Difference between revisions of "Archiving Emails from Google Workspace"

[unchecked revision][checked revision]
 
(33 intermediate revisions by 4 users not shown)
Line 1: Line 1:
This tutorial only covers the specifics of archiving Google Mail mailboxes based on Google Apps. It is assumed that you already have a MailStore Server installation or [http://www.mailstore.com/en/lp/sendlicense.aspx test installation] and are familiar with the fundamentals of MailStore Server. Please refer to the [[MailStore_Help|Manual]] or the [[Quick Start Guide]] for more information.
+
{{Implementation Guide Preamble|Google Workspace}}
 
+
Since MailStore accesses user mailboxes via IMAP, IMAP access must be enabled for users in the Google Admin console.
MailStore Server offers several ways to archive emails from Google Apps, which are described below. If you are not sure which archiving method best suits your company, please refer to chapter [[Choosing the Right Archiving Strategy]].
 
 
 
 
== Synchronizing Users ==
 
== Synchronizing Users ==
It is required to first set up a synchronization with Google Apps as described in chapter [[Google Apps Integration]] of the MailStore Server manual as the API credentials needed to configure archiving must first be created in the [[Google Apps Integration]] configuration process.
+
It is required to first set up a synchronization with Google Workspace as described in chapter [[Google Workspace Integration]] of the MailStore Server manual as the API credentials needed to configure archiving must first be created in the [[Google Workspace Integration]] configuration process.
  
Note that while Google Apps uses it's own internal user database, this itself can be synchronized with external LDAP or Active Directory environments. Even if the Google Apps directory is not the primary source of user account information, it is highly recommended to synchronize MailStore Server directly with Google Apps to fetch all relevant information such as email addresses.
+
Note that while Google Workspace uses it's own internal user database, this itself can be synchronized with external LDAP or Active Directory environments. Even if the Google Workspace directory is not the primary source of user account information, it is highly recommended to synchronize MailStore Server directly with Google Workspace to fetch all relevant information such as email addresses.
  
 
== Archiving Individual Mailboxes ==
 
== Archiving Individual Mailboxes ==
<p class="msnote">The following steps describe the setup of a single mailbox archiving profile by an administrator using a special service account. Alternatively a single Google Apps mailbox can also be archived using the GMail archiving profile in MailStore that make use of the username and password of the mailbox owner. Please be aware that this will lead to a different result in displaying labels/folders in the archive and that Google considers accessing mailboxes via username and password as "insecure mailbox access".</p>
+
The following steps describe the setup of a single mailbox archiving profile by a MailStore administrator using a special service account.  
 +
 
 +
Alternatively, non-admin users which have the ''Archive E-mail'' privilege, may archive their own Google Workspace mailbox by using the [[Archiving_Emails_from_Gmail|Gmail archiving profile]] in MailStore Server, where the mailbox owner explicitly authorizes MailStore Server to access his mailbox.
  
{{Archiving Single Mailbox Preamble|Google Apps}}
+
{{Archiving Single Mailbox Preamble|Google Workspace}}
  
 
Please proceed as follows for each individual mailbox:
 
Please proceed as follows for each individual mailbox:
  
* Make sure that you configured the service account as descibes in the  [[Google Apps Integration]] chapter of the MailStore Server manual.
+
* Make sure that you configured the service account as descibes in the  [[Google Workspace Integration]] chapter of the MailStore Server manual.
* Log on to MailStore Client as MailStore administrator. Only an administrator can archive emails via a Google Apps Service Account.
+
* Log on to MailStore Client as MailStore Server administrator. Only an administrator can archive emails via a Google Workspace Service Account.
 
* Click on ''Archive Email''.
 
* Click on ''Archive Email''.
* From the ''Email Servers'' list in the ''Create Profile'' area of the window, select ''Google Apps'' to create a new archiving profile.
+
* From the ''Email Servers'' list in the ''Create Profile'' area of the window, select ''Google Workspace'' to create a new archiving profile.
 
* A wizard opens to assist in specifying the archiving settings.
 
* A wizard opens to assist in specifying the archiving settings.
 
*: [[File:Gapps_mailbox_00.png|center|350px]]
 
*: [[File:Gapps_mailbox_00.png|center|350px]]
 
* Select ''Single Mailbox'' and click on ''OK''.
 
* Select ''Single Mailbox'' and click on ''OK''.
* The ''Service Account'' and ''Certificate'' from the [[Google Apps Integration]] configuration are also used for archiving.
+
* Configure the basic archiving settings. The JSON file generated by Google for the service account during the [[Google Workspace Integration]] configuration is also required for mailbox access.
 
*: [[File:Gapps_mailbox_01.png|center|350px]]
 
*: [[File:Gapps_mailbox_01.png|center|350px]]
 
*: Fill out the following fields:
 
*: Fill out the following fields:
 
** '''Email Address'''<br/>The email address of the user to be archived.
 
** '''Email Address'''<br/>The email address of the user to be archived.
** '''Service Account'''<br/>The service account's ''email address'' provided by the Google Apps Project (e.g. ''1047453716425-4l533u425bp2m3lfp0c23ntf8mghlbmb@developer.gserviceaccount.com'').
+
** '''Key ID'''<br/>To import the private key, select the JSON file that has been generated by Google for the service account.
** '''Certificate'''<br/>P12 file which was provided by Google.
+
** '''Service Account'''<br/>The service account is determined automatically from the JSON file.
** '''Received''' and '''Sent'''<br/>The target folder in which MailStore will store received and send email.
+
** '''Received''' and '''Sent'''<br/>The target folder in which MailStore Server will store received and send email.
** '''Archive Spam'''<br/>Google Apps spam folders are excluded by default, but can be archived by selecting this option.
+
** '''Archive Spam'''<br/>Google Workspace spam folders are excluded by default, but can be archived by selecting this option.
*: '''Important notice:''' MailStore will archive all mail contained within the selected mailbox, excluding Spam and Deleted messages. Due to the nature of how Google represents user defined labels in IMAP, they are not supported by MailStore, as a consequence, the entire mailbox will be archived.
+
*: <div class="msnote">'''Important notice:''' MailStore Server will archive all mail contained within the selected mailbox, excluding Spam and Deleted messages. Due to the nature of how Google represents user defined labels in IMAP, they are not supported by MailStore Server; as a consequence, the entire mailbox will be archived.</div>
 
* Click on ''Next''.
 
* Click on ''Next''.
* If needed, adjust the settings for the [[Email_Archiving_with_MailStore_Basics#Archiving_Specific_Folders|list of folders to be archived]], the filter and the [[Email_Archiving_with_MailStore_Basics#Archiving_Specific_Folders|deletion rules]]. By default, no emails will be deleted from the mailbox. The ''Timeout'' value only has to be adjusted in specific cases (e.g. with very slow servers). Please keep in mind that these settings apply to all mailboxes to be archived.
+
* If needed, adjust the [[Email_Archiving_with_MailStore_Basics#Specifying_Filter_Criteria_for_Archiving|filter]] and the [[Email_Archiving_with_MailStore_Basics#Deleting_Emails_after_Archiving|deletion rules]]. By default, no emails will be deleted from the mailbox. The ''Timeout'' value only has to be adjusted in specific cases. Please keep in mind that these settings apply to all mailboxes to be archived.
 
*: [[File:Gapps_mailbox_02.png|center|350px]]
 
*: [[File:Gapps_mailbox_02.png|center|350px]]
 
* Click on ''Next''.
 
* Click on ''Next''.
Line 38: Line 38:
 
*:[[File:Gapps_mailbox_03.png|center|350px]]
 
*:[[File:Gapps_mailbox_03.png|center|350px]]
 
* Click on ''Next''.
 
* Click on ''Next''.
* In the last step, a name for the archiving profile can be specified. After clicking ''Finish'', the archiving profile will be listed under ''Saved Profiles'' and can be run immediately, if desired.
+
* In the last step, a name for the archiving profile can be specified. After clicking ''Finish'', the archiving profile will be listed under ''Saved Profiles'' and can be run immediately or automatically, if desired.
  
More information on how to execute archiving profiles can be found under the topic [[Email Archiving with MailStore Basics]]
+
More information on how to execute archiving profiles can be found under the topic [[Email Archiving with MailStore Basics]].
  
 
== Archiving Multiple Mailboxes Centrally ==
 
== Archiving Multiple Mailboxes Centrally ==
By following the procedure described here, multiple Google Apps mailboxes can be archived without specific configuration for each MailStore user. The archiving process can be executed manually or automatically according to a schedule.
+
By following the procedure described here, multiple Google Workspace mailboxes can be archived without specific configuration for each MailStore Server user. The archiving process can be executed manually or automatically.
  
* Make sure that you configured the service account as described in the  [[Google Apps Integration]] chapter of the MailStore Server manual.
+
* Make sure that you configured the service account as described in the  [[Google Workspace Integration]] chapter of the MailStore Server manual.
* Log on to MailStore Client as MailStore administrator. Only an administrator can archive emails via a Google Apps Service Account.
+
* Log on to MailStore Client as MailStore Server administrator. Only an administrator can archive emails via a Google Workspace Service Account.
 
* Click on ''Archive Email''.
 
* Click on ''Archive Email''.
* From the ''Email Servers'' list in the ''Create Profile'' area of the window, select ''Google Apps'' to create a new archiving profile.
+
* From the ''Email Servers'' list in the ''Create Profile'' area of the window, select ''Google Workspace'' to create a new archiving profile.
 
* A wizard opens to assist in specifying the archiving settings.
 
* A wizard opens to assist in specifying the archiving settings.
 
*: [[File:Gapps_mailboxes_00.png|center|350px]]
 
*: [[File:Gapps_mailboxes_00.png|center|350px]]
* Select ''Multiple Mailboxes''and click on ''OK''.
+
* Select ''Multiple Mailboxes'' and click on ''OK''.
* Specify some basic settings. The service account and certificate from the [[Google Apps Integration]] configuration are also used for accessing mailboxes.
+
*: {{Archiving_Multiple_or_Multidrop_Note|multiple mailboxes|[[#Synchronizing_Users|directory synchronization]]}}
 +
* Configure the basic archiving settings. The JSON file generated by Google for the service account during the [[Google Workspace Integration]] configuration is also required for mailbox access.
 
*: [[File:Gapps_mailboxes_01.png|center|350px]]
 
*: [[File:Gapps_mailboxes_01.png|center|350px]]
 
*:  Fill out the following fields:
 
*:  Fill out the following fields:
** '''Service Account'''<br/>The service account's ''email address'' provided by the Google Apps Project (e.g. ''1047453716425-4l533u425bp2m3lfp0c23ntf8mghlbmb@developer.gserviceaccount.com'').
+
** '''Key ID'''<br/>To import the private key, select the JSON file that has been generated by Google for the service account.
** '''Certificate'''<br/>P12 file which was provided by Google.
+
** '''Service Account'''<br/>The service account is determined automatically from the JSON file.
** '''Received''' and '''Sent'''<br/>The target folder in which MailStore will store received and send email.
+
** '''Received''' and '''Sent'''<br/>The target folder in which MailStore Server will store received and send email.
** '''Archive Spam'''<br/>Google Apps spam folders are excluded by default, but can be archived by selecting this option.
+
** '''Archive Spam'''<br/>Google Workspace spam folders are excluded by default, but can be archived by selecting this option.
*: '''Important notice:''' MailStore will archive all mail contained within the selected mailbox, excluding Spam and Deleted messages. Due to the nature of how Google represents user defined labels in IMAP, they are not supported by MailStore, as a consequence, the entire mailbox will be archived.
+
*: <div class="msnote">'''Important notice:''' MailStore Server will archive all mail contained within the selected mailbox, excluding Spam and Deleted messages. Due to the nature of how Google represents user defined labels in IMAP, they are not supported by MailStore Server, as a consequence, the entire mailbox will be archived.</div>
 
* Click on ''Next''.
 
* Click on ''Next''.
* If needed, adjust the settings for the [[Email_Archiving_with_MailStore_Basics#Archiving_Specific_Folders|list of folders to be archived]], the filter and the [[Email_Archiving_with_MailStore_Basics#Archiving_Specific_Folders|deletion rules]]. By default, no emails will be deleted from the mailbox. The ''Timeout'' value only has to be adjusted in specific cases (e.g. with very slow servers). Please keep in mind that these settings apply to all mailboxes to be archived.
+
* If needed, adjust the [[Email_Archiving_with_MailStore_Basics#Specifying_Filter_Criteria_for_Archiving|filter]] and the [[Email_Archiving_with_MailStore_Basics#Deleting_Emails_after_Archiving|deletion rules]]. By default, no emails will be deleted from the mailbox. The ''Timeout'' value only has to be adjusted in specific cases. Please keep in mind that these settings apply to all mailboxes to be archived.
 
*: [[File:Gapps_mailboxes_02.png|center|350px]]
 
*: [[File:Gapps_mailboxes_02.png|center|350px]]
 
* Click on ''Next''.
 
* Click on ''Next''.
*: [[File:Gapps_mailboxes_03.png|center|350px]]
+
{{Archiving_Multiple_Mailboxes_Centrally_Options|Gapps_mailboxes_03.png|Google Workspace}}
* Select the users whose mailboxes are to be archived. The following options are available:
 
** '''All users with configured email address'''<br/>Choose this option to archive the mailboxes of all users who are set up, along with their email addresses, in MailStore's user management.
 
** '''All users except the following'''<br/>Choose this option to exclude individual users (and thereby their Exchange mailboxes) from the archiving process, using the list of users below.
 
** '''Only the following users'''<br/>Choose this option to include individual users (and thereby their Google Apps mailboxes) in the archiving process, using the list of users below. Only the mailboxes of those users explicitly specified will be archived.
 
** '''Synchronize with Directory Services before archiving'''<br/>If selected, the MailStore user list will be synchronized with Google Apps before any archiving process is executed. This has the advantage that, for example, new employees will be created as MailStore users before archiving, so once the archiving process is executed, their Google Apps mailbox is archived automatically as well. This option is especially recommended when the archiving process is to be executed regularly according to a schedule. 
 
* Click on ''Next''.
 
* In the last step, a ''name for the archiving profile'' can be specified. After clicking ''Finish'', the archiving profile will be listed under ''Saved Profiles'' and can be run immediately, if desired.
 
 
 
More information on how to execute archiving profiles can be found under the topic [[Email Archiving with MailStore Basics]]
 
  
 
== Archiving Incoming and Outgoing Emails Directly ==
 
== Archiving Incoming and Outgoing Emails Directly ==
MailStore can archive all incoming and outgoing emails of all users within a Google Apps email domain. Using this scenario it is possible to ensure a complete and compliant archive.
+
MailStore Server can archive all incoming and outgoing emails of all users within a Google Workspace email domain. Using this scenario it is possible to ensure a complete and compliant archive.
  
 
=== Basic Functionality ===
 
=== Basic Functionality ===
In Google Apps, Google Mail can be configured to forward a copy of all incoming, outgoing or internal email traffic to an external mailbox.
+
In Google Workspace, Google Mail can be configured to forward a copy of all incoming, outgoing or internal email traffic to an external mailbox.
 +
 
 +
There are two method for archiving these emails:
 +
 
 +
# '''Using MailStore Gateway (recommended)'''<br/>Use the free [https://help.mailstore.com/en/gateway/ MailStore Gateway] program that provides mailboxes that are suitable as target for the corresponding Google Workspace rules. Unlike using another 3rd party mailbox provider, this method ensures that emails remain unmodified and the important ''X-Gm-Original-To'' header is retained. MailStore Server is then configured to archive from the MailStore Gateway mailboxes at regular intervals.
 +
# '''Using Another Mailbox Provider'''<br/>Use another provider's mailbox as target and configure MailStore Server to archive this so-called multidrop mailbox at regular intervals. The multidrop mailbox needs to be an external IMAP mailbox, that must not belong to the Google Workspace email domain because the Gmail duplicate detection would drop identical emails that have been addressed to several recipients. By using an internal Gmail mailbox completeness of the archive cannot be achieved. Futhermore, the receiving mailserver must not temper the email headers, especially not remove the ''X-Gm-Original-To'' header, and anti-virus and spam checking should also be disabled.
  
MailStore Server can be configured to archive this so called multidrop mailbox at regular intervals. During this process, the emails from the multidrop mailbox will be assigned to their respective MailStore users (i.e. their user archives) automatically. This means that each user is able to view only their own emails.
 
  
Before the archiving process can be set up in MailStore Server, email forwarding has to be set up for the Google Apps email domain.
+
Whichever option has been chosen, the emails from the multidrop mailbox will be assigned to their respective MailStore users (i.e. their user archives) automatically. This means that each user is able to view only their own emails.
  
=== Step 1: Configuring email forwarding for a Google Apps email domain ===
+
=== Method 1: Using MailStore Gateway ===
 +
==== Step 1: Setup and Configure MailStore Gateway ====
 +
Please refer to the [https://help.mailstore.com/en/gateway/ MailStore Gateway Manual] for detailed instructions about:
 +
 +
* Installation and Setup of MailStore Gateway
 +
* Logging on to MailStore Gateway's Management Console
 +
* Creating MailStore Gateway mailboxes
  
 +
After these steps, a mailbox with an individual email address (i.e. [email protected]) should exist.
 +
 +
==== Step 2: Configuring email forwarding for a Google Workspace email domain ====
 
Please proceed as follows:
 
Please proceed as follows:
  
* Log on to your Google Apps domain as an administrator.
+
* Log on to your Google Workspace domain as an administrator.
* On the ''Settings'' tab, select ''Gmail'' in the ''Services'' section.
+
* Navigate to ''Apps'' > ''Google Workspace'' > ''Gmail ''.
* Configure ''Receiving routing'':
+
* Click on ''Advanced settings'' on the ''Settings for Gmail'' page.
*# Under ''Also deliver to'', activate the ''Add more recipients'' option.
+
* In the ''General Settings'' tab, scroll down to ''Routing''.
*#: [[File:GM_routing_01_en.png|center|347px]]
+
*: [[File:GM_routing_00_en.png|center|500px]]
*# Select ''Advanced'' and activate the ''Change envelope recipient'' option.
+
* Click ''Configure'' or ''Add Another'' to create a new routing rule. A new window appears.
*# Enter the email address of the multidrop mailbox into the ''Replace recipient'' field.
+
* Enter a name and enable all checkboxes in the ''Messages to affect'' section.
*# Activate the ''Add X-Gm-Original-To header'' option.
+
*: [[File:GM_routing_01_en.png|center|500px]]
*#: [[File:GM_routing_02_en.png|center|347px]]
+
* Under ''Also deliver to'', activate the ''Add more recipients'' option and ''Add'' an additional delivery recipient.
*# Click on ''Save'' further down the window and then on ''Add setting''.
+
* Select ''Advanced'' from the drop-down list.
* Repeat steps 1 to 5 for ''Sending routing''.
+
* Activate the ''Change envelope recipient'' option.
* Click on ''Save changes''.
+
* Enter the email address of the MailStore Gateway mailbox into the ''Replace recipient'' field.
<p class="msnote">'''Important:''' The multidrop mailbox needs to be an external IMAP mailbox, that must not belong to the Google Apps email domain because the Gmail duplicate detection would drop identical emails that have been addressed to several recipients. By using an internal Gmail mailbox completeness of the archive cannot be achieved.</p>
+
* Activate the ''Do not deliver spam to this recipient'' option if desired.
 +
* Activate the ''Suppress bounces from this recipient'' option.
 +
* Activate the ''Add X-Gm-Original-To header'' option.
 +
*: [[File:GM_routing_02a_en.png|center|500px]]
 +
* Click on ''Save'' further down the window and then on ''Add setting'' for a new rule or ''Save'' when modifying an existing rule.
 +
* Click on ''Save'' in the footer bar.
 +
 
 +
==== Step 3: Setting up the Archiving Process ====
 +
{{Archiving MailStore Gateway Mailbox|''Google Google Workspace''|Arch_MailStore_Gateway_G_Suite_01.png|Arch_MailStore_Gateway_G_Suite_02.png|POP3Hint=DontShow|DSLink=[[#Synchronizing_Users|directory synchronization]]}}
 +
 
 +
=== Method 2: Using Another Mailbox Provider ===
 +
 
 +
==== Step 1: Configuring email forwarding for a Google Workspace email domain ====
 +
Please proceed as follows:
  
=== Step 2: Setting up the Archiving Process ===
+
* Log on to your Google Workspace domain as an administrator.
 +
* Navigate to ''Apps > Google Workspace > Gmail > Settings for Gmail > Advanced settings''.
 +
* In the ''General Settings'' tab, scroll down to ''Routing''.
 +
*: [[File:GM_routing_00_en.png|center|500px]]
 +
* Click ''Configure'' or ''Add Another'' to create a new routing rule. A new window appears.
 +
* Enter a name and enable all checkboxes in the ''Messages to affect'' section.
 +
*: [[File:GM_routing_01_en.png|center|500px]]
 +
* Under ''Also deliver to'', activate the ''Add more recipients'' option and ''Add'' an additional delivery recipient.
 +
* Select ''Advanced'' from the drop-down list.
 +
* Activate the ''Change envelope recipient'' option.
 +
* Enter the email address of the multidrop mailbox into the ''Replace recipient'' field.
 +
* Activate the ''Suppress bounces from this recipient'' option.
 +
* Activate the ''Add X-Gm-Original-To header'' option.
 +
*: [[File:GM_routing_02_en.png|center|500px]]
 +
* Click on ''Save'' further down the window and then on ''Add setting'' for a new rule or ''Save'' when modifying an existing rule.
 +
* Click on ''Save'' in the footer bar.
  
The above settings will ensure that a copy of all emails will be forwarded to a single external multidrop mailbox. MailStore extracts the sender and recipient information from the email headers to assign them to the appropriate users. By using this type of mailboxes it is possible to archive all incoming and outgoing emails.
+
==== Step 2: Setting up the Archiving Process ====
 +
The above settings will ensure that a copy of all emails will be forwarded to a single external multidrop mailbox. MailStore Server extracts the sender and recipient information from the email headers to assign them to the appropriate users. By using this type of mailboxes it is possible to archive all incoming and outgoing emails.
  
{{Archiving Multidrop_Mailbox|Google Apps|Gapps_catchall_00.png|Gapps_catchall_01.png|Gapps_catchall_02.png}}
+
{{Archiving Multidrop_Mailbox|Google Workspace|Gapps_catchall_00.png|Gapps_catchall_01.png|[[#Synchronizing_Users|directory synchronization]]}}
  
 
== Weblinks ==
 
== Weblinks ==
* [http://www.mailstore.com/en/support.aspx MailStore Support]
+
* [https://workspace.google.com/intl/en/ Google Workspace]
* [http://www.google.com/apps Google Apps]
 
  
[[de:E-Mail-Archivierung von Google Apps]]
+
[[de:E-Mail-Archivierung von Google Workspace]]
[[en:Archiving Emails from Google Apps]]
+
[[en:Archiving Emails from Google Workspace]]

Latest revision as of 12:12, 22 July 2024

This implementation guide covers the specifics of archiving Google Workspace mailboxes. It is assumed that you already have a MailStore Server installation or test installation and are familiar with the fundamentals of MailStore Server. Please refer to the Manual or the Quick Start Guide for more information.

MailStore Server offers several ways to archive emails from Google Workspace mailboxes, which are described below. If you are not sure which archiving method best suits your company, please refer to the chapter Choosing the Right Archiving Strategy.

Since MailStore accesses user mailboxes via IMAP, IMAP access must be enabled for users in the Google Admin console.

Synchronizing Users

It is required to first set up a synchronization with Google Workspace as described in chapter Google Workspace Integration of the MailStore Server manual as the API credentials needed to configure archiving must first be created in the Google Workspace Integration configuration process.

Note that while Google Workspace uses it's own internal user database, this itself can be synchronized with external LDAP or Active Directory environments. Even if the Google Workspace directory is not the primary source of user account information, it is highly recommended to synchronize MailStore Server directly with Google Workspace to fetch all relevant information such as email addresses.

Archiving Individual Mailboxes

The following steps describe the setup of a single mailbox archiving profile by a MailStore administrator using a special service account.

Alternatively, non-admin users which have the Archive E-mail privilege, may archive their own Google Workspace mailbox by using the Gmail archiving profile in MailStore Server, where the mailbox owner explicitly authorizes MailStore Server to access his mailbox.

In MailStore Server Google Workspace archiving tasks are stored in archiving profiles. By following the procedure described here you can archive a single Google Workspace mailbox for a specific MailStore user. The archiving process can be executed manually or automatically. You can find further information about executing archiving profiles in chapter Email Archiving with MailStore Basics.


Please proceed as follows for each individual mailbox:

  • Make sure that you configured the service account as descibes in the Google Workspace Integration chapter of the MailStore Server manual.
  • Log on to MailStore Client as MailStore Server administrator. Only an administrator can archive emails via a Google Workspace Service Account.
  • Click on Archive Email.
  • From the Email Servers list in the Create Profile area of the window, select Google Workspace to create a new archiving profile.
  • A wizard opens to assist in specifying the archiving settings.
    Gapps mailbox 00.png
  • Select Single Mailbox and click on OK.
  • Configure the basic archiving settings. The JSON file generated by Google for the service account during the Google Workspace Integration configuration is also required for mailbox access.
    Gapps mailbox 01.png
    Fill out the following fields:
    • Email Address
      The email address of the user to be archived.
    • Key ID
      To import the private key, select the JSON file that has been generated by Google for the service account.
    • Service Account
      The service account is determined automatically from the JSON file.
    • Received and Sent
      The target folder in which MailStore Server will store received and send email.
    • Archive Spam
      Google Workspace spam folders are excluded by default, but can be archived by selecting this option.
    Important notice: MailStore Server will archive all mail contained within the selected mailbox, excluding Spam and Deleted messages. Due to the nature of how Google represents user defined labels in IMAP, they are not supported by MailStore Server; as a consequence, the entire mailbox will be archived.
  • Click on Next.
  • If needed, adjust the filter and the deletion rules. By default, no emails will be deleted from the mailbox. The Timeout value only has to be adjusted in specific cases. Please keep in mind that these settings apply to all mailboxes to be archived.
    Gapps mailbox 02.png
  • Click on Next.
  • The Target Archive must be specified. Select the archive of the user for whom the selected mailbox is to be archived. If the user does not exist yet, click on Create a New User.
    Gapps mailbox 03.png
  • Click on Next.
  • In the last step, a name for the archiving profile can be specified. After clicking Finish, the archiving profile will be listed under Saved Profiles and can be run immediately or automatically, if desired.

More information on how to execute archiving profiles can be found under the topic Email Archiving with MailStore Basics.

Archiving Multiple Mailboxes Centrally

By following the procedure described here, multiple Google Workspace mailboxes can be archived without specific configuration for each MailStore Server user. The archiving process can be executed manually or automatically.

  • Make sure that you configured the service account as described in the Google Workspace Integration chapter of the MailStore Server manual.
  • Log on to MailStore Client as MailStore Server administrator. Only an administrator can archive emails via a Google Workspace Service Account.
  • Click on Archive Email.
  • From the Email Servers list in the Create Profile area of the window, select Google Workspace to create a new archiving profile.
  • A wizard opens to assist in specifying the archiving settings.
    Gapps mailboxes 00.png
  • Select Multiple Mailboxes and click on OK.
    Please note: To be able to archive multiple mailboxes, MailStore Server users along with their email addresses must exist in the MailStore Server user management. If this is not the case, MailStore Server will offer to set up and run the directory synchronization at this point. Once completed, the wizard will resume.
    Alternatively, you can cancel the wizard and create users manually as described the in chapter User Management.
  • Configure the basic archiving settings. The JSON file generated by Google for the service account during the Google Workspace Integration configuration is also required for mailbox access.
    Gapps mailboxes 01.png
    Fill out the following fields:
    • Key ID
      To import the private key, select the JSON file that has been generated by Google for the service account.
    • Service Account
      The service account is determined automatically from the JSON file.
    • Received and Sent
      The target folder in which MailStore Server will store received and send email.
    • Archive Spam
      Google Workspace spam folders are excluded by default, but can be archived by selecting this option.
    Important notice: MailStore Server will archive all mail contained within the selected mailbox, excluding Spam and Deleted messages. Due to the nature of how Google represents user defined labels in IMAP, they are not supported by MailStore Server, as a consequence, the entire mailbox will be archived.
  • Click on Next.
  • If needed, adjust the filter and the deletion rules. By default, no emails will be deleted from the mailbox. The Timeout value only has to be adjusted in specific cases. Please keep in mind that these settings apply to all mailboxes to be archived.
    Gapps mailboxes 02.png
  • Click on Next.
  • Select the users whose mailboxes are to be archived.
    Gapps mailboxes 03.png
    The following options are available:
    • All users with configured email address
      Choose this option to archive the mailboxes of all users who are set up, along with their email addresses, in MailStore's user management.
    • All users except the following
      Choose this option to exclude individual users (and thereby their Google Workspace mailboxes) from the archiving process, using the list of users below.
    • Only the following users
      Choose this option to include individual users (and thereby their Google Workspace mailboxes) in the archiving process, using the list of users below. Only the mailboxes of those users explicitly specified will be archived.
    • Synchronize with Directory Services before archiving
      If selected, the MailStore user list will be synchronized with the configured directory service before any archiving process is executed. This has the advantage that, for example, new employees will be created as MailStore users before archiving, so once the archiving process is executed, their Google Workspace mailbox is archived automatically as well. This option is especially recommended when the archiving process is to be executed automatically.
  • Click on Next.
  • In the last step, a name for the archiving profile can be specified. After clicking Finish, the archiving profile will be listed under Saved Profiles and can be run immediately or automatically, if desired.


Archiving Incoming and Outgoing Emails Directly

MailStore Server can archive all incoming and outgoing emails of all users within a Google Workspace email domain. Using this scenario it is possible to ensure a complete and compliant archive.

Basic Functionality

In Google Workspace, Google Mail can be configured to forward a copy of all incoming, outgoing or internal email traffic to an external mailbox.

There are two method for archiving these emails:

  1. Using MailStore Gateway (recommended)
    Use the free MailStore Gateway program that provides mailboxes that are suitable as target for the corresponding Google Workspace rules. Unlike using another 3rd party mailbox provider, this method ensures that emails remain unmodified and the important X-Gm-Original-To header is retained. MailStore Server is then configured to archive from the MailStore Gateway mailboxes at regular intervals.
  2. Using Another Mailbox Provider
    Use another provider's mailbox as target and configure MailStore Server to archive this so-called multidrop mailbox at regular intervals. The multidrop mailbox needs to be an external IMAP mailbox, that must not belong to the Google Workspace email domain because the Gmail duplicate detection would drop identical emails that have been addressed to several recipients. By using an internal Gmail mailbox completeness of the archive cannot be achieved. Futhermore, the receiving mailserver must not temper the email headers, especially not remove the X-Gm-Original-To header, and anti-virus and spam checking should also be disabled.


Whichever option has been chosen, the emails from the multidrop mailbox will be assigned to their respective MailStore users (i.e. their user archives) automatically. This means that each user is able to view only their own emails.

Method 1: Using MailStore Gateway

Step 1: Setup and Configure MailStore Gateway

Please refer to the MailStore Gateway Manual for detailed instructions about:

  • Installation and Setup of MailStore Gateway
  • Logging on to MailStore Gateway's Management Console
  • Creating MailStore Gateway mailboxes

After these steps, a mailbox with an individual email address (i.e. [email protected]) should exist.

Step 2: Configuring email forwarding for a Google Workspace email domain

Please proceed as follows:

  • Log on to your Google Workspace domain as an administrator.
  • Navigate to Apps > Google Workspace > Gmail .
  • Click on Advanced settings on the Settings for Gmail page.
  • In the General Settings tab, scroll down to Routing.
    GM routing 00 en.png
  • Click Configure or Add Another to create a new routing rule. A new window appears.
  • Enter a name and enable all checkboxes in the Messages to affect section.
    GM routing 01 en.png
  • Under Also deliver to, activate the Add more recipients option and Add an additional delivery recipient.
  • Select Advanced from the drop-down list.
  • Activate the Change envelope recipient option.
  • Enter the email address of the MailStore Gateway mailbox into the Replace recipient field.
  • Activate the Do not deliver spam to this recipient option if desired.
  • Activate the Suppress bounces from this recipient option.
  • Activate the Add X-Gm-Original-To header option.
    GM routing 02a en.png
  • Click on Save further down the window and then on Add setting for a new rule or Save when modifying an existing rule.
  • Click on Save in the footer bar.

Step 3: Setting up the Archiving Process

Setting up archiving processes for MailStore Gateway mailboxes is done using archiving profiles. General information about archiving profiles is available in chapter Working with Archiving Profiles.

Before configuring MailStore Server, please make sure that a MailStore Server user account exists for each user whose emails are to be archived with the MailStore Gateway. Please refer to chapter User Management for more information.

Important notice: It is imperative that, in user management under Properties, the email address is specified for each user. This is the only way to make sure that the emails in the archive are assigned to the appropriate users.

Please proceed as follows:

  • Log on as MailStore Server administrator using MailStore Client.
  • In MailStore Server, click on Archive Email.
  • To create a new archiving profile, select MailStore Gateway Mailbox from the Email Server list in the Create Profile area of the application window.
  • A wizard opens that guides you through the setup process.

    Arch MailStore Gateway G Suite 01.png
  • Select Google Google Workspace and click OK.

    Please note: To be able to archive a MailStore Gateway mailbox, MailStore Server users along with their email addresses must exist in the MailStore Server user management. If this is not the case, MailStore Server will offer to set up and run the directory synchronization at this point. Once completed, the wizard will resume.
    Alternatively, you can cancel the wizard and create users manually as described the in chapter User Management.

  • Fill out the fields Host, Mailbox ID and Password. Click on Test to verify the data entered.

    If MailStore Gateway uses a TLS certificate from a certificate authority that is not trusted by the MailStore Server computer, the option Accept all certificates must be checked.

    Arch MailStore Gateway G Suite 02.png
  • Adjust any further settings such as how to handle emails with unknown addresses or asking MailStore Server to delete emails after they have been archived.

    Please note: If you are additionally archiving messages from the users mailboxes, you have to set the target folder names here to the folder names that match the names that were created by the user mailbox archiving profiles. Otherwise, additional or similar folders could be created in the users' archives. The folder names are case-sensitive.

  • If the option Synchronize with Directory Services before archiving is enabled, the MailStore Server user list will be synchronized with the configured directory service before the archiving process actually runs. This has the advantage that, for example, new employees will be created as MailStore Server users before archiving which enables MailStore Server to sort their emails into the correct archives.
  • Click on Next.
  • The timeout value only has to be adjusted on a case-by-case basis (e.g. with very slow servers or network connections).
  • Click on Next.
  • At the last step, select a name for the new archiving profile. After clicking on Finish, the archiving profile will be listed under Saved Profiles and can be run immediately or automatically, if desired.


Method 2: Using Another Mailbox Provider

Step 1: Configuring email forwarding for a Google Workspace email domain

Please proceed as follows:

  • Log on to your Google Workspace domain as an administrator.
  • Navigate to Apps > Google Workspace > Gmail > Settings for Gmail > Advanced settings.
  • In the General Settings tab, scroll down to Routing.
    GM routing 00 en.png
  • Click Configure or Add Another to create a new routing rule. A new window appears.
  • Enter a name and enable all checkboxes in the Messages to affect section.
    GM routing 01 en.png
  • Under Also deliver to, activate the Add more recipients option and Add an additional delivery recipient.
  • Select Advanced from the drop-down list.
  • Activate the Change envelope recipient option.
  • Enter the email address of the multidrop mailbox into the Replace recipient field.
  • Activate the Suppress bounces from this recipient option.
  • Activate the Add X-Gm-Original-To header option.
    GM routing 02 en.png
  • Click on Save further down the window and then on Add setting for a new rule or Save when modifying an existing rule.
  • Click on Save in the footer bar.

Step 2: Setting up the Archiving Process

The above settings will ensure that a copy of all emails will be forwarded to a single external multidrop mailbox. MailStore Server extracts the sender and recipient information from the email headers to assign them to the appropriate users. By using this type of mailboxes it is possible to archive all incoming and outgoing emails.

Setting up archiving processes for multidrop mailboxes is done using archiving profiles. General information about archiving profiles is available in chapter Working with Archiving Profiles.

Please proceed as follows:

  • Log on as MailStore administrator using MailStore Client.
  • In MailStore, click on Archive Email.
  • To create a new archiving profile, select Google Workspace from the Email Server list in the Create Profile area of the application window.
  • A wizard opens guiding you through the setup process.
    Gapps catchall 00.png
  • Select Multidrop Mailbox and click OK.
    Please note: To be able to archive a multidrop mailbox, MailStore Server users along with their email addresses must exist in the MailStore Server user management. If this is not the case, MailStore Server will offer to set up and run the directory synchronization at this point. Once completed, the wizard will resume.
    Alternatively, you can cancel the wizard and create users manually as described the in chapter User Management.
  • Fill out the fields Access via, Host, Username and Password. Click on Test to verify the data entered.

    For the TLS and SSL protocols only: If the certificate provided by the remote host cannot be verified (e.g. self-signed or signed by an unknown certificate authority), enable the option Accept all certificates to allow MailStore to establish a connection. As this option leads to an insecure configuration, warnings may appear in the summary and/or the dashboard.
    Gapps catchall 01.png
  • Adjust any further settings such as how to handle emails with unknown addresses or asking MailStore to delete emails after they have been archived. The latter option is especially sensible when dealing with mailboxes that are exclusively used for archiving.
  • The placeholders {u-email} or {h-email} can be used under Target Folders. {u-email} represents a user's primary email address and {h-email} is the email address found in the email header. Should a user have multiple aliases, using {h-email} will result in emails sent to different aliases of a user being archived in different folders, while using {u-email} will file all emails below the primary email address.

    Notice: If you are additionally archiving messages from the users mailboxes, you have to set the target folder names here to the folder names that match the names that were created by the user mailbox archiving profiles. Otherwise, additional or similar folders could be created in the users' archives. The folder names are case-sensitive.
  • If the option Synchronize with Directory Services before archiving is enabled, the MailStore user list will be synchronized with configured directory service before the archiving process actually runs. This has the advantage that, for example, new employees will be created as MailStore users before archiving which enables MailStore to sort their emails into the correct archives.
  • Click on Next.
  • The timeout value only has to be adjusted on a case-by-case basis (e.g. with very slow servers).
  • Click on Next.
  • At the last step, select a name for the new archiving profile. After clicking on Finish, the archiving profile will be listed under Saved Profiles and can be run immediately or automatically, if desired.


Weblinks