Blog/ Switching and migration

How to Revoke App Access After Switching Email Clients

Nafiul HasanNafiul Hasan· 9 min read
Diagram showing how revoking an OAuth grant removes a switched-away email client's access to your Google or Microsoft mailbox

The short answer

Uninstalling an email app does not revoke its OAuth access. The old client retains a live token and can keep syncing your mailbox until you remove the grant at your provider. Go to your Google Account permissions page or Microsoft account app settings and delete the entry for the old client.

How to revoke email app access after switching clients: remove the OAuth grant at Google and Microsoft before the old app keeps syncing your inbox.

On this page
  1. 01The short answer
  2. 02Before you start
  3. 03Steps: revoking access at Google
  4. 04Steps: revoking access at Microsoft (Outlook and Microsoft 365)
  5. 05Platform differences at a glance
  6. 06What to do when revocation doesn't work as expected
  7. 07A faster way to stay on top of this

When you switch email clients, most guides cover how to set up the new one. Almost none explain what to do about the old one. The gap matters: uninstalling an app does not revoke email app access after switching. The software may be gone from your device, but the OAuth token it was issued stays alive at your mail provider — and the provider will honor it until you explicitly remove it.

This means your old email client can still read, sync, and in some cases act on mail from your account. This guide covers how to revoke that access at Google, Microsoft, and Apple, what to do when the standard steps don't work, and how to handle data the vendor may already hold server-side.

The short answer#

OAuth grants survive uninstallation. When you connected your email app to Gmail or Outlook, your provider issued a token — a persistent credential that authorizes the app to access your mailbox. Deleting the app from your device destroys the local software. It does not destroy the token.

The fix is a single action at the provider: go to connected-apps settings, find the old client, and remove its access. The token is invalidated immediately. The next time the old app attempts to sync, the request is rejected. If the app also cached your messages on its own servers, you then request data deletion from the vendor separately — revocation stops the flow, but it does not erase what is already there.

Before you start#

Check two things before you open any settings page.

  • Which type of access did the app use? OAuth (the modern standard) or an app password (a one-off credential generated manually, common for older IMAP clients)? If you connected by clicking a 'Sign in with Google' or 'Sign in with Microsoft' button, it was OAuth. If you typed a sixteen-character random string, it was an app password. These are revoked in different places.
  • Did you connect more than one mailbox? Many email clients support multiple accounts. Each connection creates a separate grant at that provider. You need to revoke the old client's access at every provider where you connected it — not only the primary one.

Check before you assume the old app is dormant

A dormant email app with a live OAuth token is a real security surface. If the vendor is breached, that token grants read access to your mailbox. If the vendor was sold or shut down, the token may belong to an entity you never agreed to authorize. Revoke proactively, not reactively.

Steps: revoking access at Google#

  1. 1

    Open Google Account permissions

    Go to myaccount.google.com/permissions while signed in to the account you connected. You will see every third-party app that holds an active grant, including all email clients you have ever authorized.

  2. 2

    Find the old email client

    Scroll through the list. Apps are listed by the name the developer registered with Google, which may differ slightly from the app's marketing name. If you use Google Workspace through an employer, this page shows your personal grants; apps approved by your administrator at the tenant level are managed separately in the Google Admin console.

  3. 3

    Click the entry, then Remove Access

    Each entry expands to show the scopes the app requested — for example, gmail.readonly, gmail.modify, or the broader gmail scope. Click 'Remove Access.' The change takes effect immediately; the next sync request from the old app is rejected with an authorization error.

  4. 4

    Check app passwords separately

    If you also set up the client with an app password, it will not appear on the permissions page. App passwords are managed at myaccount.google.com/apppasswords. Delete the entry for the old client. If you do not recognise a password in the list, revoke it anyway — you can create a new one for any client that still needs it.

Steps: revoking access at Microsoft (Outlook and Microsoft 365)#

  1. 1

    Open My Apps

    Go to myapplications.microsoft.com when signed in. For personal Microsoft accounts, you can also reach the same settings via account.microsoft.com, then Apps and services, then Apps and services that can access your data.

  2. 2

    Find the old client and select it

    Microsoft shows each app alongside the permissions it was granted and the date it last accessed your account. The 'last used' date is useful: an app that last synced recently is still active, not dormant.

  3. 3

    Revoke access

    Select the option to remove the app's access or revoke its permissions. The token is invalidated and the app loses the ability to read, compose, or send mail on your behalf.

  4. 4

    For Microsoft 365 work accounts, involve IT

    If your account is managed by an employer or school, apps approved at the tenant level by an administrator will persist even after you revoke your personal consent. You will need to ask an IT admin to remove the app in Microsoft Entra ID (formerly Azure Active Directory). This is a legitimate security request; explain which app and why you want it removed.

Platform differences at a glance#

The mechanism is the same across providers — remove the token grant — but the path varies. The table below covers the four most common cases.

Before and after revocation: before, the old email client holds an active OAuth token and syncs the mailbox; after, the token is deleted at the provider and the app is blocked on its next sync attempt
Revocation happens at the provider, not on the device. The token is invalidated the moment you remove the grant.
ProviderWhere to revoke OAuth accessApp passwords (if used)Admin-controlled grants
Google / Gmailmyaccount.google.com/permissionsmyaccount.google.com/apppasswords — delete the entry for the old clientGoogle Workspace Admin console — admin must revoke apps approved at tenant level
Microsoft / Outlookmyapplications.microsoft.com or account.microsoft.com > Apps and servicesRare for modern clients; review account security settings if in doubtMicrosoft Entra ID admin center — admin controls tenant-wide app consent
Apple / iCloudappleid.apple.com > Sign-In and Security > Apps and websites using Apple IDappleid.apple.com > App-Specific Passwords — delete the relevant entryNot typically enterprise-managed; each Apple ID controls its own grants
IMAP / generic providerNo OAuth grant — access uses your account password or an app passwordChange your account password to invalidate all sessions, or delete the app password in your provider's security settingsVaries by host; check your provider's documentation

What to do when revocation doesn't work as expected#

In most cases, removing the grant is clean and immediate. A few situations are more complicated.

  • The app is not in the list. It may have connected under a different developer name, used a different account, or used IMAP with your main account password rather than OAuth. If you cannot find it, change your account password — this invalidates all IMAP sessions simultaneously — and audit your app passwords for unfamiliar entries.
  • The app still appears to sync after revocation. An email client may show locally cached data and look active while actually being blocked. It will fail on its next live sync request. If real sync activity persists beyond a few minutes, verify you removed the correct entry on the correct account.
  • Admin-controlled access persists on a work account. Apps approved at the tenant level in Google Workspace or Microsoft 365 require an admin to remove them. Individual revocation of your personal consent does not affect those grants. Raise a ticket with IT explaining the app and why it should no longer have access.
  • The vendor cached your mail server-side. Revoking the OAuth token stops future syncing but does not delete data the vendor already holds. If the old client used server-side storage for features like cross-device search or AI drafting, you need to separately request deletion through its privacy settings or support channel.

Revocation stops the flow — it does not erase the past

Once you revoke OAuth access, no new data moves to the old app. But messages, drafts, or contacts the vendor already synced to its servers stay there until you request deletion. Under GDPR and similar frameworks, vendors are required to action data deletion requests within 30 days. Even if those laws do not apply to your jurisdiction, reputable vendors honour the request.

A faster way to stay on top of this#

Manually auditing OAuth grants once after a switch is the minimum. If you change clients regularly or manage several accounts, the list of live grants grows quickly and the gaps between audits get longer. The security risk scales with the number of grants you have forgotten.

AI Emaily connects to your mailbox over OAuth with least-privilege scopes — it requests only what it needs for the features you use, and nothing more. Its audit log shows exactly what the agent has accessed or sent on your behalf. When you stop using it, revoking access is one entry removed from one permissions page. Nothing is cached server-side beyond what you have consented to, and there is no training on your mail. The trial period is seven days with a card required; there is no permanent free tier. Cancel before day seven and you pay nothing.

Disclosure: we build AI Emaily. You can review how it handles mailbox access at aiemaily.com/security and see plan details at aiemaily.com/pricing.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Switching email clients? Keep the access audit clean from day one.

AI Emaily connects over least-privilege OAuth, logs every action, and never trains on your mail. Start a 7-day free trial at aiemaily.com.

  • 7-day free trial
  • Cancel anytime
  • Every provider