How to Recall an Email in Outlook (And When It Fails)
Outlook recall only works inside your organization on unread mail. Learn the steps, the limits, and why Undo Send protects you far more reliably.
Outlook recall only works inside your organization on unread mail. Learn the steps, the limits, and why Undo Send protects you far more reliably.
Outlook can recall a sent email, but only inside narrow limits. Both people need Microsoft 365 or Exchange work accounts in the same organization, and the recipient must not have opened the message. Recall fails for Gmail, Yahoo, and personal addresses. So the more reliable option is Undo Send, which holds the message before it leaves.
Table of Contents
ToggleOutlook recall tries to remove a message that has already been delivered. That is a harder job than Gmail’s approach, which simply delays sending, so it succeeds far less often.
Microsoft sets clear conditions. Both sender and recipient need Microsoft 365 or Exchange work or school accounts in the same organization. The recipient must not have opened the message. They also need to read mail in a supported Outlook client, and no inbox rule can have moved the message out of the inbox.
Miss any one condition and the recall fails. That is why a recall sent to an outside client or a personal Gmail address never works. Sending to the wrong person is a leading cause of accidental data loss, and recall rarely rescues it.
The steps differ slightly by version.
Classic Outlook for Windows
New Outlook for Windows and Outlook on the web
Outlook usually sends you a recall report within about 30 seconds. It tells you whether the recall succeeded, failed, or is still pending for each recipient.
Discover how Threatcop protects your workforce from modern cyber threats.
Because recall often fails, a send delay protects you better. It holds the message, so you can stop it before anyone receives it.
| Client | Undo Send available? | Maximum delay |
|---|---|---|
| New Outlook for Windows | Yes | Up to 10 seconds |
| Outlook on the web | Yes | Up to 10 seconds |
| Outlook.com personal | Yes | Up to 10 seconds |
| Outlook for Mac | Yes | Up to 120 seconds |
| Classic Outlook for Windows | No built-in option | Use a delayed-delivery rule instead |
Microsoft documents the undo send setting too. To turn it on in new Outlook or on the web, open Settings, then Mail, then Compose and reply, and set the Undo send delay. On Mac, open Settings, then Composing, and set the Undo Send delay.
Classic Outlook has no Undo Send, though a rule that defers delivery by one or two minutes achieves something similar across the whole mailbox.
Assume the message stayed where it landed, then act on what it contained.
The deadline is the reason for speed. Under GDPR, HIPAA, and similar rules, a misdirected email can count as a reportable breach, and the clock starts when your organization learns of it. So an incident reporting culture that treats these reports as routine gets the response started hours earlier, which is often what limits the damage.
Recall is a last resort with poor odds, so the practical work sits earlier.
These habits address the same gap as other outbound email errors. They cost nothing, and they work in every client.
Set expectations before an incident, because people assume recall works everywhere.
Tell staff plainly that recall only works inside the organization and only on unread mail. Many people assume it works like deleting a file, and that belief makes them slower to report a real problem.
Then enable a send delay where your clients support it, and publish one clear route for reporting a misdirected email. Make that route blame-free, since staff who fear blame delay the report. Keep a simple log of these incidents too, because regulators ask what you did and when.
Finally, cover this alongside phishing in training. Sending data to the wrong person is an everyday risk, and it rarely gets the same attention as an inbound attack.
Recall fails quietly, and staff often keep trying it instead of telling anyone. A reporting route works better, because it does something useful in every case rather than only in the narrow one where recall succeeds.
Threatcop Phishing Incident Response (TPIR) gives staff one-click reporting from the mail client, so a misdirected message reaches the security team in seconds. Its “Who Else” insight shows which other mailboxes received the same message, which turns a vague “I think it went to the whole list” into an exact recipient list. Admins get bulk actions and advanced search in one console, so the response starts while the recall attempt is still pending.
That matters for the clock. Recall gives you a maybe. A report gives you a timestamp, a scope, and a decision, which is what a breach assessment actually needs.
Treat Outlook recall as a long shot rather than a safety net, because it works only inside your organization and only on unread mail. Three things protect you more. Turn on a send delay in whichever client supports it, since stopping a message beats retrieving one. Build the habit of addressing the email last, after the message and the file are ready. Then make sure staff know exactly who to tell when something sensitive goes astray, and that reporting it carries no blame. Recall occasionally saves an email. The send delay and the fast report are what save the response time, and response time is what regulators ask about.
Recall only appears for Microsoft 365 or Exchange work and school accounts. Personal Outlook.com accounts do not have it, and your administrator can also disable the option.
No. Standard recall requires both sender and recipient to be in the same Microsoft 365 or Exchange organization. Messages to Gmail, Yahoo, or personal addresses cannot be recalled.
No. The recipient must not have opened the message. Recall also fails when an inbox rule moved the message, or when they read mail in a client that does not support recall.
There is no fixed time limit, unlike Gmail’s 30-second cap. What matters is whether the message is still unread and the other conditions are met, so a recall after an hour can still succeed if nobody opened it.
Undo send holds the message briefly before it leaves, so nothing is delivered. Recall tries to remove a message that already arrived. Undo send is far more reliable, which is why it is worth enabling.
Shikha Mishra is responsible for driving the growth and adoption of TDMARC, a flagship product of Threatcop, across India, the Middle East, APAC, and the UK region. With her expertise, she helps organizations safeguard their domains so that no hacker can misuse them to send fraudulent emails, thereby protecting both their brand and reputation. She is passionate about enabling businesses to simplify the complexities of outbound email security through TDMARC’s comprehensive solution, allowing them to stay focused on what matters most to their success.
Shikha Mishra is responsible for driving the growth and adoption of TDMARC, a flagship product of Threatcop, across India, the Middle East, APAC, and the UK region. With her expertise, she helps organizations safeguard their domains so that no hacker can misuse them to send fraudulent emails, thereby protecting both their brand and reputation. She is passionate about enabling businesses to simplify the complexities of outbound email security through TDMARC’s comprehensive solution, allowing them to stay focused on what matters most to their success.
Gateways filter mail before delivery. API-based tools inspect it inside the mailbox. See how they differ, where each fails,...
Gmail has no true recall, but Undo Send gives you up to 30 seconds. Learn how to set it,...
A phishing simulation is safe practice, not a trap. See how it works step by step, which metrics matter,...
Table of Contents
×