How to Recall an Email in Gmail (Undo Send Guide)
Gmail has no true recall, but Undo Send gives you up to 30 seconds. Learn how to set it, use it, and exactly what to do once that window closes.
Gmail has no true recall, but Undo Send gives you up to 30 seconds. Learn how to set it, use it, and exactly what to do once that window closes.
Gmail does not truly recall an email. Instead, it holds the message for a few seconds after you press send, and clicking Undo cancels it. You can set that window to 5, 10, 20, or 30 seconds. Once the window passes, the message is delivered and you cannot pull it back.
Table of Contents
ToggleThe difference between a delay and a recall decides what is still possible in Gmail. Gmail waits before it actually sends. During that pause, Undo stops the message entirely, so the recipient never sees it.
Outlook works differently. It tries to remove a message that has already arrived, which only succeeds in narrow conditions. Gmail makes no such attempt, and in practice its approach is more reliable within its short window.
So the useful question is not how to recall a sent Gmail message. It is how to widen the window, and what to do once the window has closed. Sending to the wrong person is one of the most common ways company data leaks outbound, so the answer matters beyond one awkward email.
Act immediately, because the window is short.
On the Gmail mobile app, a similar bar appears at the bottom of the screen. Tap Undo there. Google does not publish how long the mobile window lasts and offers no mobile setting for it, so do not count on the full 30 seconds.
Discover how Threatcop protects your workforce from modern cyber threats.
Most accounts default to 5 seconds, which is rarely enough to notice a mistake. Change it once and forget it.
Google documents 30 seconds as the maximum, so there is no setting beyond it. The trade-off is small: your mail sits for half a minute before it leaves.
Once Gmail delivers the message, no feature brings it back, as Google’s own help pages make clear. Confidential mode does not help either, since it restricts forwarding and can expire access, but it must be set before sending.
What to do instead depends on what went wrong.
| What happened | What to do |
|---|---|
| Wrong recipient, harmless content | Send a short follow-up asking them to delete it |
| Wrong attachment with company data | Tell your security or IT team the same day |
| Personal or customer data to an outsider | Treat it as a possible breach and report it internally |
| Wrong content, right recipient | Send a correction and move on |
The second and third rows matter most. Under rules such as GDPR and HIPAA, one misdirected email can count as a reportable breach, and the clock starts when your organization becomes aware. So speaking up quickly matters more than feeling embarrassed about it.
Undo Send is a safety net, not a strategy. A few habits cut the number of times you need it.
These are the same habits that reduce outbound email errors, which remain a common cause of data loss. None of them take extra time once they become routine, and together they catch the errors Undo Send is too slow to stop.
If you manage Google Workspace, treat this as a policy question rather than a personal setting.
Start by telling staff to set the 30-second window, since it is per-user and not enforced centrally. Then make sure people know who to tell when an email goes to the wrong place, and make that report blame-free. Staff who expect blame stay quiet, and silence is what delays the response.
Finally, train for the habit rather than the feature. Data-handling lessons reach the decision that happens before send, which is where the real fix lives.
The slowest part of a misdirected email is rarely the technology. It is the minutes or hours before someone admits what happened.
Threatcop Phishing Incident Response (TPIR) shortens that gap by putting one-click reporting inside the mail client, so telling security takes the same effort as deleting the message. Its “Who Else” reporter insight then shows whether the same message reached other mailboxes, which matters when a file went out on a distribution list rather than to one person. The security team sees the report, the recipients, and the content in one console instead of reconstructing it from a worried phone call.
That speed is what regulators actually examine. When a misdirected email counts as a reportable breach, the question is when you knew and what you did next, and a timestamped report answers both.
Gmail gives you seconds, not second chances. So do three things. Set the cancellation window to 30 seconds today, because it costs nothing and catches real mistakes. Build the habit of addressing the email last, after the message and the attachment are done, since that single change prevents most wrong-recipient errors. Then make sure everyone knows who to tell when something does go out, and that reporting it quickly is treated as normal, and that telling them is quick and blame-free. Undo Send handles the first 30 seconds. What happens after that depends entirely on how fast your people speak up, and that is the part worth building.
No. Gmail’s Undo Send only works within the cancellation window you set, up to 30 seconds. After delivery, there is no way to remove the message from the recipient’s mailbox.
30 seconds. Google documents that as the longest available setting, chosen from 5, 10, 20, or 30 seconds in Gmail settings. There is no supported way to extend it further.
Yes. The Undo option appears in a bar at the bottom of the screen right after you send. Google publishes no duration for the mobile window and no mobile setting to change it, so treat it as short and act immediately.
No. Once Gmail completes delivery, the message belongs to the recipient’s mailbox. Undo Send only works before delivery, which is why it is a delay rather than a true recall.
Report it internally the same day, rather than only asking the recipient to delete it. Depending on the data and your region, it may qualify as a reportable breach, and regulators look at how quickly you responded.
Shikha Mishra is responsible for driving the growth and adoption of TDMARC, a flagship product of Threatcop, across India, the Middle East, APAC, and the UK region. With her expertise, she helps organizations safeguard their domains so that no hacker can misuse them to send fraudulent emails, thereby protecting both their brand and reputation. She is passionate about enabling businesses to simplify the complexities of outbound email security through TDMARC’s comprehensive solution, allowing them to stay focused on what matters most to their success.
Shikha Mishra is responsible for driving the growth and adoption of TDMARC, a flagship product of Threatcop, across India, the Middle East, APAC, and the UK region. With her expertise, she helps organizations safeguard their domains so that no hacker can misuse them to send fraudulent emails, thereby protecting both their brand and reputation. She is passionate about enabling businesses to simplify the complexities of outbound email security through TDMARC’s comprehensive solution, allowing them to stay focused on what matters most to their success.
Outlook recall only works inside your organization on unread mail. Learn the steps, the limits, and why Undo Send...
Gateways filter mail before delivery. API-based tools inspect it inside the mailbox. See how they differ, where each fails,...
A phishing simulation is safe practice, not a trap. See how it works step by step, which metrics matter,...
Table of Contents
×