There are many reasons that you need to keep all of your business’s emails. The period over which you are legally required to keep all emails varies from country to country, from state to state and by industry.
If you only have time for a quick look at the tools, here is our list of the best email archiving solutions:
- SolarWinds MSP Mail Assure (FREE TRIAL) An email security and management service.
- Proofpoint Essentials A package of email security and management services that includes archiving.
- Topsec Email Archiving Specialized email archiving service.
- Barracuda Essentials An email security and management services bundle.
- ArcTitan A dedicated email archiving service.
- modusCloud Email Archiving Email archiving from an email security specialist.
- SolarWinds Spam Experts An email archiving service aimed at web hosts and ISPs.
- Hornetsecurity Email Archiving An email archiving service with automated email selection and transfer.
- Intradyn Email Archiver A comprehensive email archiving service with legal compliance features.
Keeping in mind how quickly an individual’s’ inbox can fill up, you will soon realize that a business that has been operating for a number of years soon builds up a very large back catalog of emails. The storage of these takes up a lot of space and that costs money.
You need to copy over all of your data onto a remote server in order to protect against a disaster on your premises destroying your on-site data stores. With email, you also need to store those old emails in an accessible and searchable format.
- Legal requirements for email archiving
- Obligations over email storage
- The evolution of electronic archiving
- The best email archiving solutions
- Select an email archiving solution
Legal requirements for email archiving
As the years pass, more legislation is put in place and new data protection standards arise. Each of these legal events creates new obligations. So there isn’t one single rule on how long you must retain emails. The legal requirement for email retention is different in each country. However, to give an idea of how complicated things have gotten, here is a list of the current obligations in the USA.
- PCI DSS (payment card processing) 1 year
- FCC (telecommunications industry) 2 years
- FOIA (federal, state, and local agencies) 3 years
- DOD 5015.2 (defense contractors) 3 years
- FDIC (banking) 5 years
- Food manufacturers 7 years
- Pharmaceutical industry 7 years
- IRS 7 years
- SOX 7 years
- Gramm-Leach-Bliley Act (finance) 7 years
- HIPAA (healthcare) 7 years to life
- SEC 204-2 (financial advisers) 7 years to life
- SEC 17a (securities and investments) 7 years to life
This list doesn’t take into account industry conventional practices or other advice that might recommend longer email storage periods.
Obligations over email storage
Naturally, as you are legally obliged to protect all of the data that your company holds, you need to ensure that the remote store of emails is kept secure with access restrictions and encryption. You also need to decide a time period for archiving.
There is no legal obligation over the length of time that you keep emails available within your mail server and when to archive them off. The only legal requirement is that those emails should be accessible immediately on demand and that they should not be amended.
Fortunately, all of the requirements for archiving emails are taken care of by specialist services, so you don’t have to go to the bother of putting specialized protection measures in place or working out how to transfer emails securely to the remote storage.
The evolution of electronic archiving
Thanks to the Cloud, it is now very easy to locate good email archiving services. The Software-as-a-Service model combines server facilities with managing software and that is a perfect combination for email archiving.
Specialist companies that operate in this niche know all of the legal requirements for the services that they offer. That expertise can put your mind at rest, knowing that you are fulfilling all of your legal obligations.
For these legal assurances, it is better to subscribe to a specialist email archiving service rather than just zipping all of your email storage files and transferring them to a rented virtual server. The storage format needs to be searchable and have a specific level of security.
The best email archiving solutions
Not every email archiving service goes to the trouble of making sure they are legally compliant. So, you could get yourself into legal trouble if you just pick the first email archive service from search results.
We have researched the industry and come up with a list of recommendations in this field.
You can read more about each of these email archiving solutions in the following sections.
SolarWinds MSP Mail Assure is a very flexible archiving service that is part of a bundle of cloud-based email protection utilities.
The service enables you to use the archive as a live backup utility as well as long-term storage. It is possible to restore an individual email from the archive, should one get deleted from your mail server. You can also restore emails in bulk and search through the archive without having to bring all emails back to base. There is no limit to the length of time that an email can be retained in the Mail Assure archive utility.
The service is designed with legal access in mind, so it includes search facilities that support the e-discovery requirements of auditors and legal teams.
Access to archives is protected with credentials and the storage is encrypted, so not even the technicians running the service could read your company’s emails. Mail Assure complies with all of the legal requirements for email retention.
The Mail Assure package is centered around a mail gateway. All of your incoming emails run through the Mail Assure server before they arrive at your own mail server. Outbound emails pass through the Mail assure system as well. As emails arrive, the Mail Assure system filters out spam, malware, and phishing attempts. This service greatly reduces the volume of emails that your own network needs to deal with. Outgoing emails can be scanned as part of a data loss prevention policy.
As a remote service, Mail Assure frees up resources in your business and it is also able to monitor cloud-based email servers, such as Office 365. You can get a 30-day free trial of SolarWinds MSP Mail Assure.
The Proofpoint Essential email archiving system has a 10-year time horizon. That means each email can remain in the archive for 10 years before being aged out. This is an online service, so it will protect all of your business’s emails from damaging disasters on your premises.
Emails are encrypted in the archive, but Proofpoint systems ensure that each email is readily available on-demand in order to comply with auditing and legal access requirements.
The store accepts emails together with all associated attachments. Those emails get indexed so that they can be easily identified through the system’s search facility.
The system allows you to set different retention policies for different categories of email. The search facilities in the package are tailored to ease the work of auditing and legal teams. This means they don’t have to tie up technicians working for the company in order to gain access to information about the archive and individual emails.
Proofpoint Essentials also includes a continuity service that provides online inboxes for staff should your primary mail server goes down. The continuity service can provide cover for 30 days and will update the mail server with missed emails when it comes back online.
The Proofpoint system is cloud-based and acts as a gateway to your mail server. The service blocks spam, phishing, malware, and impersonator emails. It also enables DLP monitoring of outbound emails. Proofpoint Essentials is available on a 30-day free trial.
Topsec Email Archiving is a cloud-based service from a company that offers a range of email security products. The archiving service is organized to comply with all EU and US data protection legislation. Emails are stored in an encrypted format, but can still be searched and accessed easily by authorized users. The account holder can grant different access rights to each user accessing the emails in storage. All-access events are logged for data security auditing.
Archiving can be scheduled to occur automatically and emails can be pulled back either individually or in bulk. This is an excellent service for organizations on both sides of the Atlantic.
Topsec also offers a continuity service and an email gateway system that blocks the delivery of spam emails and email-borne malware. The services channels both incoming and outgoing emails and gives client companies the opportunity to enforce content policies, and spot data theft attempts.
Barracuda Essentials is a bundle of three cloud services: a secure email gateway, an archiving service, and a continuity service.
The archiving service is fully compliant with US and EU legal requirements. The email archive gets indexed for speedy e-discovery through a search engine built into the storage environment. Retention policies can be varied according to email content. Identified email needed for a legal process can be subjected to a “legal hold” status, which preserves them from tampering.
The secure gateway acts as a continuity service by retaining all passed-through emails for 96 hours. All company inboxes are replicated on the Barracuda server and employees can access their emails during outages of the main mail server through a web browser. The gateway mail system also enables employees to send and compose emails on the company’s domain. When the primary mail server returns to service, the Barracuda system will update it with the emails that arrived during its offline period.
The secure email gateway blocks the delivery of spam emails and emails containing malware, phishing, and impersonator attacks.
You can get a 14-day free trial of Barracuda Essentials.
ArcTitan by Titan HQ is designed to work with Office 365. This cloud storage solution adds encryption, indexing, and a search facility to serve e-Discovery legal requirements. The system conforms with all of the major EU and USA data security standards, including GDPR.
Emails are protected with encryption during transfers between your mail server and the archive. The system requires individual user accounts, each of which can have customized access permissions. Emails can be restored to your primary mail server from the archive on-demand, whether individually, or in bulk.
The service is priced by subscription and is available in two editions: ArcTitan Cloud Email Archive and ArcTitan for Service Providers. Titan HQ offers ArcTitan on a free trial.
The modusCloud family of cloud services is provided by Vircom. The Email Archiving service will integrate with your on-premises mail server and also with Office 365. The archives are encrypted and all communication with your primary mail server is also protected by encryption. The archives are frozen to ensure the emails cannot be tampered with. However, all emails can be easily accessed thanks to indexing and an integrated search facility in the dashboard.
The archives of modusCloud use a 10-year time horizon for all of the emails that it stores. If an audit or legal e-Discovery takes place, searches can issue a hold on the discovered pertinent emails to ensure that they cannot be deleted from the archive.
Other email services offered in the modusCloud suite are a continuity service and a secure email gateway that blocks spam and malware. Vircom offers modusCloud Email Archiving on a 30-day free trial.
Spam Experts is aimed at web hosts and internet service providers. This cloud-based service includes inbound and outbound mail filtering and an archive facility.
Archived emails are compressed and encrypted. However, they are always accessible. The Spam Experts team is well aware of the legal requirements for email retention and their archiving service fully complies with all laws.
Stored emails can be restored individually in case of accidental deletion, or in bulk in cases of system recovery or migration.
The service acts as a gateway to your mail server. As such, it is able to queue emails, should your mail server go down. This delivers a continuity service for short periods of primary mail server downtime and would allow you to take your server offline for maintenance.
The main service of the Spam Experts offering lies in its incoming email filters. These block spam emails, drastically reducing the volume of emails that your network and mail server have to deal with. The system uses AI techniques to identify phishing or scams and it will also block the delivery of malware by email. Outbound emails can be automatically checked for data disclosure.
SolarWinds offers a 30-day free trial of Spam Experts.
Hornetsecurity provides a range of email security services from the cloud, including spam and malware protection, email encryption, email continuity, and email archiving.
The Hornetsecurity Email Archiving system protects email stores with encryption, making unauthorized access impossible. All incoming and outgoing emails get added to the archive automatically as they pass through the Hornetsecurity server on the way to or from your mail server. This means that the service also acts as a backup system. This enables you to immediately restore any or all lost emails on your primary mail server. Archives can easily be searched for e-Discovery and emails can be stored for up to 10 years.
The Intradyn Email Archiver is a very comprehensive service that acts as an immediate backup service as well. The system doesn’t include replacement inboxes for continue access in times of mail server outage, so it can’t be treated as a continuity service. However, as all incoming and outgoing emails are stored in the system automatically, it could be used for disaster recovery.
All of the features of Intradyn were designed with legal requirements in mind. Archives are encrypted for security and also emailed for quick access with an integrated search facility. The system includes a legal hold function. Two very nice extras that few other email archiving services have are a redacting tool and a review and commenting utility, both of which leave the original email untouched.
Select an email archiving solution
This list of recommendations has some very well-planned archiving solutions for email. All of these tools were designed with legal requirements in mind and should keep your company safe from fines for non-compliance. Take advantage of the free trials that many of these services offer to put your top choices to the test.