Export a mailbox from Purview eDiscovery and you face a format decision before the redaction work even starts: one PST archive per mailbox, or thousands of individual message files. The decision matters more than it looks, because it determines whether attachment content gets scanned. The short answer for SafeRedact users: choose PST. The archive is expanded directly in your browser, messages, folder structure, and embedded attachments included, and nothing is uploaded anywhere in the process.
The Three Formats, Briefly
PST is Outlook’s mailbox archive: one file containing an entire mailbox’s folders, messages, and attachments. EML is a single message in the open internet format, headers and body with attachments encoded inline. MSG is Outlook’s proprietary single-message format. Purview can export Exchange data as PST archives or as individual messages, and DSAR bundles routinely contain all three once forwarded messages and saved files enter the mix.
PST in the Browser: How It Works and Where the Limits Are
SafeRedact parses the PST client-side and expands it into its constituent messages before detection begins. Three engineering realities shape the workflow. First, the whole archive loads into browser memory to be parsed, so there is a hard limit of 2GB per PST file, with a warning shown from about 1.5GB. The practical consequence is one setting: when exporting a large mailbox from Purview, set the package size to 1 to 2GB so the export arrives as multiple PSTs that each fit comfortably. Second, an archive can hold up to 25,000 messages. Third, attachments embedded in the mailbox are extracted and scanned for personal data like any other file in the case, and if something inside the archive cannot be extracted, the message carries an inline placeholder naming the attachment and the reason, so nothing is ever silently dropped from the disclosure record. That last behaviour is worth more than it sounds in a DSAR: an unscanned attachment you know about is a task, an unscanned attachment you do not know about is a complaint.
EML and MSG: When Individual Messages Make Sense
Individual EML export is a perfectly good path: each message is parsed for its headers, body, and embedded attachments, and the attachments run through the appropriate file-type handler. MSG is the format to treat with care. SafeRedact processes MSG files by binary extraction, recovering the message text and metadata strings, but the content of attachments embedded inside an MSG file is not scanned. For a mailbox where attachments carry the personal data, and in HR and housing cases they usually do, that difference is detection coverage. The working rule: PST first, EML second, and avoid MSG-only exports for attachment-bearing mail. Our Exchange email guide covers the message-level detection detail, including signature blocks and threading.
A Purview Recipe That Does Not Fight You Later
Scope the collection to named custodians and date ranges per the reasonable and proportionate standard, export Exchange content as PST with the package size set to 1 to 2GB, and let SharePoint and OneDrive items come through as native files. The result is a bundle where every attachment either gets scanned or gets named, the folder structure survives for context, and the export decision never has to be revisited mid-review. The Purview export guide walks the portal steps.
Big Mailboxes and the Laptop Doing the Work
Because processing is client-side, the machine running the browser does the expansion. That is the privacy feature, the mailbox never leaves your custody, and it is also the reason the 1 to 2GB package guidance exists: several mid-sized archives processed in sequence behave better than one enormous one. For multi-custodian cases, running one custodian’s mailbox as its own case keeps memory comfortable and makes the eventual disclosure log per-person, which is usually how the response is organised anyway.
How SafeRedact Fits
Files never leave your browser: documents are processed client-side, only extracted text is sent for AI detection, and no documents are stored on servers. Detection text is never used for training and is deleted within 30 days. DSAR mode lets you name the data subject whose information should be preserved while other individuals’ personal information is flagged for redaction across every file in the case. Every detection is reviewed by a human before anything is exported, and the output includes a processing summary and audit trail your privacy officer can stand behind if the ICO asks how the response was produced.
A Data Processing Agreement is available, and enterprise cases are priced per case, with the price set with you and shown before you download. See the enterprise overview or the enterprise FAQ for how cases run end to end.
Redact the Mailbox, Not Just the Messages
PST expanded in your browser, attachments scanned, and an audit trail that names anything that could not be. Files never leave your machine.
Start Your EvaluationRelated Guides
Microsoft, Microsoft 365, Outlook, SharePoint, Exchange Online, OneDrive, Teams, and Purview are trademarks of Microsoft Corporation. SafeRedact is not affiliated with or endorsed by Microsoft. This page is informational, not legal advice.