logo
search
Others

Why Microsoft Purview Content Search is Larger Than an Exchange Mailbox

Olivia MillerOlivia Miller Sep 25, 2026 869 views

Question details

Understand the reasons behind the significant size discrepancy between a standard Exchange mailbox and the data reported by Microsoft Purview Content Search.

Why Microsoft Purview Content Search Reports a Larger Size Than an Exchange Mailbox
Product
Microsoft Purview
Device & OS
not provided
Scenario
Performing an eDiscovery or Content Search in Microsoft Purview for litigation or data export.
Observed behavior
An Exchange mailbox reports a size of 9.8 GB, but Microsoft Purview Content Search reports 57 GB for the exact same mailbox, even after explicitly excluding SharePoint and Teams data.
Before you start

Verify your Microsoft Purview search query parameters and export settings to ensure you are not unintentionally including secondary archive mailboxes or unindexed items in your size estimates.

Solution 1Recommended

Understand Purview Data Calculation and Hidden Items

Identify the common architectural differences that cause Purview to report significantly more data than standard Exchange mailbox storage metrics.

Microsoft Purview Content Search scans deep into a mailbox's architecture, including data that a standard Exchange mailbox size calculation often ignores. This leads to a much larger reported size during eDiscovery.

1
Account for Uncompressed Export Data

Exchange server data is highly compressed to save storage. When Purview runs a search or estimates an export, it calculates the uncompressed size of the data and attachments, which is naturally much larger.

2
Check the Recoverable Items Folder

Purview searches include the 'Recoverable Items' folder (Deletions, Purges, DiscoveryHolds, and Versions). If a mailbox is on Litigation Hold, this hidden folder can grow massively and will be included in the Purview size, but not in the standard user mailbox size.

3
Identify Hidden Mailbox Data

Content Search includes hidden diagnostic files, inbox rules, system messages, and audit logs stored inside the mailbox that are completely invisible to standard size reporting tools and the end user.

4
Verify Archive Mailboxes

Check your eDiscovery settings to see if the search is pulling from the user's Online Archive mailbox simultaneously. This data counts towards the search total but is not reflected in the primary mailbox size.

Understand Purview Data Calculation and Hidden Items
Cached Outlook Size: Do not rely on the local OST file size in Outlook to determine mailbox size. Cached mode often only downloads recent emails (e.g., the last 12 months), making the local file much smaller than the actual server mailbox.
Free Microsoft Office alternative

Manage Your Exported Reports and Data Easily with WPS Office

While WPS Office cannot directly alter Microsoft Purview server configurations, it is an excellent, lightweight alternative for opening, reviewing, and analyzing large CSV or Excel export logs generated during your eDiscovery process.

  1. 1. Open WPS Spreadsheet: Launch WPS Office on your computer and select the 'Spreadsheet' module.
  2. 2. Import the Purview Export Log: Click 'Menu' > 'Open' and locate the CSV or Excel summary report generated by your Purview Content Search.
  3. 3. Analyze the Data: Use the built-in Data filtering and PivotTable tools to isolate errors, locate hidden folders, and analyze why the size discrepancy occurred.
Fully compatible with Microsoft Excel (.xlsx) and CSV formats used in Purview export logs.Lightweight architecture handles large eDiscovery datasets smoothly without lagging.Free Microsoft Office alternative with a familiar, easy-to-navigate interface.Built-in PDF tools to help you prepare and share litigation or compliance reports securely.
microsoft office alternative - wps office

Frequently Asked Questions

Does Purview Content Search include Teams chat data by default?

Yes. One-on-one and group Teams chats are stored in a hidden folder within the participants' Exchange mailboxes. Unless specifically excluded in the query, Purview will pull these records, inflating the mailbox search size.

How can I check the size of the hidden Recoverable Items folder?

You can connect to Exchange Online via PowerShell and run the 'Get-MailboxFolderStatistics -Identity <User> -FolderScope RecoverableItems' cmdlet. This will reveal the true size of the hidden data that Purview is capturing.

Why is my exported PST file larger than the Purview search estimate?

Search estimates often approximate the compressed size or omit certain overhead data. Once exported, the PST file contains uncompressed data, complete folder structures, and unindexed items (if selected), resulting in a significantly larger file.

Are unindexed items included in Purview search totals?

If you choose to include unindexed items in your search results or export settings, Purview will add items it cannot read (like encrypted files or unrecognized formats) to the total, heavily increasing the final reported size.