How to Use Email Log Search in Google Workspace

The short answer
A Google Workspace admin can check whether an email was delivered using Email Log Search in the Admin console under Reporting. Search by sender, recipient, subject, or Message-ID, then read the status column: Delivered, Rejected, or Quarantined. Results cover the last 30 days by default; Google Vault extends the window further.
Step-by-step guide to Email Log Search in Google Workspace — trace a missing message, read delivery status, look up a Message-ID, and fix common failures.
On this page
When a message does not arrive — or when a sender insists they sent something and the recipient insists they never got it — someone in IT ends up with a support ticket, two conflicting stories, and no evidence. Email Log Search is the tool in the Google Workspace Admin console that settles those disputes. It shows exactly what happened to every message that touched your domain: whether Google delivered it, rejected it at the gateway, quarantined it as spam, or handed it to another server. This guide explains how to use email log search in Google Workspace, what each status means, how far back the logs go, and what to do when a search comes back empty.
The short answer#
Open the Admin console, go to Reporting, then Email, then Email Log Search. Enter what you know — sender address, recipient address, subject line, date range, or Message-ID — and run the search. The results table shows the delivery status of every matching message. Expand any row to see the full routing path, each hop the message took, the final status, and the reason code if delivery failed.
- Email Log Search lives at Admin console > Reporting > Email > Email Log Search.
- You need Super Admin access or a delegated admin role that includes Reporting privileges.
- The default search window is the last 30 days. Searches further back require Google Vault with a matching retention policy.
- Status values include Delivered, Rejected, Spam, Not Delivered, Encrypted, and Expanded.
- A Message-ID search is the fastest path to one specific message when you already have the ID from the sender's mail headers.
Before you start#
Email Log Search is an admin-only tool. You need a Super Admin account or a delegated admin role that explicitly includes Reports privileges — a role with only User Management access will not see the Reporting menu. If you cannot reach Reporting in the Admin console, ask your Super Admin to grant delegated access with the Reports privilege.
Gather what you know before opening the tool. The more specific the search criteria, the faster the result. At minimum, you need one of: the sender's full email address, the recipient's full email address, or the subject line. If the sender has already checked their sent mail, ask them to open the message, view the full headers, and copy the Message-ID header — a string that looks like a unique identifier inside angle brackets followed by the sending domain. Pasting that into the Message-ID field returns exactly one result and skips all filtering.
The retention window is 30 days by default. If the message was sent more than 30 days ago, Email Log Search will return nothing. To search further back, you need Google Vault configured with a retention rule that covers the relevant mailbox and date range. Without Vault, messages older than 30 days are outside the tool's reach.
Get the Message-ID before you open the tool
How to search email logs in Google Workspace#
The steps below trace a message from the moment it left the sending server to the final delivery event. Work through them in order — later steps assume you have already narrowed the result set.
- 1
Sign in to the Admin console
Go to admin.google.com and sign in with your Super Admin or delegated admin account. If you land in a standard Gmail inbox rather than the Admin console, you are signed in to a regular user account. Switch accounts or use a separate browser profile for the admin session.
- 2
Navigate to Reporting > Email > Email Log Search
In the left sidebar, click Reporting. If you see a condensed navigation menu, expand it. Inside Reporting, choose Email, then Email Log Search. The tool opens a search form with separate fields for sender, recipient, subject, date range, and Message-ID.
- 3
Enter your search criteria
Fill in the fields you have. For a missing-message trace, enter the recipient address and a date range covering when the sender claims to have sent it. For a specific message, paste the Message-ID. Leave fields blank if you are uncertain — partial matches on subject lines work, but they return more rows to sort through. More specific is always faster.
- 4
Set the date range
The date range defaults to the last 24 hours. Widen it to cover the full period in question, up to a maximum of 30 days per search. If you are unsure exactly when the message was sent, expand the range to be safe — the tool handles wide ranges quickly.
- 5
Run the search and read the status column
Click Search. The results table shows one row per matching message-recipient pair. The Status column is the first thing to read: Delivered means Google placed it in the recipient's inbox or handed it to their mail server; Rejected means Google refused it at the gateway; Spam means it was accepted but quarantined; Not Delivered means Google accepted it from the sender but could not complete delivery after retries.
- 6
Expand a row for the full routing detail
Click any row to expand it. The detail pane shows every routing event: receipt timestamp, sending IP, SPF and DKIM results, which routing rule or compliance policy touched the message, and the final disposition. For a rejected or undelivered message, the reason code here tells you exactly what failed — a policy match, an authentication failure, a recipient not found in the directory, or a content compliance rule.
What each status means#
The status column uses terms that are precise in the Email Log Search context but do not always match what users mean when they say a message bounced or was delivered. The table below maps each value to its meaning and the most common causes.
| Status | What it means | Most common causes |
|---|---|---|
| Delivered | Google placed the message in the recipient's Gmail inbox or handed it to the next mail server for an external recipient. | Normal delivery. If the user cannot find it, check Spam, All Mail, or any inbox filter or label that may have moved it automatically. |
| Rejected | Google refused the message before accepting it. No copy was delivered to anyone. | SPF, DKIM, or DMARC authentication failure; recipient address not in the directory; a content compliance rule set to Reject; a sender policy that blocks the sending IP. |
| Spam | Google accepted the message but placed it in the recipient's spam folder rather than the inbox. | Spam classifier triggered, sending domain on a blocklist, message matched a quarantine policy set to quarantine rather than reject. |
| Not Delivered | Google accepted the message from the sender but could not complete delivery after multiple retry attempts. | Temporary failure on the receiving mail server, the recipient's server offline or misconfigured, storage quota exceeded on the destination. |
| Encrypted | The message was sent or received over an encrypted (TLS) connection. This is a modifier — look at the underlying Delivered or Rejected status in the same row for the actual outcome. | TLS enforcement policies on either the sending or receiving end. |
| Expanded | The message was sent to a distribution list or Google Group, and Email Log Search shows the expanded individual delivery events. | Sending to a group alias. Expand the row to see each member's individual Delivered, Rejected, or Spam status. |
Email Log Search by Google Workspace edition#
Email Log Search is available on every paid Google Workspace edition, but the retention window and whether Google Vault is included vary by plan. The table below summarises what each tier provides as of August 2026 — verify current details on the Google Workspace pricing page, as packaging changes.

| Edition | Log retention | Vault included | Notes |
|---|---|---|---|
| Business Starter | 30 days | No | Standard Email Log Search only. Vault is available as a paid add-on to extend retention. |
| Business Standard / Plus | 30 days | No | Same 30-day window as Starter for Email Log Search. Vault is an optional add-on on both tiers. |
| Enterprise Starter / Standard / Plus | 30 days (live logs); longer via Vault | Yes | Vault is included with all Enterprise editions. Set a retention rule to keep mail audit data beyond 30 days. |
| Education Fundamentals / Standard | 30 days | No | Same constraint as Business tiers. Vault is not included in the base education plans. |
| Education Plus | 30 days (live logs); longer via Vault | Yes | Vault is included. Retention rules can be set to cover the full duration required by the institution. |
What to do when Email Log Search does not work#
Empty results and ambiguous statuses are the two most common failure modes. Each has a specific cause and a specific fix.
| Symptom | Likely cause | What to do |
|---|---|---|
| No results returned | Date range too narrow, wrong address, or message older than 30 days. | Widen the date range to the full 30-day window. Double-check that the addresses match exactly — aliases and alternate addresses can differ from the primary account. If the message is older than 30 days, use Google Vault instead. |
| Status shows Delivered but recipient cannot find the message | Message was delivered but moved by a filter, label, or forwarding rule before the user saw it. | Check Spam, All Mail, and any active inbox filters. Delivered in Email Log Search confirms Google handed the message to the mailbox — not that the user saw it. A forwarding rule may have redirected it to another address. |
| Status shows Rejected with no clear reason code | A content compliance rule, routing policy, or sender policy rejected the message silently. | Expand the row fully and note the exact rule name or policy ID. Open Apps > Google Workspace > Gmail > Compliance and cross-reference. Adjust or create an exception if the rejection was unintended. |
| Status shows Spam but message is not in the spam folder | A quarantine policy moved the message before the user could see it, or it was automatically deleted by a quarantine rule. | Check Admin console > Apps > Google Workspace > Gmail > Spam, Phishing, and Malware for active quarantine rules. Quarantined messages are visible to admins in the Gmail quarantine view. |
| Search times out or returns too many rows | Search criteria too broad — no sender, no recipient, and a wide date range. | Add at least one specific field before running again. Email Log Search is built for targeted lookups, not bulk log exports. Start with the recipient address and a narrow date range. |
The 30-day limit is a hard boundary
A faster way to stay ahead of delivery problems#
Email Log Search answers the question after something has already gone wrong. It does not surface the pattern — that a specific client domain is consistently rejecting your team's messages, that a reply thread has gone quiet because a routing rule intercepted it, or that a thread has stalled waiting for a follow-up that nobody sent.
We build AI Emaily, an AI-native email client that connects to Google Workspace, Gmail, Outlook, and IMAP mailboxes. For teams that lose time to did-you-get-my-email back-and-forth, AI Emaily's rules layer and living brief flag when a thread has gone cold — so the follow-up gets sent before it becomes a support ticket, rather than after. It does not replace Admin console tools; it sits in the workflow where the inbox is actually managed. AI Emaily is available on a 7-day free trial — see current plans at aiemaily.com/pricing.
Frequently asked
See it in AI Emaily
Keep reading

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.