Someone goes on leave on Friday and their mailbox keeps receiving customer mail all week. The quick fix most small teams reach for is the password: handed over in a chat message, or dropped into a shared vault entry nobody remembers to rotate afterwards. It works, and it also means a second person is now signing in as them, with their two-step verification, in their account settings, with no record of who did what.
Email delegation is the built-in answer to that, on both Gmail and Outlook. The other person works the mailbox from inside their own account, with their own login. Nobody shares a credential. The setup takes a couple of minutes once you know where it lives, and the interesting part isn't the clicks: it's which permission you actually granted, because on the Microsoft side five different ones get called delegation and they don't do the same thing.

The short version
- Delegation gives someone access to one person's mailbox from inside their own account. No password changes hands, and the delegate keeps their own login and their own two-step verification.
- Gmail: the owner grants it under Settings, Accounts and Import, "Grant access to your account", after verifying their own identity. On a work or school account the feature can be switched off domain-wide, which is the usual reason the option isn't on someone's screen.
- Outlook: the owner grants it in classic Outlook under File, Info, Account Settings, Delegate Access. Microsoft is explicit that "Delegate access is only available if you're using a work or school account in Microsoft 365 or with Exchange Online", so a personal Outlook.com mailbox can't be delegated at all.
- Five different Microsoft permissions get called "delegation" and they're not interchangeable. Full Access, the one an admin grants, explicitly "doesn't allow the delegate to send messages from the mailbox".
- The Gmail caps are documented and not what the folklore says. Up to 10 delegates on a personal
@gmail.comand up to 1,000 on a work or school account, with 40 concurrent as a performance guideline. The widely repeated "25" appears in no Google documentation. - What delegation can't do: divide the work. It shares one pile with several people. Giving an individual message a named owner is a different job, and on Gmail there's a free route to part of it before anyone buys anything.
What email delegation actually is, and how a delegated mailbox differs from a shared one
Delegation is access to one person's mailbox, granted to another named person, and used from inside the delegate's own account. The delegate opens a second mailbox alongside their own, reads it, replies from it, and does all of that signed in as themselves.
That makes it a different mechanism from a team address. A shared mailbox or a group address is a mailbox that doesn't belong to any individual; delegation is somebody's personal mailbox that other people can reach into. The distinction decides what happens when that person leaves the company, and whether you're solving a cover problem or an ownership problem.
It also decides which page you need. If the address you're worried about belongs to the team rather than to a person, delegation is only one of four routes and probably not the right one: the four ways to run a Gmail team address covers that decision, including the Gmail delegation detail in more depth than this page does.
Delegate a Gmail account: the setup, and what the delegate gets
Start with the admin setting if this is a work or school account, because it's the reason the option is sometimes missing entirely. In the Admin console the path is Menu, Apps, Google Workspace, Gmail, User settings, then Mail delegation, where the checkbox reads "Let users delegate access to their mailbox to other users in the domain". A colleague staring at an Accounts tab with no "Grant access to your account" section is usually looking at a domain policy rather than a bug.
Then the owner's side, in Gmail itself:
- Verify your identity when prompted. Google's guide to delegating and collaborating on email puts this first: "Before you can add delegates, verify your identity. This confirms you requested the change in your Google Account." Plenty of walkthroughs skip it and leave you wondering why the option isn't there.
- Click the Settings icon, then See all settings.
- Open the Accounts and Import tab, labeled just Accounts on some account types.
- Under Grant access to your account, click Add another account.
- Enter the delegate's address, click Next Step, then Send email to grant access.
- The delegate accepts from the invitation mail, which "expires after a week".
Budget a day rather than a lunch break. Google says "It can take up to 24 hours before a delegate can use your account", and admin-side changes carry their own "up to 24 hours" caveat, so this isn't a thing to set up an hour before someone's flight.
On the delegate's side there's nothing to install. They click their profile picture in Gmail, pick the other address from the menu where it's labeled "Delegated", and it opens in its own tab as an ordinary inbox alongside their own.
Two constraints land before you start. You can't delegate an alias: Google's wording is that "You can't add delegates to an alternate email address or alias because it's not a Google Account", so if your info@ address is an alias on somebody's mailbox there's nothing to delegate. And you can't grant delegation from the Gmail app, so the whole handover has to happen on the web.
Using it, though, is no longer desk-bound. Google brought delegated accounts to the mobile Gmail apps with rollout completing in July 2026: delegates can switch between their own inbox and delegated ones, see unread counts for each, and "See emails intermingled across delegated accounts and their own account using the mobile 'All inboxes' view". If your cover plan involves someone answering from a phone at the weekend, that now works.
What the delegate loses is composing assistance. A long list of Gmail features switches off inside a delegated mailbox, Smart Compose, Smart Reply, Gemini in Gmail, Chat, Meet, Tasks, autocorrect and spell check among them, plus "Add attachments to Drive". Somebody used to drafting with help is about to write everything by hand.
Delegate access in Outlook: both sides of the setup
Before any clicks, the wall: Microsoft states in its guide to letting someone else manage your mail and calendar that "Delegate access is only available if you're using a work or school account in Microsoft 365 or with Exchange Online". Personal Outlook.com accounts don't have this feature at all. No permission level, no admin, no workaround.
The second thing to know is that you'll probably need classic Outlook for the mail part. Microsoft's own note: "Currently, assigning delegate permissions to mail folders in new Outlook is only partially available. You can still have delegates, but you must use classic Outlook to assign those permissions first." The same partial availability applies in Outlook on the web. Delegates work fine in the new clients; it's the granting that has to happen in the old one.
The owner's path in classic Outlook, from Microsoft's page on managing another person's mail and calendar items: File > Info > Account Settings > Delegate Access > Add, then pick the person and set a level per folder across Calendar, Tasks, Inbox, Contacts and Notes. Microsoft defines the levels as:
- Reviewer: "the delegate can read items in your folders".
- Author: "the delegate can read and create items, and change and delete items that they create".
- Editor: "the delegate can do everything that an Author has permission to do and additionally can change and delete the items that you created".
For mailbox cover, Editor on the Inbox is usually what you want. A colleague who can read and reply but can't file or delete anything will leave the mailbox in a state the owner has to untangle on their return.
Then the delegate's side, which is a separate job on their own machine: File > Account Settings > Account Settings, then on the Email tab select Change, then More Settings, then on the Advanced tab under Open these additional mailboxes select Add and enter the mailbox name. To send, they "Open a new email message. Above the To line, select From, then select the other person's mailbox". Recipients see that the message was "sent by you on behalf of the other person".
One detail here explains more confusion than anything else on this page. Setting every folder to None while adding a delegate isn't a no-op: Microsoft's page on allowing messages to be sent on your behalf says it "gives the delegate the basic ability to send messages on your behalf, but nothing more". The send right and the folder rights are separate dials on the same dialog, which is how someone ends up able to send as a colleague while seeing none of their mail.
The five permissions people all call "delegation"
These get used interchangeably almost everywhere, including by people who administer them for a living. They're granted by different people, in different places, and they allow different things. Microsoft's reference on managing permissions for recipients is the authority, and the exact wording is where the surprises are. The one-line version: delegate access is granted by the mailbox owner and carries the right to send, while Full Access is granted by an admin and doesn't.
| Grant | Who grants it | Where | What it allows | What the recipient sees |
|---|---|---|---|---|
| Delegate access | The mailbox owner | Classic Outlook: File > Info > Account Settings > Delegate Access | Per-folder read, create and edit rights, and it carries the right to send on the owner's behalf | "Delegate on behalf of Owner" in the From line |
| Folder permissions | The mailbox owner | Right-click the folder, Properties, Permissions | Access to that one folder only, no right to send | Nothing, because nothing is sent |
| Full Access | An admin | Exchange admin center: Mailbox delegation, "Read and manage (Full Access)" | "Open the mailbox, and view, add and remove the contents of the mailbox. Doesn't allow the delegate to send messages from the mailbox" | Nothing, because it can't send |
| Send as | An admin | Exchange admin center: Mailbox delegation, Send as | Sending only, no read access | The mailbox's own address. "There's no indication that the message was sent by the delegate" |
| Send on behalf | An admin, or the owner via delegate access | Exchange admin center: Mailbox delegation, Send on behalf | Sending only, no read access | "Delegate on behalf of MailboxOrGroup", and "replies to these messages are sent to the mailbox or group, not to the delegate" |
Three practical consequences fall out of that table.
Full Access is mute, not read-only. An admin can give someone complete access to a mailbox, including the ability to delete things out of it, and that person still can't answer a single email from it. If the goal was cover, Full Access alone isn't it.
Send as and Send on behalf answer a question the owner usually hasn't thought about: whether the customer should be able to tell. Send as is invisible, which is right for a team address and wrong for a person's mailbox, because a reply that looks like it came from someone on leave will get a confused answer. Send on behalf names who typed it and routes the reply back to the mailbox rather than to the stand-in. If someone holds both, Microsoft notes that "the Send as permission is always used", so the invisible one wins by default.
And the owner can't grant the admin-side send permissions themselves. Microsoft is direct: "Send as permissions can only be set by your organization's admin." If you want a colleague's replies to look like they came from the address itself, that's a ticket for IT. The admin-side grant path is the same one used for team addresses, and how Full Access and Send As actually get granted walks through it from the admin's seat.
Which route fits which situation
| Situation | On Gmail | On Microsoft 365 | Anything to buy |
|---|---|---|---|
| One person is away, a colleague covers their mailbox for a fortnight | Delegation, set up by the owner | Delegate access, Editor on the Inbox | No |
| A named person plus a permanent assistant | Delegation, with the sender-visibility setting chosen deliberately | Delegate access, which already carries send-on-behalf, so replies are attributable | No |
| Someone must send from the address but must not read the mail | Not via delegation, which is all or nothing on the mailbox. "Send mail as" does it, but the address owner has to click a confirmation link | Send as or Send on behalf, granted by an admin, without Full Access | No |
The address belongs to the team rather than a person (support@, info@) |
A team address, not delegation | A shared mailbox, not delegation | No |
| Several people working one queue who need to know who's handling what | Not delegation. A Collaborative Inbox gets you assignment and resolution states for free | Not delegation, and there's no free equivalent | Gmail: not at first. Microsoft: yes |
The first four rows are the honest part: for the situations delegation was built for, the feature is the right answer and there's nothing to buy. If you're reading a page that arrives at a purchase recommendation in row one, that's why.
The limits worth knowing before you set it up
The Gmail delegate caps are documented, and the number most widely repeated about them is not one of them: "25" appears in no Google documentation. The real figures, and what they mean in practice, are covered alongside the other Gmail sharing routes on the Gmail team address page. Two limits that page doesn't cover are worth having here, because both change plans:
Delegation adds people, not capacity. Google states that "Delegation does not increase the limits for a Gmail account. Gmail accounts with delegated users have the standard Gmail account limits and policies." Five people answering from one delegated mailbox share one mailbox's sending quota, which matters the first time a rota tries to clear a backlog.
A Google Group can be a delegate, with a prerequisite. Google's admin documentation on delegating a user's email address says "Google Groups can be added as account delegates. One Group counts as a single delegate for that account", which is the clean way to give a rotating team access without re-granting every time somebody joins. The catch is on the settings page: it needs the separate option "Allow users to grant their mailbox access to a Google group", and Google's instructions for enabling mail delegation add that "it must be enabled for the OU of the delegated account and for each group member's OU. Group members that belong to an OU without this option enabled can't access the delegated account." If one person in the group can't get in, that's the first thing to check.
Who did what: the trail exists, just not where your team can see it
It's widely written that delegation leaves no audit trail. That's wrong on both platforms, and the accurate version is more useful than the claim.
On Microsoft 365, mailbox auditing "is turned on by default in all organizations", and "Delegate" is one of three sign-in types it classifies actions under, defined as "A user assigned the SendAs, SendOnBehalf, or FullAccess permission to another mailbox" or "An admin assigned the FullAccess permission to a user's mailbox". For that sign-in type, SendAs, SendOnBehalf, MailItemsAccessed, Update, SoftDelete, HardDelete and UpdateInboxRules are all logged by default. On Google Workspace, Gmail log events carry a Delegate attribute, defined as the "Email address of the delegate user who performed the action on the owner's behalf", alongside a "Has delegate" flag.
So the record exists. Four things are true about it, and together they're what the "no audit trail" line is reaching for:
- It's admin territory. Reaching it means the Exchange admin center, PowerShell, or the Admin console under Menu, Reporting, Audit and investigation. The person actually working the mailbox never sees it.
- It's after the fact. Google's retention and lag times reference puts Gmail log events at "Near real time (couple of minutes)" with "6 months" retention, and Email Log Search at 30 days. On the Microsoft side, retention "is now configured and managed through Microsoft Purview", so what you can still look up depends on your own policy.
- It's coarser than it sounds for delegates. Microsoft notes that "Audit records for folder bind actions performed by delegates are consolidated. One audit record is generated for individual folder access within a 24-hour period". And
Sendis logged for owners and admins but not for the Delegate type, where SendAs and SendOnBehalf are the equivalents. - Parts of it are gated. Google's security investigation tool, the thing that makes those log events searchable, requires specific editions: Frontline Standard and Plus, Enterprise Standard and Plus, Education Standard and Plus, Enterprise Essentials Plus, or Cloud Identity Premium.
Put together: there's a forensic record you can retrieve when something has gone wrong, and there's nothing at all for the person at 09:04 wondering whether a colleague already replied to the angry customer. Those are different needs, and delegation only covers the first.
Where delegation runs out
Delegation shares a mailbox. It doesn't divide one. Every delegate sees the same undivided inbox, and the only native coordination signal is read state, which tells you somebody looked rather than that anybody is dealing with it.
The usual workaround is to improvise ownership out of what's already there: a label called @anna in Gmail, a category or a flag in Outlook. It's shared state, every delegate can see it, and it genuinely works for a while. It also has no enforcement, no notification, no history of who changed it, and no answer when two people label the same thread within a minute of each other. It falls over at the same point read state does, just later.
On Gmail there's a real step before anybody buys anything, and it's free with Workspace. A Collaborative Inbox does give you per-conversation assignment and resolution states: Google's documentation says "You can assign responsibility for a conversation to yourself or another group member", and a conversation can be marked "complete", "needing no further action", or "a duplicate of another conversation". The caveats are worth knowing before you count on it. Assignment is wired to Groups moderation permissions rather than to a workflow, marking a conversation as a duplicate "locks the conversation so that you can't perform any actions on it", and the things it still doesn't have are the ones that bite a growing queue: no response clock, no reporting, and nothing that warns you a colleague is composing a reply to the message you just opened. Microsoft has no equivalent on the mailbox side at all, and that asymmetry is worth planning around rather than discovering: a Workspace team gets a free rung between delegation and buying something, while on Microsoft 365 the step after delegation is a tool, because there's no native assignment layer to try first.
So the honest sequence is: delegation, then an improvised label convention, then a Collaborative Inbox if you're on Workspace, then a dedicated shared inbox tool, TriageFlow among them, when assignment needs to be a workflow with a clock on it rather than a label somebody remembers to set. That last step is the one where a shared inbox puts a named owner on each thread instead of asking the team to remember who took what.
Three triggers say you've reached the end of what delegation can do, and they're concrete enough to check this week.
The address stopped belonging to a person. If sales@ is an alias or a delegation on somebody's personal mailbox, it inherits their name, their leaving date and their holidays. The day they resign, a customer-facing address is sitting in a leaver's account. That's an argument for a team address, which every client handles slightly differently, before it's an argument for buying anything.
Two people answered the same customer in one morning. Once is a story. Twice in a week means your coordination signal has stopped working, whatever you were using as one.
Working out who's handling a thread needs a conversation. If the inbox can't answer that question by itself, it's stopped being the source of truth about its own work.
If the real question underneath is whether you need another person rather than another tool, our support team size calculator takes monthly ticket volume, a target response time and your average handling time per ticket and returns the headcount that implies. It's a staffing answer rather than a tooling one, and it's usually the number that settles the argument.
Frequently asked questions
Can a delegate see all my emails?
In Gmail, yes. Delegation is granted on the mailbox, and there's no way to scope it to a label, a sender or a date range. In Outlook it depends which grant was used: delegate access and folder permissions are per folder, so an owner can hand over the Inbox without the rest, while Full Access covers the whole mailbox.
How many delegates can one account have?
Ten on a personal @gmail.com, and up to 1,000 on a work or school account, where Google also recommends keeping concurrent users to around 40 for performance reasons. The "25 delegates" figure that circulates widely isn't in Google's documentation.
Can a delegate change my password or read my chats?
No. Google's wording is that "A delegate can't chat with anyone or change your password", and account settings are on the list of things that don't work inside a delegated mailbox. Delegation is mailbox access, not account access.
What's the difference between delegate access and Full Access in Outlook?
Delegate access is granted by the mailbox owner in classic Outlook, works per folder, and carries the right to send on the owner's behalf. Full Access is granted by an admin in Exchange and covers the whole mailbox, but Microsoft is explicit that it "doesn't allow the delegate to send messages from the mailbox". If your delegate can read everything and send nothing, that's the reason.
Can I delegate a personal Outlook.com mailbox?
You can't. Microsoft limits delegate access to work and school accounts in Microsoft 365 or Exchange Online. For a personal account the options are forwarding, which doesn't let anyone reply from the address, or moving the address onto a platform that supports delegation properly.
How do I know who answered an email from a delegated mailbox?
From the From line, if the reply went out as send-on-behalf: the recipient sees the delegate named alongside the mailbox owner, and in Gmail the delegate's address appears on anything they send. Send as is the exception, because Microsoft's documentation is explicit that there's "no indication that the message was sent by the delegate". Past that it's an admin lookup in the audit log, which answers the question days later and never during a shift.
Bottom line
For one person's mailbox covered by one or two colleagues, delegation is the right tool and you've already paid for it. Grant it on the owner's side, decide the sender-visibility question deliberately rather than by default, and expect it to take a day to go live. On Microsoft 365, check which of the five permissions you actually granted, because the one an admin hands out most readily is the one that can't send. And if what you're really trying to do is run a queue that several people answer every day, delegation was never the mechanism for that: start with a Collaborative Inbox if you're on Workspace, and look at a real shared inbox when assignment needs a clock on it.