Blog · Dmarc
When It Is Safe to Reassign a Former Employee Email Alias
When It Is Safe to Reassign a Former Employee Email Alias
The day after someone leaves, their mailbox goes quiet. But their email alias does not.
An alias like j.smith@company.com is not a private mailbox. It is a routing address that has been collecting replies, password resets, and account verifications from the outside world for as long as it existed. The moment you reassign it to a new person, every one of those incoming messages goes to them instead.
So when is it safe? The honest answer is: almost never automatically, and always with verification first.
This guide covers what can go wrong when alias reassignment is done without checking, how to build a safe process, and how DMARC aggregate reports can surface the evidence you need before you make the switch.
Why Email Aliases Carry More Risk Than Regular Mailboxes After Offboarding
A regular mailbox accumulates sent mail, drafts, and internal threads. An alias accumulates something more dangerous: unsolicited inbound mail from external parties.
When someone creates an account on a SaaS platform, they often use their corporate email alias as the login. When they sign up for a newsletter, conference, or supplier portal, they use the same alias. When they trigger a password reset on a forgotten account, the reset link arrives at that address.
None of that mail lives in your email system. It arrives from outside, directed at the alias, and routes to wherever the alias currently points. The moment you reassign that alias to a new employee, the new owner starts receiving everything the old owner subscribed to or registered with.
IT administrators managing Microsoft 365 offboarding commonly report that receiving another users mail after reassignment is among the most frequent post-offboarding support tickets. It is a documented, recurring problem.
What Can Go Wrong When You Reassign an Alias Too Soon
The risks fall into three categories.
Private mail for the former owner. Subscription services, personal accounts, and invitations addressed to the previous holder still arrive. The new alias owner can read them. If any of those messages contain sensitive data, this is a data exposure incident.
Account takeover risk. If the former employees alias is still registered on third-party services, a password reset triggered from those services will land in the new owners inbox. Depending on what those accounts contain, this could range from embarrassing to serious.
Spam and marketing noise. The new alias owner inherits months or years of newsletter subscriptions and marketing lists. They will receive mail they did not sign up for, from senders who expect the previous owner.
One concrete scenario: a departing employee used their work alias to register a financial services account. Three months after they leave, the new person receiving that alias gets a password reset email from that service. They can click it, reset the password, and access the former employees financial account. This is not hypothetical. It has been reported in security literature as a real attack vector.
The Quarantine Rule: How Long to Wait Before Reassigning an Alias
There is no universally correct waiting period. The right answer depends on what mail the alias is still receiving.
A common recommendation among IT practitioners is a minimum 90-day quiet period. This covers most billing cycles, contract renewals, and recurring subscription confirmations. For aliases that were used to register high-value accounts (banking, healthcare portals, legal services), 180 days or more may be appropriate.
But time alone is not a guarantee. An alias could go quiet for two months and then suddenly receive a password reset from a service the former owner used once two years ago. Waiting helps reduce volume, but it does not eliminate the risk.
How to Check If an Alias Is Still Receiving Mail Before Reassignment
Before you reassign any alias, do these three things.
Step 1: Set up temporary forwarding and monitor. Point the alias to a private audit mailbox that nobody else has access to. Leave it in place for 30 days. Log every message that arrives. This gives you a concrete record of what the alias is still receiving.
Step 2: Search for external registrations. Ask the departing employee to audit their use of the alias before they leave. In practice, most people will not remember every service they signed up with. Do not rely on this step alone.
Step 3: Use DMARC aggregate reports. This is where DMARCFlow becomes directly relevant. If you have DMARC monitoring enabled for your domain, aggregate reports show you which external senders are delivering mail to your domains and which From addresses they are sending to. You can use this to identify whether any external senders are still targeting the alias after the former employee has left.
Specifically, if a DMARC aggregate report shows a high volume of mail from external senders directed at the former employees alias, you know reassignment is not safe yet. If the report shows near-zero external mail over a 60-to-90-day window, the risk drops significantly.
How DMARC Reports Can Reveal Residual External Mail Addressed to the Old Alias
DMARC aggregate reports are not just for catching spoofing. They are also a visibility tool for your own mail flow.
When an external sender delivers mail to user@yourdomain.com, and your DMARC record is properly configured, you receive a daily aggregate report. That report lists the sending domains, the volume, and the result (pass or fail) for each unique sending source.
If you notice that an alias address is still receiving mail from external senders months after the employee departed, that is a signal. Either the alias needs a longer quarantine, or the former employee registered it with services that keep sending regardless of account status.
Tools like DMARCFlow surface these lingering deliveries in aggregate reports, showing which external senders are still targeting an address you expected to go quiet. This makes it possible to make reassignment decisions based on evidence rather than guesswork.
For organizations managing many aliases across multiple domains, the multi-domain monitoring in a DMARC reporting tool makes it practical to check this systematically rather than manually reviewing individual mailboxes.
A Safe Alias Reassignment Checklist
Use this before reassigning any former employee alias:
- [ ] Set up a private audit mailbox for the alias
- [ ] Monitor incoming mail for at least 30 days, ideally 90
- [ ] Review DMARC aggregate reports to identify external senders still targeting the alias
- [ ] Confirm no billing, subscription, or account registration mail is arriving
- [ ] Document the monitoring period and findings
- [ ] Wait a minimum of 90 days from the employees last active day before reassigning, longer for aliases used with high-value services
- [ ] Notify the new alias owner that they may receive residual mail for a short period after reassignment
Frequently Asked Questions
Is it ever completely safe to reassign a former employees email alias?
Complete safety is not guaranteed because you cannot know every service the alias was used with. Following the checklist above significantly reduces the risk, but some residual exposure always remains for aliases that were actively used.
How long should I wait before reassigning an alias?
A minimum of 90 days is a common starting point. For aliases tied to financial, legal, or healthcare services, consider 180 days or more. Use DMARC aggregate reports to verify that external mail volume has dropped to near zero before you proceed.
What happens if someone emails the old address after reassignment?
It depends on your mail routing configuration. If the alias is forwarded to a new mailbox, the new owner receives it. If the alias is set to reject, the sender gets a bounce. If you use a quarantine policy, the message is held for review.
Can I use DMARC reports to check if an alias is still active?
Yes. If external senders are delivering mail to a specific alias address, DMARC aggregate reports will show sending activity from those external domains to that address. A drop in external mail volume is a strong signal that the alias is no longer in active use.
Proper offboarding is one of the most effective email security controls. DMARCFlow helps you monitor your domains for unexpected mail flows, including residual deliveries to former employee addresses. Start with a free DMARC check at dmarcflow.com.