CheckEmoji Community · the emoji forum
🏠 Home 🆕 What's new ❓ Unanswered 🔥 Popular 📡 RSS Members 👥 0 online log in · register
Home › IT › IT Support › Work email issues

Work email issues

Started by Jose Scott3 · · 👁 3 views · 9 replies

📡 Subscribe to replies

Participants Jose Scott3swiftowl7Michelle Bennett5Jack Cook7William Palmer7Jacob Cooper5
Jose Scott3 Jose Scott3 MemberOP
31 messages
joined Mar 2023
#1 ·
Just found out our boss has full access to everyone's email inboxes (which isn't even legal without prior notice and signed consent). Is there some kind of app or a workaround to block him from snooping through our mail? Or should we just head down to the office IT-experts and try to bribe them with a bottle of bourbon... 😬

p.s. please spare me the moral lectures and life lessons, I just want to know if this is technically doable and how.
swiftowl7 swiftowl7 Member
46 messages
joined Dec 2017
#2 ·
To be honest, without getting all preachy about it—no.

The admins of any domain can read through all your emails, much like how someone might have access at a place like Google, and I’m really not one to lecture anyone on the legal intricacies of it all, nor do I think those legal arguments actually hold much water in the grand scheme of things.

At its core, the internet is a bit of a wild west where freedom rules, and if you look closely at almost any Terms of Use agreement, they basically boil down to saying, "this site belongs to us, so we can do whatever we want with it."

It looks like your boss's admin figured out how to get into the system or was simply given the keys to the email database, and once that happens, there isn't much you can do to stop it.
Michelle Bennett5 Michelle Bennett5 Active Member
89 messages
joined Dec 2007
#3 ·
Jose Scott3 said:Is there actually an app for this, or some way to block them from hitting the inbox? Or maybe we just head down to the office, find the local IT-experts, and see if we can bribe them with a bottle of high-end bourbon.

you can definitely sabotage unauthorized reading
The easiest way? Don't put the info in the email itself. Type everything up in a Word doc, password-protect it so only the recipient has the key, and then just attach that Word document to the email instead.
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#4 ·
John Cook72 said:you can stop people from snooping on your messages
the easiest way? instead of typing stuff directly in an email, write it in a Word doc, password-protect that file so only the recipient can open it, and then just attach that document to your email.

That’s incredibly easy to crack.

The buddy swiftowl7 is totally spot on here. The domain belongs to the company, the mail server is company property, and every single email you send is company property.

Your work laptop? That's company property. Everything sitting on that hard drive belongs to the firm. If you want to use your own personal laptop during office hours, you basically need explicit written permission from the higher-ups—and even then, they'll likely demand the right to inspect everything on that machine.

Work phones are company property too, which means management can access all your call logs, incoming and outgoing. They can record voice calls, read texts, whatever—as long as it stays within the corporate network.

If you're planning on using your personal phone while on the clock, you're gonna need that official thumbs-up from management, which usually comes with them wanting full access to your device.

Now, if you go the encryption route, you've got PGP or other similar tools. But that puts you in a weird spot because your boss will notice immediately that you're encrypting things, and you'll find yourself under a microscope within 24 hours. Plus, you probably can't even install a VPN because the company group policy has blocked you from having admin rights on your CPU.

Every single thing you do online is being logged—which sites you visit, what you're reading, how much time you're wasting there. It's all recorded.

Even if your boss is a complete jerk and totally incompetent, the rules don't change. Most of these guys just use their power to cling to their positions by micromanaging their employees' lives. And I'm sure
his bosses are totally fine with it. I've seen it happen way too often. These are toxic companies. Honestly, you should just grab your references and run for the hills.

The types of people running this kind of control? Total idiots. They aren't smart, they aren't capable, and they definitely aren't hardworking—otherwise, they'd be doing something useful, like actually helping a customer. All they care about is manipulation. I've known plenty of them. They're just parasites that poison everything they touch.
swiftowl7 swiftowl7 Member
46 messages
joined Dec 2017
#5 ·
John Cook72 said:you can actually prevent unauthorized reading
it’s pretty simple: instead of putting everything directly in an email, just type it out in a Word doc, password-protect that file so only the recipient can open it, and then just attach that document to your email message

Sure, you can hide your communication that way, but I wouldn't really call that "emailing" in the traditional sense...

In today's fast-paced world, there's a golden rule you should probably follow:
- maintain a professional work email
- and keep a private one (strictly for your personal devices)

and stick to that separation like glue.

I honestly suspect the author might have been flirting a bit with a coworker, which would explain the reaction... or maybe the boss is just hovering over everything, or checking up on what kind of meds someone is picking up at the pharmacy, who knows?

Anyway, my personal take is that a huge number of companies monitor employee communications via email—mostly just to pass the time, since there isn't much actual benefit to snooping on people's chats—but it's also incredibly stupid for them to let employees know they're doing it. There are even some firms that go as far as spying on their staff's real-life habits and movements, almost like they're working for the FBI or something. Don't even get me started on the hidden cameras in offices.

I bet they're sniffing through people's Facebook profiles too, let alone their emails...

Personally, if someone were looking through my emails, I wouldn't even care, because honestly, so many people are already curious about how I live my life and what I'm up to that I've just grown used to it. 😁
Jose Scott3 Jose Scott3 MemberOP
31 messages
joined Mar 2023
#6 ·
swiftowl7 said:In today’s corporate world, there’s one golden rule:
- have a work email
- and a personal one (strictly on your own devices)

And you stick to that separation like glue...

Hold on a second... I get that my boss can peek at my work Outlook, but how exactly are they reading my private Gmail just because I logged in once or twice on my office PC? Do they magically have my password now, or can they just watch my screen while I'm logged in? I don't follow...

swiftowl7 said:Long story short, and without getting preachy—no.

The domain admins can read any email, including stuff like Gmail, and I don't know much about the legal loopholes involved, nor do I think those legalities even matter here...

That's not quite right. Under US law, they can monitor work emails, but before they do that, they actually have to get a signed consent form from you stating that you're aware of it.
swiftowl7 swiftowl7 Member
46 messages
joined Dec 2017
#7 ·
Jose Scott3 said:Just a quick thought on this... I totally get why you're feeling a bit uneasy, because while it makes perfect sense that a boss could access a work Outlook account from their own machine, the idea that they could just peek into your private Gmail just because you logged in once or twice on a company computer feels a little more intense. I was actually wondering something similar a few months ago when I was setting up my home office setup, and it really helps to break down how these things actually work. It isn't like they automatically have your password or anything like that—that would be a massive security breach—and they definitely can't see your screen in real-time while you're logged in unless they've installed some pretty heavy-duty monitoring software. Usually, it all comes down to how much data stays cached in the browser or if the company uses certain management tools on the hardware itself, so it’s less about them "watching" you and more about what traces your login leaves behind on the device.

When you're thinking about business email security, you don't even have to worry about someone hacking into your Outlook or physically sitting at your computer to see what you're doing. It’s actually much more direct than that because everything can be intercepted right at the mail server level. Someone could technically sit there and read through emails before they ever even hit your inbox or show up on your screen. And honestly, it isn't just limited to your private messages either; they could systematically go through the emails of every single employee in the entire company, one by one.

Typically, the company’s mail server keeps a complete archive of all your business emails, regardless of whether you decide to clear them out of your Outlook inbox or not. Honestly, the only person with the power to permanently wipe everything out is the company’s systems administrator. I remember back when I was working at a tech firm in Seattle, the admins would occasionally have to do some heavy lifting to free up space when the server started getting bogged down by massive amounts of data. They don't just hit delete and walk away, though; they usually make sure to back up the entire mail database onto a local drive before clearing anything out, just to stay on the safe side.

Just a heads-up regarding Outlook... since most of our professional conversations happen through business email, there’s a good chance those threads are being archived permanently. It really all comes down to the specific company's policy. Some organizations have strict data retention rules and keep everything on file, while others don't bother, and some managers might actually be reading through them while others couldn't care less. But at the end of the day, if you're an employee communicating with clients via email, almost every boss out there is going to be interested in seeing how those interactions are playing out.

***
Now, when you're talking about a private Gmail account, that’s a whole different ball game. There are actually a few ways to handle it. You could technically bypass that PIN through some software tricks, or even use a camera to get around it.

I just stumbled upon this really interesting company today, and I honestly can't stop thinking about how much potential they have to shake things up in the industry. It’s one of those rare finds where everything seems to click perfectly, from their core mission to the way they handle their day-to-day operations, and it reminded me of a small startup I used to follow back when I lived in Seattle. There’s just something so refreshing about seeing a business operate with that kind of vision and energy! 👍 If you really want to stay ahead of things and keep everything locked down, I’d just suggest changing your Gmail password while you're hanging out at home, and then honestly, if you stick to that one simple rule, you should be golden. I’ve always found that keeping my private emails strictly on my own personal devices just makes life so much easier and keeps everything feeling organized. There’s something really peaceful about knowing my personal inbox isn't floating around on a work laptop or a shared tablet, especially when I'm trying to unwind after a long day at the office.

That’s not actually how it works. Under current US labor laws, they can certainly go through my business emails, but they really ought to get a signed consent form first—one that clearly states I've been notified about the policy.

I honestly think you’re on the right track here. If you’re feeling confident that you've got the facts on your side, I’d say go ahead and pull those specific sections from the labor code to show your boss exactly what we're looking at, and then maybe start thinking about what our next actual move should be.
William Palmer7 William Palmer7 Member
36 messages
joined Jul 2019
#8 ·
Jose Scott3 said:We just found out our boss can peek into everyone's email inbox (which isn't even legal without prior consent and notice). Is there an app or some workaround to block his access? Or should we just head down to the office IT-experts and try to bribe them with a bottle of bourbon? 😬

p.s. please skip the lectures and moralizing; I just want to know if this is technically possible and how to do it.

Sure. Just smash his computer with a crowbar.
Jacob Cooper5 Jacob Cooper5 Active Member
169 messages
joined Nov 2014
#9 ·
Jose Scott3 said:We just found out our boss has access to everyone's inbox—which, by the way, isn't even legal here without prior notice and signed consent. Is there some kind of app or a workaround to block him from getting into our emails? Or should we just head over to the firm's IT-experts and see if we can bribe them with a bottle of bourbon? 😬

p.s. please spare me the moralizing and the life lessons... I just want to know if this is technically doable and how.

Just give him a group slap to the face. 😁

Jokes aside, that’s something the network administrator handles—they're the ones who set the permission levels for everything on the network.
If the boss has already mandated unrestricted access to every terminal on the network, then that's just the reality you're stuck with... nothing you can really change from the outside.
Whether or not you're allowed to use work computers for personal stuff is a matter of company policy.
Then there's the whole issue of spying on private emails sent during work hours—that's a third, separate problem entirely. If his corporate policy dictates he has total access to all machines on the network, proving he was specifically snooping through *your* private threads is going to be nearly impossible... mostly because he has access to your machine whenever he wants, making it "coincidental" that he happened to see your emails.
In a setup like this, don't use anything private at all... because using those machines for personal business is basically the same as letting someone install spyware on your own computer.
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#10 ·
Laws regarding internal company policy are super loose.

Basically, anything on official computers, phones, or paper docs belongs to the company. That includes desks, drawers, filing cabinets—everything.

So, sure, you can lock your papers in a drawer and take the key home, but the company still has the right to peek inside whenever they want without you knowing.

Even those landline calls at the office? They can be recorded at will without even telling the person on the other end. The call is company property, period.

Work cell phones are a bit more sensitive since the data usually goes through an outside carrier, but it’s the same deal. The phone or the number belongs to the firm, they pay the bill, so they own the recording. There are telecom services that can redirect every single call from an employee's mobile or work number straight to a server chosen by the owner of Company X. You might think you have a phone, but if the number belongs to Company X, every call or text gets sent straight to them automatically.

It's the same if you're using a company phone but have a private number plugged in. Ever heard of "locked" phones?

Whose money, whose rules.

A company can't touch your private email, Skype, or WhatsApp accounts—not legally—even if you open them on a work device.

But! If you use them on company gear, they have plenty of rights to install spyware that logs everything from your passwords to every chat, encryption be damned. It happens all the time. There are stealth programs that run in the background and beam everything to specific servers. There are even third-party cloud services that handle this. Just a quick Google search will show you.
https://www.spyagent.net/

They can even capture full screenshots without ever touching your webcam. And don't even get me started on how some bosses feel entitled to use the camera—whether it's on your PC or your phone—to spy on employees, even after hours, just because the device is "official."

So, if you start a private video or voice session like Skype on a work device, the company basically has the right to record everything you do.

Don't confuse this with talking to outside parties; for those people, companies actually have to give explicit notice at the start of the call if it's being recorded.

American laws are pretty weak on this stuff. (Like everything else, honestly.)

Back in the day under socialism, this was explicitly banned, but hey, technological progress... democracy and the rule of law, right?

And no, encryption won't save you. Your only bet is using completely private devices that are totally disconnected from the company.

As far as I'm concerned, if you find a company pulling this kind of surveillance, you should bail the second you get a few solid references under your belt. That’s a toxic, rotten environment run by incompetent bosses. If someone is really riding you, gather evidence of the spying. It’s always useful when you can shove proof in the face of the people "supervising" you that they never disclosed they were watching. Nothing shuts a monitor up faster than proving you were actually monitoring *them*. And since you did it on your own private gear, they can't claim any rights to your logs or content. Watch how fast their tone changes then. 😉

=================

Keep in mind, all they need to surveil you is to know you're posting on Facebook, Twitter, Instagram, or Reddit.

Some sites aren't even properly secured with HTTPS, making them extra vulnerable. Bosses like that can literally read what employees are writing online in real-time. These managers think they're so clever, assuming their staff doesn't realize they're reading their messages. The only question is who those messages are for—the random people on a forum or their own bosses.

It’s the exact same deal with Facebook, Twitter, or whatever else—even if they’re technically "safe" because of HTTPS. Look, if you check the logs on a local firewall, it’s dead easy to see when Employee X hits up Facebook to drop a message (you can tell just by looking at the traffic spikes). Give me an hour or two of shallow digging, and I can bridge that 1:1 gap to prove that "John Doe" on Facebook is actually Mike Miller from Company X. It’s honestly as simple as signing a contract with your full legal name and SSN.

Sure, there are ways to put some guardrails up (like using a VPN, Secure DNS, DNS over TLS, or DNS over HTTPS), for example: https://www.cloudflare.com/learning/dns/dns-over-tls/

But at the end of the day, it always comes back to this: any halfway decent firewall admin can spot user activity in their sleep.

There’s a fix for that too, but that’s a whole different conversation.

Bottom line? Use your own phone, your own number, your own laptop. Keep everything encrypted and stay off the company Wi-Fi or the office cellular network entirely.

You must log in or register to reply here.

Log in Register

🔗 Similar threads