MailFundus Archive · Support · Privacy · Legal notice · Deutsch
Empty mailbox. Keep everything. Find it instantly.
MailFundus Archive takes the messages out of Apple Mail, stores them byte for byte in an archive, verifies every single one of them, and only then cleans up in Mail. Nothing is deleted that has not first been read back and compared with the original.
The whole process sits behind one menu item: Archive → Back Up to Archive…, shortcut ⇧⌘L, also a button in the toolbar. It walks you through five steps and stops wherever a decision is yours to make.
| Step | What happens |
|---|---|
| Select | You pick the mailboxes and, if you like, an age limit. MailFundus shows count and size. |
| Back up and verify | The messages go into the archive and are checked byte for byte against the original. Missing attachments are filled in and the search index is built, both automatically. Mail stays untouched. |
| Delete from Mail | Only now, and only what has been verified byte for byte. MailFundus lists the verified mailboxes with message counts. You confirm with “Move to Mail's Trash”, and MailFundus moves exactly those messages to Mail's Trash, verifying each one against the archive once more right before. Anything not verified byte for byte stays in Mail. |
| Trash | The verified messages now sit in Mail's Trash. Only you can empty it, in Mail: Mailbox → Erase Deleted Items. Only then does disk space become free. Afterwards click “Trash Emptied, Update Now”: MailFundus asks Mail what is really gone and records it in the archive. |
| Done | Three answers: what was backed up, what is out of Mail, and where you find it now. |
macOS protects the folder in which Mail keeps its messages. That is why the first launch starts with the page “Before You Begin”: one click opens an Open dialog with Mail's folder already selected, and “Grant Access” is all it takes. MailFundus only reads there. It writes only to the archive. The grant stays in place for the next launches and ends when you remove the app.
If MailFundus ever loses that access, it shows “Grant Access to Mail's Folder…” again before it goes on.
An archive is a package named Name.fundus. It is made of blocks that are
written once and never changed afterwards. That is why Time Machine backs up only what is
new on each run, not everything all over again.
The save dialog starts in your Documents folder. An external drive is just as good. Do not put the archive inside Mail's own folder.
In the first step you pick the mailboxes. Count and size are shown next to each one. Below that you set what counts as old enough for the archive:
MailFundus remembers your choice for the next run. Messages without a readable date are included rather than skipped. Leaving them out would be the riskier assumption.
Every message is stored, read back from the archive, and compared byte for byte with what Mail has on disk. At the end, MailFundus restores a random sample and compares that too: the sample restore. Mail is not changed in this step.
You can stop a run at any time with Stop Safely. What has been read is sealed and stays valid in the archive. Mail is untouched. The next run picks up where this one left off, without backing anything up twice.
This step opens on its own once the verification has passed. As soon as it opens, MailFundus asks Mail which accounts and mailboxes exist, to build the preview. That is the moment macOS asks for permission the first time, see below.
At the top stands the line that sums it up: how many messages are archived and verified byte for byte, and that they are safe to delete from Mail now. Below it is the list of mailboxes that are backed up and verified, with the number of messages in each. A mailbox marked not everything, only the verified ones still holds messages that MailFundus will leave in place. That is deliberate, see below.
Confirm with “Move to Mail's Trash”, and MailFundus asks Mail, through Mail's own scripting interface, to move exactly those messages to Mail's Trash. Nothing is deleted permanently. Everything is still in Mail's Trash until you empty it.
The first time the step “Delete from Mail” opens, macOS asks once: “MailFundus Archive” would like to control “Mail”. This is the macOS Automation permission. Click Allow, and the preview appears.
MailFundus uses this permission to read account and mailbox names and message identifiers for the preview, to move the messages you confirmed to Mail's Trash, and for “Show in Mail” in a mailbox's context menu. It never reads message contents this way, never sends mail, never empties the Trash, and never deletes anything permanently.
Only Mail can empty its Trash. Until you do, not a single byte is free. In Mail: Mailbox → Erase Deleted Items.
Before you do, look at the warning MailFundus shows if the Trash also holds messages that are not in the archive. Those would be gone for good.
Afterwards click “Trash Emptied, Update Now”. MailFundus asks Mail what has really disappeared and reads each of those messages from the archive once more before it records them as deleted.
In the step “Delete from Mail”, the second button “Delete in Mail Yourself…” skips the automatic move. MailFundus shows you the verified mailboxes and the three steps in Mail:
Then click “Deleted in Mail, Check Now”. MailFundus checks what is really gone from Mail and reads each of those messages from the archive once more before it records them as deleted. That way the archive knows what left Mail even though MailFundus did not move it. You can catch up on deleting at any time, from the card in the main window or from Archive → Advanced → Delete Archived Messages from Mail….
A mailbox rarely ends up completely empty, and that is not a bug:
MailFundus leaves these where they are and names them. Better a remainder that is explained than a deletion that is not proven.
After a run, the card at the top of the main window shows two lines. The first counts messages, for example “42 messages archived and fully verified”. The second counts locations, for example “59 locations incl. 17 duplicates · only as files in Mail's folder now: 17 · in Mail's Trash: 1 · deleted from Mail: 41”. Depending on where things stand, it also shows “still in Mail: N” and “without attachment: N”.
Here is the difference. The archive stores every message exactly once. It recognizes byte-identical content, even when it sits in Mail more than once. On top of that, it remembers every location where the message was found. A mailbox with 59 files and 42 different messages therefore yields 42 messages and 59 locations. 17 of those locations are duplicates.
The second line counts locations, not messages. Its total can therefore be larger than the number in the first line. That is not an error. Nothing is missing, and nothing is stored twice in the archive.
Mail keeps its own index. What Mail shows in a mailbox is not always what sits in Mail's folder on disk. After cleaning out junk, after an import, or after “Mailbox → Rebuild”, a mailbox can be empty in Mail while the files are still in Mail's folder. Mail often removes such files only after a delay.
MailFundus reads the disk. That is how it also finds what was forgotten. In addition, it reads Mail's index. No system dialog is needed for that. Files that Mail no longer lists appear on the card as “only as files in Mail's folder now”.
Deleting through Mail works only for messages Mail shows. If a mailbox holds nothing but such files, the step “Delete from Mail” says so: “Nothing can be deleted: Mail no longer lists these N messages in any mailbox. The files are still in Mail's folder, but as far as Mail is concerned they are already gone, so nothing can be moved through Mail. They are safe in the archive.”
You have two options. Select the mailbox in Mail and choose “Mailbox → Rebuild”. After that, Mail lists the files again, and MailFundus can move them to Mail's Trash. Or leave the files where they are. They are safe in the archive.
Duplicates appear in Mail more easily than you might think. An import through “File → Import Mailboxes…” creates every message anew, even if it is already there. Mail does not check. “Mailbox → Rebuild” writes the files under new names.
The archive does not do that. MailFundus recognizes the content and never stores byte-identical messages twice. It only records the additional location. On the card, such cases show up as duplicates among the locations. The same applies to messages you bring back from the archive into Mail, see “Back to Mail”.
An archive from before content recognition can contain duplicates. Leave nothing out, and “Shrink Archive…” in the menu Archive → Advanced rebuilds the archive without duplicates. The locations are kept.
The step “Delete from Mail” moves only what has been verified byte for byte and what Mail shows. If something in a mailbox is left over, the step names the reason. These are the reasons, and what you can do:
| Reason | What you can do |
|---|---|
| “Mail doesn't know this file (orphaned or not yet cleaned up)” | The file is in Mail's folder, but Mail no longer lists it. Select the mailbox in Mail, choose “Mailbox → Rebuild”, then delete again. Or leave it. The message is safe in the archive. |
| “not in the archive” | The message is not archived. MailFundus never deletes what is not archived. First back up the mailbox with “Back Up to Archive…”. |
| “changed in the source since archiving” | The message in Mail is no longer byte-identical to the archive. Back it up again, then delete. |
| “no longer present in the source” | The file has since disappeared from Mail's folder. There is nothing left to delete. The message is safe in the archive. |
| “already removed from the source at this location” | This location is already done. Nothing to do. |
| Attachments never downloaded | The message is backed up but incomplete. When deleting, it deliberately stays in Mail. Open it once in Mail, then back it up again. |
If Mail no longer lists any of the remaining files, the step says so in one sentence. The section “What Mail shows and what is on disk” explains that case. What else Mail keeps is listed under “What stays in Mail on purpose”.
MailFundus moves messages to Mail's Trash only after you confirm, and only what has been verified byte for byte. In the Trash, the messages are still on disk. Disk space becomes free only when you empty the Trash in Mail: Mailbox → Erase Deleted Items.
Before you do, MailFundus looks into the Trash. If it holds messages that did not come from MailFundus and are not in any archive, it warns you: “Note: The Trash also holds N messages that did not come from MailFundus and are not in any archive. Emptying the Trash would delete them for good. To keep them, move them back into a mailbox in Mail first.” Take that warning seriously. Whatever you want to keep, move it back into a mailbox in Mail before you empty the Trash.
After emptying, click “Trash Emptied, Update Now”. MailFundus reads every message that has disappeared from the Trash once more from the archive and only then records it as deleted.
Mail moves the messages one by one. Depending on the size of the mailbox, this takes a few minutes. The counter in MailFundus keeps up as it goes. “Stop Safely” exists only while backing up. Deleting runs through, mailbox by mailbox. Simply let MailFundus and Mail work during that time.
Everything else follows from that:
For exactly that case there is the Activity History, ⇧⌘C. It lives outside the archives and therefore outlives them. It records which mailbox was backed up when and into which archive, and whether that archive can still be found.
Archive → Restore to Mail…, ⇧⌘R, writes messages back out as
.mbox or .eml files and shows them in the Finder. An
.mbox can be read into Mail with File → Import Mailboxes…. The
messages then appear under “Import”. An .eml opens in Mail with a double-click.
Single messages are quicker: select the message, then ⌘E for the
.eml or ⇧⌘A for all attachments. Both are byte-identical to what
was stored.
“Restore to Mail…” writes the files and shows them in the Finder. The way into Mail
is your step: an .mbox through “File → Import Mailboxes…”, an
.eml with a double-click. MailFundus does not touch Mail for this.
If the original is still in Mail, the import creates a copy. Mail does not check whether the message is already there. So bring back only what is missing in Mail. If you back up the mailbox again later, MailFundus recognizes the copy by its content and does not store it twice.
⌘F jumps to the search field. Search covers subject, sender, body, and the text of attachments, including what is inside PDF attachments. If a hit is in an attachment, the results list says so. Accents and spellings do not matter: “Zürich” also finds “Zurich”.
Filters sit next to the search field: mailbox, year, and “with attachment only”. Press Space on a selected attachment to open it in Quick Look, just like in the Finder. ⌘Y does the same.
MailFundus claims nothing it has not checked. Under Archive → Verification Logs…, ⇧⌘P, every run lists how many messages were read, stored, and compared byte for byte, whether the count check and the sample restore passed, and which messages were removed from Mail.
For your accountant or the tax office there is a Verification Report. The Support Diagnostics next to it deliberately contain no mailbox names, so you can pass them on.
Archive → “Verification Logs…” shows, for every run, what MailFundus did and checked. The most important lines and what they mean:
| Line in the log | What it means |
|---|---|
| When deleting | |
| N specific messages from “mailbox” scheduled | That many messages were selected for moving in the preview. |
| N confirmed byte-identical in source and archive right before moving | Each of them was checked against the archive once more, right before the move. |
| N moved to Mail's Trash and recorded per location | That many were moved by Mail. The archive knows it for every location. |
| N messages left alone: Mail returned no unique result for their number | These stay in Mail. Better one too few than the wrong one. |
| “N blocked by the fresh check” | Something changed between the preview and the deletion. Simply start the run again. |
| After emptying the Trash | |
| N gone from Mail's Trash, M still there | What Mail reports as gone, and what still sits in the Trash. |
| N read back byte for byte from the archive before recording | Only after this read is a message recorded as deleted. |
| When backing up | |
| N locations belonged to messages already in the archive, byte for byte. Only the location was recorded, nothing was stored twice. | Known content at another location. Nothing was stored twice. |
| Nothing new — all N messages were already in the archive, verified byte for byte. | The second run over the same mailbox reports this. It is the expected result, not an error. |
MailFundus Archive is free to download. The free version backs up your first 500 messages, with every feature: backing up, verifying byte for byte, searching, deleting from Mail. The full version removes the free limit. It is a one-time purchase in the app, no subscription, and it applies on every Mac that uses the same Apple Account.
Only messages that are new to the archive count, across all your archives together. Whatever is already in the archive does not count again when you back up again. The same goes for byte-identical messages in another mailbox: MailFundus then only records the additional location. If you back up the same messages into another archive, they are new there and count. What has been backed up stays counted, even if you throw the archive away later. The guided path shows how many messages are left in the step “Select”, before anything is backed up.
A run that reaches the limit ends normally, not with an error. Everything backed up until then is verified byte for byte, is searchable, and can be deleted from Mail. The remaining messages stay in Mail, unchanged. The guided path tells you that the free limit is reached and offers “Full Version…”. Once the free version is used up, “Full Version…” appears where “Back Up and Verify” would otherwise be. After the purchase, the next run backs up the rest without storing anything twice.
Even without a purchase, and even past the free limit, you can open, read,
and search archives, export messages and attachments as .eml or
.mbox, restore messages to Mail, and read the verification logs and
the log inside the archive. No one has to pay to get at their own mail.
You buy the full version from the app menu, MailFundus Archive → Full Version…, or in the guided path once the free version is used up. The app shows the price before you buy, as the App Store reports it for your country. You pay through your Apple Account.
On another Mac with the same Apple Account, MailFundus usually recognizes the purchase on its own. If the app still shows the free version after a purchase, for example after reinstalling, choose MailFundus Archive → Restore Purchases…. You are not charged again.
If you bought MailFundus Archive 1.0, you get the full version automatically, without a second purchase. You need to be signed in to the App Store with the Apple Account you bought 1.0 with. If the app still shows the free version, “Restore Purchases…” helps.
Every archive keeps its own log as a plain text file, readable without MailFundus: Log.txt sits right inside the archive package (right-click the archive → “Show Package Contents”). Every completed run appends an entry: date and time, mailboxes, age limit, result, the numbers (read, stored, verified byte for byte, already present) and, for deletions, how many messages were scheduled and confirmed removed. The file is only ever appended to, never rewritten.
For every backup run, the runs folder holds a file with one line per message: sent, from, subject, mailbox. It appears once the run's messages have been made searchable, because only then does the archive know subject and sender. Archives from earlier versions get both the next time they are opened. If MailFundus runs in German, the file is named Protokoll.txt; an existing file keeps its name.
Backed up a mailbox you do not want to keep after all, such as junk or old newsletters? Archive → Advanced → Shrink Archive… builds a new archive without the mailboxes you check. MailFundus shows beforehand how many entries carry over, how many are dropped, and how many messages would be gone for good because they exist nowhere else. The old archive is not changed. Delete it yourself once you are happy with the new one.
| ⌘0 | Main Window (Window menu): reopens the window after you have closed it. MailFundus keeps running after the window closes so that a backup run is not cut off. |
| ⌘F | Search |
| ⌘O | Open Archive… |
| ⇧⌘N | Set Up New Archive… |
| ⇧⌘L | Back Up to Archive…, the guided path |
| ⇧⌘R | Restore to Mail… |
| ⇧⌘P | Verification Logs… |
| ⇧⌘C | Activity History… |
| ⌘E | Save As .eml |
| ⇧⌘A | Save All Attachments |
| ⌘Y | Quick Look Attachment |
| Space | Preview the selected attachment |