Who opened my mail
A record of who read, moved, flagged or deleted mail in somebody's mailbox when it wasn't them: delegates, shared mailboxes' members, colleagues and administrators.
People can reach mail that isn’t theirs: a delegate reads a manager’s mail, members work in a shared mailbox, a colleague sees a folder somebody shared, and an administrator can take a message out of every mailbox. Each mailbox keeps a record of what was done in it by anybody but its owner, so a person can see who opened their mail, and an auditor can prove it.
The examples use the vsx shell function from the Quick start.
What is recorded
| Action | When |
|---|---|
| Opened | A message’s text or attachments were read: in a mail app, over JMAP, or downloaded. Seeing a message in a list, its sender and subject only, is not opening it. |
| Moved, copied | A message was moved to another folder, or copied out. |
| Flagged | A message’s flags changed: read, flagged, marked for deletion. |
| Deleted | A message was deleted. |
| Recovered | A message was put back from deleted mail: on the console, over the API, by a mail app over JMAP, or on the person’s own page. |
| Purged, released, discarded | An administrator took a message out of every mailbox, or released or discarded it from quarantine. |
| Hold set, hold lifted | An administrator put the mailbox on legal hold or lifted it. |
Each entry says who did it, and what they were to the mailbox then: delegate, shared mailbox member, colleague with a shared folder, or administrator. It also says which messages it was, by sender and subject, never what they say; which app or service it was done through; and from which network address.
Actions are grouped: a session that opens a hundred messages in a minute is one entry naming the hundred.
A person’s own actions in their own mailbox are not recorded, unless the organisation names them (below).
A POP3 mail app only ever reaches its own account’s inbox, so what it does is recorded only for the people the organisation names. Downloading a message, or the first lines of its text, is opening it; fetching its headers alone is not. A message the app deletes is recorded when the app ends the session and the deletion is carried out; one the app takes back, or a session that drops first, deletes nothing and records nothing.
Seeing it
People themselves. On their account page, people see who worked in their mailbox, and whether each person can still reach it today. They can take a delegate’s access away themselves, with their password: POST /account/delegates lists who may work in their mail, and POST /account/delegates/remove with delegate set to that person’s address takes them off, with every right they had, leaving everybody else as they were. Their mail app can offer this. Taking somebody off is in the audit log. Only an administrator adds a delegate, under Delegates, and changes a shared mailbox’s Members.
Administrators and auditors. On the console, open the person from People and choose Mailbox activity. Filter it by who and by day, and download it as a CSV file. From the command line:
vsx admin mailbox activity ada@example.com
vsx admin mailbox activity ada@example.com --by bob@example.com --from 2026-10-01
vsx admin mailbox export-activity ada@example.com --to ada-activity.csv
Organisation administrators and auditors can see any mailbox’s activity. A domain administrator sees it for the people in their domains. Helpdesks cannot see it, and a delegate cannot see the activity of a mailbox they work in. Looking at somebody else’s mailbox activity is itself in the audit log.
Legal holds are shown only to those who may see holds: not to the person on hold, and not to a domain administrator.
Settings
On the console, Settings has a Mailbox activity card. From the command line:
vsx admin org mailbox-audit --days 365
vsx admin org mailbox-audit --record-own ceo@example.com,cfo@example.com
vsx admin org mailbox-audit --record-own none
| Setting | Default | What it does |
|---|---|---|
--days | 180 | How long activity is kept, from 30 to 3,650 days. A mailbox on legal hold keeps its activity until the hold is lifted. |
--record-own | Nobody | People whose own actions in their own mailbox are recorded too, for mailboxes that need a full record. |
Over the API
| Route | What it does |
|---|---|
GET /api/v1/tenants/{tenant}/accounts/{id}/activity | The mailbox’s activity, newest first, with by, from, to, after and limit to narrow and page it. |
Something unclear or out of date on this page? Tell us.