1-844-366-6700

Real estate runs on email. Listing updates, disclosure packages, financing contingencies, and closing instructions all move through agent and broker inboxes, often within tight, deadline-driven windows. That makes email the single most valuable target in a real estate transaction, and it’s also why switching email platforms in this industry carries risks that don’t show up in a generic migration checklist.

This guide covers what brokerages and agencies need to know before moving from Google Workspace to Microsoft 365, from Microsoft 365 to Google Workspace, or off a legacy IMAP or hosting-provider setup, with a focus on the wire fraud exposure, records retention rules, and transaction-timing considerations specific to real estate.

Want to see more content like this? Add us as a Preferred Source on Google to see more of our articles when you search.

Why real estate email is a prime target

Real estate transactions combine three things fraudsters look for: large dollar amounts, hard deadlines, and multiple parties (agent, buyer, seller, lender, title company, escrow officer) who don’t all know each other and are accustomed to receiving last-minute instructions by email. Business email compromise (BEC) exploits exactly that mix.

The scale of the problem has kept growing. The FBI’s 2025 Internet Crime Report logged $275.1 million in real estate fraud losses across 12,368 complaints, up from approximately $173 million the prior year, with business email compromise, the primary mechanism behind real estate wire fraud, accounting for $3.04 billion in total losses across all sectors that year. Industry-specific research backs this up: in Qualia’s 2026 survey of title and escrow professionals, 86% said phishing emails and BEC are where most attacks against their firms originate, and 72% reported experiencing phishing directly.

The recovery odds aren’t great once money moves. Per the same IC3 reporting cited above, the FBI’s Recovery Asset Team initiated 3,900 fraud incidents in 2025 and froze $679 million of the $1.16 billion attempted, a recovery rate of roughly 58%, which means close to half of every dollar wired to a fraudulent account is gone for good.

None of this means a platform migration is inherently dangerous. It means a migration is a moment when email authentication, forwarding rules, and account access all change at once, and that’s precisely the kind of disruption a BEC actor can exploit if the transition isn’t planned around it.

The retention and recordkeeping backdrop

There’s no single federal law that governs how long a real estate agent has to keep email, the way HIPAA governs healthcare records. Instead, retention obligations come from a mix of state real estate license law and transaction-specific federal rules, which makes migration planning a bit more state-dependent than in more heavily regulated industries.

A few patterns show up across most states:

  • State license law sets a minimum. Under California’s Business & Professions Code §10148, a licensed broker must retain listings, deposit receipts, canceled checks, trust records, and other transaction documents for three years, and that requirement explicitly includes email. Many other states set similar three- to five-year minimums for brokers, though the exact period and scope vary, so confirm your state’s specific rule before setting a retention policy.
  • The minimum isn’t the safe number. Legal guidance for brokers generally recommends keeping records well beyond the statutory minimum, since claims tied to a transaction can sometimes be filed years after the discovery of an injury, not just after closing.
  • Lender-side retention runs longer. Mortgage lenders and their loan originators fall under separate federal recordkeeping rules tied to loan disclosures, which is relevant if your brokerage handles any in-house lending or affiliated business arrangements.
  • Electronic storage has to be tamper-resistant, not just backed up. Some states, including California, require electronically stored broker records to use non-erasable, write-once storage that doesn’t allow the stored document to be altered, which is a detail worth checking against your target platform’s archiving and legal hold configuration before migration, not after.

The practical implication for a migration: don’t treat “we exported everything to a PST/MBOX file” as done. Confirm the destination platform’s retention and legal hold policies are configured to your state’s requirements before the old mailboxes are decommissioned, and keep a verified, searchable archive of anything approaching the outer edge of your retention window.

Platform comparison: what matters for brokerages specifically

Both Microsoft 365 and Google Workspace are viable for real estate, and the platform-by-platform tradeoffs are covered in full in our general email migration guide. A few considerations matter more in this industry than most:

  • Shared and team mailboxes. Brokerages routinely need shared inboxes for a team or office location (listings@, offers@) that multiple agents and a transaction coordinator can access without sharing individual credentials. Both platforms support this, but the permission models differ enough that it’s worth mapping your current shared-mailbox structure before migration rather than recreating it from memory afterward.
  • Mobile-first usage. Agents live in their phones between showings. Whichever platform you choose, test mobile client behavior (push notifications, calendar sync, attachment handling for disclosure PDFs) with a pilot group before the full brokerage cutover.
  • Domain authentication for outbound trust. Given the BEC exposure described above, DMARC, SPF, and DKIM enforcement on your domain matters more here than in lower-target industries. A migration is the right moment to tighten this, not just preserve whatever was there before.
  • E-signature and transaction management integrations. Confirm your DocuSign, Dotloop, SkySlope, or similar transaction platform’s email integration is re-authorized and tested against the new platform before agents rely on it for a live deal.

The migration risk unique to real estate: timing around open transactions

In most industries, the worst-case outcome of a mistimed migration is a few hours of inconvenience. In real estate, a mailbox access gap during an active transaction can mean a missed contingency deadline, a delayed closing, or a window where a client can’t verify wiring instructions with their agent because the agent’s email is mid-cutover.

A few practices reduce that risk:

  • Avoid migrating mailboxes with contracts pending toward closing in the next 5-7 business days. Stagger the migration schedule so agents with imminent closings move last, or move first with extra support standing by, rather than landing in the middle of the cutover window.
  • Never change wiring instructions or bank details during a migration window, and tell clients that in writing. If clients hear “we’re switching email systems” around the same time as a legitimate request involving money, that’s exactly the cover story BEC actors use. A short, proactive notice (“We are moving email providers on [date]; we will never send you new wiring instructions by email, during this transition or otherwise”) closes that gap.
  • Watch for a spike in look-alike domain registrations during the transition. Fraudsters sometimes register a domain that mimics a brokerage’s name shortly after a migration is announced or noticed publicly (e.g., in an out-of-office reply). Monitoring for this is a standard part of a managed migration.
  • Keep the old platform’s inbound mail flowing (or clearly bounced) during cutover, so a client or lender emailing the old address gets a fast, unambiguous signal rather than a silently dropped message during a live transaction.

Step-by-step migration framework

  1. Inventory active transactions first, not last. Before touching any technical settings, get a list of every mailbox with a contract in progress and its expected closing date. This drives your migration schedule more than IT convenience does.
  2. Audit shared mailboxes, distribution lists, and delegate access. Map who currently has access to office@, offers@, or team inboxes, and confirm the same structure will exist on day one of the new platform.
  3. Confirm retention and legal hold settings before migrating a single mailbox. Set retention policies on the destination platform to match your state’s requirements, and verify archived mail is actually searchable, not just present.
  4. Run a pilot migration with a small group, ideally including one agent with a mobile-heavy workflow and one with an active transaction close to (but not inside) the no-migrate window.
  5. Notify clients and counterparties in active transactions in writing, including the standing instruction that wiring details will never change by email.
  6. Migrate mailboxes in waves, holding agents with imminent closings for last (or first, with dedicated support), and verify calendar, contacts, and shared mailbox access after each wave, not just mail.
  7. Harden domain authentication (DMARC/SPF/DKIM) as part of cutover, rather than treating it as a follow-up project.
  8. Decommission the old platform only after a verified retention export, keeping the source data intact until your state’s minimum retention period is independently confirmed on the new system.

For a broader walkthrough of the technical migration process itself, see our guides on Google Workspace to Microsoft 365 migration and Microsoft 365 to Google Workspace migration.

Frequently asked questions

Does RESPA regulate how real estate agents migrate or store email? No. RESPA governs referral fees, kickbacks, and settlement service disclosures, primarily affecting lenders, title companies, and agents around affiliated business arrangements. It doesn’t set email retention or migration requirements directly. State real estate license law is the primary source of email recordkeeping rules for agents and brokers.

How long do we need to keep agent emails after a migration? It depends on your state’s real estate license law, commonly a three- to five-year minimum for transaction-related records, which explicitly includes email in most states. Confirm your state’s specific requirement, and consider retaining longer than the minimum since claims can sometimes surface years after closing.

Is it safe to migrate email during an active transaction? It’s avoidable risk rather than an outright ban. The safer approach is to schedule migrations around active closings, holding mailboxes with deadlines in the next 5-7 business days until after the transaction closes or moving them first with dedicated support standing by.

Can wire fraud happen because of the migration itself? The migration doesn’t create wire fraud risk on its own, but the disruption and client communication around it (new email addresses, temporary access issues) can be exploited as cover for a BEC attempt. Sending clients a clear, written notice that wiring instructions will never change by email closes that opening.

Do we need to notify clients before migrating? It’s strongly recommended for anyone in an active transaction. A short notice covering the migration date and a reminder that wiring instructions never change by email protects both the client and the brokerage.

What happens to shared mailboxes like offers@ or listings@ during migration? These need to be mapped and recreated deliberately, not assumed to transfer automatically. Document who has access to each shared mailbox before migration and verify the same access exists immediately after cutover.

Should DMARC and SPF be set up before or after migration? Before, or as part of cutover, whenever possible. Since BEC is the dominant fraud vector in real estate, domain authentication is worth prioritizing rather than treating as a later cleanup task.

Does moving from Google Workspace to Microsoft 365 (or vice versa) affect our e-signature integrations? Yes, DocuSign, Dotloop, SkySlope, and similar platforms typically need their email integration re-authorized against the new platform. Test this with a live (non-binding) document before agents rely on it for an actual transaction.

Want to see more content like this? Add us as a Preferred Source on Google to see more of our articles when you search.