How to Export a Google Workspace Mailbox: Vault, Data Export and Takeout
Google documents each of these tools on a different help page, with different requirements, formats and time limits. This guide puts them side by side, then goes through each one step by step. It also covers the checklist for a departing employee, where deleting the account too early can destroy the mail you meant to keep.
Everything below comes from Google's own Workspace and Vault help pages, checked on September 28, 2026. Google changes these tools often, so confirm anything critical against the linked page before you rely on it. This is operational guidance, not legal advice on retention or eDiscovery obligations.
Which tool for which situation
Pick the tool from the job you need done, not from the one you already know. The four common situations map to different tools:
| Situation | Best tool | Who can run it | What you get |
|---|---|---|---|
| An employee is leaving and you need a copy of their mailbox | Google Vault export | Admin with a Vault license and export privileges | PST or MBOX, plus metadata CSV |
| Legal hold, investigation or eDiscovery request | Google Vault (hold first, then export) | Vault admin | PST or MBOX with metadata and result counts |
| Whole-organization export (leaving Google, full archive) | Admin Data Export tool | Super admin | Zip archives per user in Cloud Storage |
| The user wants their own mail | Google Takeout | The user, if the admin allows Takeout | MBOX archive of their Gmail |
| A spreadsheet of one label or search, not an archive | Browser extension such as Gmail Exporter | The user, from their own Gmail tab | CSV (free), Excel or JSON (Pro) |
The documented limits in one place
These are the numbers that decide which tool fits your timeline. Each comes from the Google help page linked in the section below it.
| Google Vault | Data Export tool | Takeout (user) | |
|---|---|---|---|
| Scope | Any search: one user, several, an org unit, a date range | Whole org, or specific users/groups/OUs if available | The signed-in user only |
| Gmail format | PST or MBOX (your choice) | Same data as Takeout, in zip files | MBOX |
| Required role | Manage Matters, Manage Searches, Manage Exports | Super admin account at least 30 days old, with 2-Step Verification | None, if Takeout is allowed |
| License | Vault license for the admin and the searched users | Available in all editions | None |
| Speed | Several hours for large exports; stops at 24 h with partial results you can continue | No earlier than 48 h; typically 72 h, up to 14 days | Minutes to a few days; most people get the link the same day |
| Download window | 15 days after the export starts | 60 days from the start (Google-provided bucket) | The archive expires in about 7 days |
| Concurrency | No more than 20 simultaneous exports per organization | Cannot be cancelled from the Admin console once started | Per user |
Google Vault export (one or several mailboxes)
Vault is Google's retention and eDiscovery tool. For exporting a specific person's Gmail, it is the most precise option: you can narrow by account, date and keywords, and choose PST or MBOX.
Who can use Vault
Vault needs a license. Google's Vault overview lists it as included in Business Plus, Enterprise Standard and Plus, Frontline Standard and Plus, all Education editions, and Enterprise Essentials and Essentials Plus (domain-verified only). For other editions, Google points to a Vault add-on or its sales team. Since November 1, 2025, admins also need a Vault license to keep using Vault.
Coverage works per user: Vault can only search and retain data for users who hold a license that includes Vault. If you're on Business Standard without the add-on, you won't have Vault. Skip to the Data Export tool or the user-side options.
On top of the license, the admin running the export needs the Manage Matters, Manage Searches and Manage Exports privileges, according to Google's Export data from Vault page.
Steps to export a mailbox from Vault
- Open Vault. Sign in at vault.google.com with an account that has the privileges above.
- Open or create a matter. A matter is the container for your searches and exports.
- Search Gmail. Choose the service Gmail, enter the account (or accounts), and add a date range or terms if you don't need everything.
- Click Export. Give the export a plain name. Google warns that special characters such as
~!$'(),;@:/?can prevent the download. - Pick the format. For Gmail you choose PST or MBOX for the message files. Optionally include confidential-mode messages and linked Drive files.
- Wait, then download. Under Exports, a green check means it's done. Click Download within 15 days.
If a super admin has turned on multi-party approval for Vault exports, a second Vault admin must approve the request before processing starts. An unapproved request is removed after 15 days.
PST or MBOX?
Choose PST if the mailbox will be reviewed in Microsoft Outlook or in a legal review platform that expects PST. Choose MBOX for Thunderbird, Apple Mail, scripts, or when you want to match messages to Vault's metadata CSV, because Google notes that PST contents can't be correlated with the XML metadata file. PST exports can also leave some messages unconverted; those are delivered separately as EML files.
For the Outlook side of that choice, see how to export Gmail to PST, which also covers personal accounts without Vault.
What's inside a Vault Gmail export
Vault gives you more than the mail files. Per Google's Vault export contents page, a Gmail export includes:
| File | What it's for |
|---|---|
export_name-N.zip | The PST or MBOX files, one set per account. Split into more zips above 1 GB for PST or 10 GB for MBOX. |
export_name-metadata.csv / .xml | Per-message metadata (including labels) as stored on Google's servers. |
export_name-result-counts.csv | Each account, how many messages it owns, and how many exported or failed. |
export_name-errors.xml | Errors retrieving messages. Always present, even when empty. |
export_name-conversion_errors-N.zip | PST exports only: messages that didn't convert, as EML files. |
export_name-drive-links.csv | Only if you chose to export linked Drive files and links exist. |
That metadata CSV is useful on its own. If someone only needs a list of who wrote what and when, it opens straight in a spreadsheet.
When a large export stops at 24 hours
Google says large Vault exports can take several hours. If one isn't finished after 24 hours, Vault stops it and marks it Export contains partial results. You can download what it collected, plus a CSV of accounts that weren't exported, then click Continue export to gather another 24 hours' worth. You can continue as many times as needed. To avoid this, Google suggests splitting the job: fewer accounts per search, or one search per year.
Admin Data Export tool (the whole organization)
The Data Export tool is for exporting everyone, or a large group, when you are leaving Google Workspace or need a full archive. It exports the same data users could get with Takeout, plus admin-only data such as Vault-retained deleted items and messages in admin quarantine. Source: Export all your organization's data.
Requirements
- A super administrator account that is at least 30 days old (unless the organization itself is younger).
- 2-Step Verification turned on for the admin who starts the export.
- Google Cloud turned on for the admin account, because the archive lands in a Cloud Storage bucket.
- With FedRAMP authorization or more than 1,000 users, Google asks you to contact Workspace support first.
Steps and timing
- In the Admin console, go to Data → Data import & export → Data export.
- Click Set up new export and name it.
- Pick the scope: all user data, or specific users, groups or org units if that option is available to you.
- Click Start export. All super admins get an email that an export is pending.
The archive is available no earlier than 48 hours after you start. Google says exports typically take 72 hours but can take up to 14 days. You can't cancel an export from the Admin console once it starts; stopping it requires Workspace support.
The result is a folder per user with zip files split by service, such as Gmail (Part 1) and Gmail (Part 2). In a Google-provided bucket the data is deleted 60 days from the start of the export, and because packets arrive over several days, some may expire earlier than others. Download promptly. The Cloud Storage web UI downloads one object at a time; for whole folders Google shows a gcloud storage cp --recursive command.
Two gaps to know: the tool skips accounts created within 24 hours before the export, and it doesn't include deleted data unless Vault retained it.
User-side: Google Takeout for a Workspace account
A Workspace user can download their own Gmail with Google Takeout, which produces an MBOX file, as long as the admin allows it. Per Google's Allow or block Google Takeout page, Gmail falls under a shared control (called Data export) with Drive, Calendar and Contacts. Admins can't allow Takeout for Gmail alone.
By default the setting is Allowed for Google Workspace. For Google Workspace for Education K-12, the shared control defaults to Not Allowed.
If Takeout is blocked
- Ask the admin for a Vault export of the mail you need. Vault searches can be narrowed by date and search terms.
- Ask whether IMAP is allowed. Admins control IMAP on the POP and IMAP settings page, and allowed clients must support OAuth.
- Check your company's policy first. If Takeout is blocked, that's usually deliberate. Copying work mail out through another route may breach your contract or data-protection rules, even when it's technically possible.
If you're the one leaving, save your emails before leaving a job covers what you can usually keep and what belongs to the employer.
Departing employee checklist (before you suspend or delete)
This is where mail gets lost. Google's delete a user page is explicit: Gmail messages that aren't transferred before deletion are permanently deleted. And if you use Vault, its retention rules and holds stop applying to a deleted user, so the data "can be purged immediately" and can't be recovered, even if you restore the user within the 20-day window.
Work through this list in order:
- Decide what must be kept and for how long. This is a legal and HR decision. Involve whoever owns retention policy, and see Gmail export for HR for the spreadsheet side of offboarding.
- Check for holds. You can't transfer data or delete a user who's on a litigation hold. A Vault admin has to lift the hold first, and Google says that can take up to 48 hours to take effect.
- Export with Vault (if licensed) while the account still exists. Exports already made stay downloadable until they expire, even after deletion.
- Choose how to keep the live data. Options Google documents:
- Archive the user (needs an Archived User subscription, or the Flexible plan). The user can't sign in, the data stays, and with a Vault license it remains searchable and exportable. The active license becomes available to reassign within 24 hours. See Archive former employee accounts.
- Migrate the email to another account, or redirect incoming messages to another address. These are the two Gmail options Google lists before deletion.
- Suspend instead of deleting, if you need time to decide.
- Transfer other data such as Drive files and calendars. Google warns that since early 2026, deleting a calendar owner also deletes their secondary calendars and events.
- Only then delete, if you still need to. You have 20 days to restore a deleted user, and 20 days before the address is removed from Workspace.
- Check licenses. On the Annual/Fixed-Term plan, deleting a user doesn't reduce your license count or bill. You can reassign the license, but restoring the user later needs another.
For law firms or anyone handling client matters, case records for lawyers explains how to organize exported mail by matter.
Verify the export before you rely on it
An export you haven't checked is a guess. Before you delete anything:
- Open
result-counts.csv(Vault) and compare the exported count with the messages owned by each account. The errors file lists what failed. - For PST, open the conversion errors zip. Messages there are real mail that didn't make it into the PST.
- For Data Export, read the status. Complete means all data exported. Errors means some is missing, and Google lets you run a remediation.
- Spot-check against Gmail. Counting a few labels or date ranges in the live mailbox gives you a baseline. Our guide to counting the emails in Gmail shows how.
Need a spreadsheet, not an archive?
Vault and Data Export produce mailbox files for Outlook, review platforms or cold storage. Plenty of requests are smaller: a sales lead needs the contacts from one client label, finance needs every invoice email from Q3, a manager wants a list of the support threads a leaver handled.
For that, an admin console is overkill. The person who owns the mailbox can open the label or search in Gmail and export it with a browser extension. Gmail Exporter runs in the Chrome tab and writes the file to the user's computer, with no admin setup and no Vault license. The free plan exports CSV with the email address, subject, body preview and service. Dates, sent/received direction, names and phone numbers, plus Excel and JSON, are in the Pro plan. See how to export a label to a spreadsheet.
It is not a replacement for Vault. It doesn't export another user's mailbox, it doesn't produce PST or MBOX, and it isn't an eDiscovery tool. Use it when the question is "what's in these emails", not "preserve this mailbox".
Just need one label or search as a spreadsheet?
Export it in one click from Gmail. No admin console, no 48-hour wait.
Add to Chrome — It's FreeFrequently asked questions
Can I export a Workspace mailbox without Vault?
Yes. A super admin can use the Data Export tool in the Admin console, which is available in all editions but exports whole users rather than a filtered search. The user can also export their own Gmail with Google Takeout if the admin allows it, or connect an IMAP client if IMAP is turned on.
How long are Vault exports kept?
Vault export files are available for 15 days after you start the export. After that they're deleted and you must re-create the export. Data Export archives in a Google-provided bucket are deleted 60 days from the start of the export.
Should I export Gmail from Vault as PST or MBOX?
PST if reviewers will use Outlook or a PST-based review tool. MBOX for Thunderbird, Apple Mail or scripts, and when you need to match messages to Vault's metadata file. PST can leave some messages unconverted; Vault delivers those as EML files in a separate zip.
Does deleting a Workspace user delete their email?
Yes. Gmail messages not transferred before deletion are permanently deleted. Vault retention rules and holds no longer apply to a deleted user, so the data can be purged immediately and can't be recovered, even if you restore the user within 20 days. Export or archive first.
Can a regular Workspace user export their own mailbox?
Yes, with Google Takeout, if the admin has left the shared Takeout control on Allowed, which is the default for Google Workspace. Takeout produces an MBOX file. If Takeout is blocked, ask your admin rather than working around it.
How long does the Data Export tool take?
The archive is available no earlier than 48 hours after you start. Google says exports typically take 72 hours and can take up to 14 days depending on size. Once started, an export can't be cancelled from the Admin console.