Skip to content

Backup and restore

  • Exchange Online: mail, calendar and contacts, incrementally through Microsoft Graph delta queries.
  • OneDrive: files, including older file versions Restow has captured, incrementally through Microsoft Graph.
  • IMAP mailboxes: mail, over IMAP, password-authenticated today (OAuth2 sign-in for IMAP sources comes in a later release).
  • Servers and clients: files, through the Restow agent on Linux and macOS, into restic repositories in your storage target. See Endpoint backup.

Mail you import from files is not backed up from anywhere: it is stored as an imported mailbox, in the same format as an IMAP backup (see Mail file import and export).

Every backup run of a mailbox, OneDrive or IMAP account is content-defined-chunked, deduplicated within a tenant, and encrypted before it reaches storage (AES-256-GCM, one key per tenant), and produces a snapshot, a point in time you can browse and restore from later: a single mail, a folder, a file, an older file version, or an entire mailbox/OneDrive/IMAP account. See Backups and schedules for how runs are triggered and scheduled.

Restore browses a backup as it looked at any point in time (folders, individual mails, files and their version history) and restores or downloads what you select, either one item at a time or the entire backup at once. A search box covers names, paths and mail subjects at the selected point in time.

At the bottom of the Restore explorer a slim timeline shows the restore points of the selected account, oldest on the left and newest on the right. The restore point you are browsing sits in the centre, and the timeline opens on the newest one. Each marker shows whether a restore check has proven that backup can be read back. In the folder tree, a folder without subfolders says so.

This is the product’s firm rule: restore is not meant to overwrite an existing original in a mailbox or OneDrive. When you restore into the original location, Restow asks what to do if something with the same name is already there:

  • Keep both (the default): nothing existing is touched; the restored item is written in alongside it. Mail restores go into a new, clearly named folder (for example “Restored 2026-09-23 1432”); a file that would collide with one already there is restored under a new name.
  • Skip existing: items that are still there are left exactly as they are; only what’s actually missing is restored.

You can also restore into another account of the same tenant (mailbox, OneDrive or IMAP account; tenant admins only), or download as a ZIP: mails as .eml, other files as they are, together with a checksum list, from a link valid for 24 hours. An older file version that OneDrive itself kept (separate from Restow’s own backups) is download-only.

Before you confirm, the dialog shows a preview of what’s about to happen: the source (object and point in time), the target and mode, and, for an admin restoring another person’s data, a note that this is recorded as an admin restore on their behalf, plus a required reason. Every restore is written to the audit log: who requested it, when, exactly what and where, on whose behalf if applicable, and from which IP address. There is currently no printable or exportable restore-confirmation view beyond that audit-log entry.

A mailbox you import from files appears in the Restore explorer like any other account, marked Imported: folder tree, search, preview, print view, download, and restore into an existing IMAP account or a Microsoft 365 mailbox. There is no original to restore into, so restoring to the original location is not available for it. See Mail file import and export.

Servers and clients are restored from their own pages, not from the mailbox Restore explorer: browse a backup, download files as a ZIP, or restore into a new folder on the machine, never over existing files. See Restore for servers and clients.

You can export a mailbox or folders from a backup, an imported mailbox or the archive as files: EML files in a ZIP (with MANIFEST.csv and SHA256SUMS) or as MBOX. The download link is valid for 24 hours, and every request and download is written to the audit log. See Mail file import and export.

A backup Restow has not read back is not treated as trustworthy. A scheduled restore check (weekly by default) reads back a random sample of items from the latest backup through the restore path (the same chunk index, pack fetch and AES-256-GCM decryption a real restore uses) and compares their size and SHA-256 hash with the manifest, rating each protected object Ready, Attention or Not restorable; a backup nothing has read back yet is Not verified, whatever an earlier backup scored. There is no test restore into a live mailbox or OneDrive yet. See How Restow checks that a backup can be restored for exactly what is checked and what it does not check yet, First steps for running one by hand, and Backups and schedules for putting it on a schedule. Servers and clients are rated the same way, from a restore test of sample files: see Servers and clients.

  • Microsoft Teams is not covered: not backed up, not restorable, in this version.
  • IMAP credentials are per source, not per mailbox: one login protects every mailbox under an IMAP source (a master account or shared credentials). Separate passwords per mailbox are in development.
  • First backup of a large tenant: Microsoft throttles the Graph API, so a first backup can take days rather than hours. Restow shows this wait in the job’s progress instead of hiding it.