Email Privacy at Work: What Your Employer Can See

Assume your work mail is readable by your employer, because it generally is.


On a company email account, assume your employer can read everything — and that this is generally lawful. The account is their system, the mail is usually their record, and most jurisdictions permit monitoring for legitimate business purposes, particularly where a policy says so. The practical conclusion isn't outrage; it's that work and personal email should never share an address, an account, or a device profile.

What an employer can typically see

  • Message contents, sent and received, including deleted mail retained by the system.
  • Metadata — who you corresponded with, when, how often, subject lines.
  • Attachments, and often where files were sent.
  • Calendar entries, including private-marked ones in many configurations.
  • Archived mail under retention or legal-hold policies, sometimes for years after deletion.

Most organisations aren't reading individual inboxes casually — it's usually automated retention, security scanning and eDiscovery rather than a person browsing. But the capability exists, and it gets used during investigations, disputes and litigation.

Where the boundaries sit

This varies a great deal by jurisdiction

In the US, employer monitoring of company systems is broadly permitted, especially with a stated policy. In the EU and UK, monitoring must be proportionate, necessary for a legitimate purpose, and disclosed — employees retain some expectation of privacy even at work, and blanket covert monitoring is generally unlawful.

Elsewhere it ranges widely. If a specific situation matters to you, check your local rules and your employment contract rather than relying on a general article — including this one.

The practical rules

  1. Never use your work address for personal accounts. Shopping, banking, health, job hunting. When you leave — chosen or not — access to that mailbox usually ends the same day, and every account tied to it becomes a recovery problem.
  2. Never use your personal address for work business. It creates records outside their system, which causes problems for them and for you.
  3. Assume anything you write is readable by someone other than the recipient. Not paranoia — a reasonable default.
  4. Don't route personal aliases into a work inbox. An easy accident with a forwarding setup, and it puts your personal correspondence inside their retention system.
  5. Read the acceptable-use policy once. It usually states the monitoring position plainly.

The leaving problem

The most common concrete harm here isn't surveillance — it's losing an address you'd attached things to.

Someone uses their work address for a personal subscription, an online shop, a professional association. They leave, the mailbox closes, and the password resets for all of it now go nowhere. Recovering those accounts ranges from tedious to impossible.

If you've done this, fix it before you need to. How to find what's attached

Where aliases fit — and where they don't

Aliases don't make work email private. Nothing you route into a company mailbox becomes private, whatever the address on the front.

What they do is keep the separation clean: your personal aliases forward to your personal inbox, and none of it touches company systems. If your role involves signing up to vendors and services, per-vendor aliases on the company domain are also worth having, so you can see which supplier leaked the company's details. The business setup

More: the complete guide · the checklist

Part of the Email Privacy guides.

The full picture: The Complete Guide to Email Privacy

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading