design. A Vault hold protects the vault store copy — it has no effect on the user's Gmail interface. The user continues to work normally, deleting messages, emptying Trash, and archiving threads. Those actions affect only their Gmail view; the vault copy is preserved separately until the hold is released by an admin.

An mbox export is not opening. The mbox format requires a compatible client — Thunderbird and Apple Mail both support it natively, and most legal review platforms accept it. If your workflow requires PST instead, re-export from the Vault matter using the PST option in the export dialog. Large exports are split into multiple files. Download all parts promptly — exported files expire from the Vault export page after a defined period.

Vault cannot recover data that was never covered

If no retention rule or hold was active before a message was permanently deleted, Vault holds no copy of it. This is the most common cause of empty Vault search results and cannot be remedied retroactively. For messages deleted within Google Workspace's restore window, use the Restore data function in the Admin console under Users — that path is separate from Vault and operates on a different clock.

A faster way to manage Gmail volume while Vault handles compliance#

Vault handles the compliance layer — preservation, holds, and export for legal or audit review. What it does not touch is the daily reality of a Gmail inbox: a volume of messages that still needs to be read, triaged, and answered. For teams that have gotten their retention policies in place, the next bottleneck is usually the inbox itself, not the archive.

AI Emaily is an AI-native email client that connects to the Gmail accounts your team already uses and handles day-to-day triage, drafting, and follow-up tracking. It routes incoming mail by priority, drafts replies using a user-set Context brain and per-contact profiles — not trained on past mail — and surfaces threads that need action before they go quiet. Copilot mode keeps a human approving every reply before it sends; Autopilot handles low-stakes, repeatable categories you explicitly delegate. Vault governs what is preserved; AI Emaily governs what gets done. We build AI Emaily. A 7-day free trial is available at aiemaily.com, with plan details at aiemaily.com/pricing.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Vault handles the archive — AI Emaily handles the inbox

Once your retention policies are in place, the bottleneck shifts to daily Gmail volume. AI Emaily triages, drafts, and follows up on your Gmail using your own voice — with approval before any reply goes out and no training on your mail. Works alongside your existing Google Workspace setup. Start a 7-day free trial at aiemaily.com.

  • 7-day free trial
  • Cancel anytime
  • Every provider