Extracting Email Addresses from EML Files, MSG Files, Outlook PST Archives, Thunderbird MBOX Files and Email Backup Archives
By Email ExtractorPublished 8 min read
On this page
Email Archive Formats
Email archives store years or decades of correspondence, and the email addresses contained in them -- in headers (From, To, CC, BCC, Reply-To), message bodies and signatures -- represent a comprehensive record of an organisation's or individual's communication network. Extracting these addresses is necessary for contact recovery (rebuilding a contact list after a system failure), data migration (moving between email platforms), compliance audits (identifying all parties in communications during an investigation), mailing list reconstruction (recovering subscribers after a platform failure) and correspondent analysis (understanding communication patterns):
Format
Extension
Created by
Structure
Size range
EML
.eml
Any email client that exports individual messages; Thunderbird, Windows Mail, Apple Mail; email server exports; litigation hold software; Email Extractor supports this format
One file per email message; plain text (RFC 5322 format) with MIME-encoded attachments; human-readable headers (From, To, Subject, Date) followed by message body
1 KB-50+ MB per file (depending on attachments); a folder of EML files can range from MBs to hundreds of GBs
MSG
.msg
Microsoft Outlook (Windows); saving or dragging individual messages creates .msg files; Email Extractor supports this format
One file per email message; Microsoft proprietary binary format (OLE Compound Document); contains message properties, body text, attachments
1 KB-50+ MB per file; similar to EML but in Microsoft's binary format
MBOX
.mbox
Thunderbird, Apple Mail, Gmail (Google Takeout export), many Unix/Linux email systems; a standard format for email archive portability; Email Extractor does not directly support MBOX (convert to individual EML files first)
Single file containing multiple email messages concatenated together; each message starts with a "From " line (note the space); messages are separated by blank lines
1 MB-10+ GB per file (a single MBOX file may contain thousands of messages)
PST
.pst
Microsoft Outlook (Windows); Outlook data files for local storage; archive files; also exported from Exchange for compliance/litigation
Single file containing an entire mailbox: folders, messages, calendar items, contacts, tasks, journal entries; Microsoft proprietary format; can be password-protected
100 MB-50+ GB per file; older PST format (ANSI) limited to 2 GB; newer format (Unicode) supports up to 50 GB
OST
.ost
Microsoft Outlook; offline cache of an Exchange or Microsoft 365 mailbox
Local cache of server mailbox; similar structure to PST but tied to a specific Outlook profile; automatically regenerated from server
Similar to PST in size
EDB
.edb
Microsoft Exchange Server; the server-side database containing all mailboxes on that server
Exchange database format; contains all mailboxes, public folders and transport data for a server
10 GB-1+ TB; enterprise-scale
What Email Extractor Supports
Email Extractor directly processes the following email archive formats:
Format
Support
What it extracts
Limitations
EML
Yes (supported file type)
Email addresses from message headers (From, To, CC, Reply-To) and message body text; email addresses in plain text and HTML body content
Does not extract email addresses from attachment contents (e.g., a PDF attached to the EML); upload attachments separately
MSG
Yes (supported file type)
Email addresses from message properties and body text; email addresses in plain text and HTML body content
Does not extract email addresses from attachment contents; upload attachments separately
MBOX
Not directly supported
N/A
Convert MBOX to individual EML files first (see conversion steps below); then upload the EML files
PST
Not directly supported
N/A
Export messages from PST as individual EML or MSG files using Outlook or a PST viewer; then upload the exported files
Extraction Workflows
EML files
Step
Action
Details
1. Collect EML files
Gather EML files from: email client exports, email server exports, litigation hold collections, backup archives, forensic image extractions
EML files may be in a flat folder or organised in a folder hierarchy (by date, sender, folder name)
2. Upload to Email Extractor
Upload EML files to Email Extractor; you can upload multiple files at once (up to 25 MB per file, 100 MB per batch)
Email Extractor extracts email addresses from the message headers and body of each EML file
3. Review results
Download results as CSV with sources; the source column shows which EML file each email address came from
Header email addresses (From, To, CC) represent direct correspondents; body email addresses may be signatures, forwarded content, or mentions
4. Deduplicate
Email Extractor automatically deduplicates across all uploaded files; the result is a unique list of all email addresses found across all messages
A mailbox with 10,000 messages may contain 50,000+ email address instances but only 500-2,000 unique addresses
MSG files
Step
Action
Details
1. Collect MSG files
Gather MSG files from: Outlook saved messages, email archiving systems, litigation hold exports, backup folders
MSG files are created when a user saves an email from Outlook or when archiving software exports from Exchange
2. Upload to Email Extractor
Upload MSG files to Email Extractor; same batch limits as EML files
Extracts from message properties (sender, recipients) and body text
3. Review and deduplicate
Same as EML workflow
Same deduplication and source-tracking capabilities
MBOX files (conversion required)
Step
Action
Details
1. Identify MBOX files
MBOX files from: Thunderbird (profile folder > Mail > [account name] > Inbox, Sent, etc. -- files without extension); Apple Mail (File > Export Mailbox); Gmail (Google Takeout > Mail); Unix/Linux mail servers
Thunderbird stores each folder as an MBOX file without the .mbox extension; the file named "Inbox" (no extension) is an MBOX file
2. Convert MBOX to EML
Use a tool to split the MBOX file into individual EML files; options: (a) Thunderbird: install the ImportExportTools NG add-on > right-click folder > Export all messages > EML format; (b) command-line tools: Python script using the mailbox module; (c) desktop tools: MBOX Viewer, Aid4Mail, SysTools MBOX Converter
Conversion creates one EML file per message; a large MBOX file (5 GB, 50,000 messages) will produce 50,000 EML files
3. Upload EML files to Email Extractor
Upload the converted EML files to Email Extractor in batches (up to 100 MB per batch)
Process in batches if the total exceeds 100 MB; the tool deduplicates across all batches
PST files (export required)
Step
Action
Details
1. Open PST in Outlook
Open the PST file in Microsoft Outlook (File > Open > Outlook Data File); the PST appears as a separate mailbox in the folder pane
If you do not have Outlook, use a free PST viewer (Kernel PST Viewer, SysTools PST Viewer) that can export messages
2. Export messages as EML or MSG
In Outlook: select messages (Ctrl+A for all in a folder) > drag to a Windows folder (creates MSG files); or use an Outlook add-in to export as EML. In a PST viewer: use the export function to create EML or MSG files
Exporting large PSTs (10+ GB, 100,000+ messages) takes time; export folder by folder if needed
Same extraction and deduplication as direct EML/MSG workflows
Use Cases
Use case
What you need
Workflow
Contact recovery after system failure
CRM or contact database lost; email archive (PST, MBOX, EML backups) is the only remaining source of contact email addresses
Export/convert archive to EML/MSG > upload to Email Extractor > extract and deduplicate > result is a recovered contact list to rebuild the CRM
Email platform migration
Moving from Outlook/Exchange to Gmail/Google Workspace (or reverse); need to identify all correspondents for address book migration
Export from source platform > extract all correspondent email addresses > import as contacts in the new platform
Mailing list reconstruction
Email marketing platform failure or account cancellation; subscriber list not backed up; but sent emails are in the email archive
Extract email addresses from sent mail archive (all "To" addresses in sent items are subscriber candidates) > verify extracted list > import to new platform
Compliance audit / eDiscovery
Legal or regulatory requirement to identify all parties in communications during a specific time period
Export relevant messages by date range > upload to Email Extractor > the unique email list represents all communication parties during the period
Correspondent analysis
Understanding who an organisation or individual communicated with; network mapping; key relationship identification
Extract all email addresses from the complete archive > analyse frequency (which addresses appear most often = most active correspondents); analyse by time period to see relationship changes
Legacy archive mining
Organisation has email archives from 5-15 years ago on legacy systems (old PST files, backup tapes restored to EML); need to find contact information for historical projects, former clients, former employees
Restore archives > convert/export to EML/MSG > upload to Email Extractor > search results for specific domains or name patterns
Volume Expectations
Archive size
Approximate messages
Expected unique email addresses
Processing approach
Under 100 MB
500-5,000 messages
50-500 unique addresses
Single upload batch
100 MB - 1 GB
5,000-50,000 messages
200-2,000 unique addresses
1-10 upload batches
1 GB - 10 GB
50,000-500,000 messages
1,000-10,000 unique addresses
Multiple sessions; convert/export in batches; upload in 100 MB batches
10 GB+
500,000+ messages
5,000-50,000+ unique addresses
Convert/export in batches; process over multiple sessions; consider extracting from specific folders (sent items, inbox) rather than the entire archive for efficiency