Skip to content

Managing mailboxes

A mailbox is a real inbox on your own domain: an address, a password, and storage. It signs in to webmail and to any mail client over IMAP, POP3, SMTP or JMAP. This guide covers the day-to-day work of running them — creating a mailbox, changing its settings, and taking one away — inside a mailspace that is already set up.

Mailboxes are not the only kind of address a mailspace holds. Aliases, groups, mailing lists and masked emails all deliver into mailboxes without being mailboxes themselves, and each mailbox can also have its own mail rules and an out-of-office reply. Those live on their own pages; this one is about the mailboxes.

Before you start

  • A finished mailspace. Every mailbox page needs the mailspace to be verified and created first. If it isn't, the dashboard sends you to the domain verification page instead of the mailbox screens — see Verifying your domain.
  • A role that can edit this workspace. Creating, changing, deleting and restoring a mailbox are all edit actions. A member whose role can't edit is turned back with You do not have permission to perform this action.
  • Room in your plan. Your mail package sets how many mailboxes the mailspace may have. When they're all used, creating another is refused with a message naming the limit and your package; the same check applies when you restore a mailbox.

Create a mailbox

  1. Open the mailspace. Choose Mailspace in the workspace sidebar, then open the mailspace you want. Its Overview page opens first.

  2. Start a new mailbox. Click New Mailbox in the page header. Three other routes reach the same form: the Mailboxes figure in the overview's stat row has a Manage link, the Recent Mailboxes card has View All — both of which land on the mailboxes list, which carries its own New Mailbox button — and while you have no mailboxes at all, the Recent Mailboxes card shows No mailboxes yet with Create your first mailbox to get started. and a New Mailbox button of its own.

  3. Enter the address. Under Email address, type the part before the @ — the hint reads The address and login for this mailbox. If the mailspace has one domain, that domain is shown beside the field; if it has several, pick one from the Domain selector next to it.

    The form checks the address as you type and says either that <name>@<domain> is available or that it is already used by something. Addresses are shared across the whole mailspace, so a name can be taken by a group, a mailing list or an alias rather than by another mailbox — the message names which. Both create buttons gray out while the address is known to be taken, so the way forward is to change the name.

  4. Set a display name. Display name is Shown as the sender name on outgoing mail. Leave it and the form fills in a guess from the address as soon as you move on; anything you type yourself is kept as-is.

  5. Set a password. This is the mailbox's own sign-in password — for webmail and for mail clients. Type one under Password, or click Generate for a strong random one. A meter under the field rates what's in it (Weak, Fair, Good or Strong), and Copy password copies it once the field has a value.

  6. Choose a quota. Quota caps how much storage this one mailbox may use. Unlimited is ticked by default, which lets the mailbox draw on the mailspace's whole storage pool rather than a slice of it; untick it to cap this mailbox in GB or MB. The hint beside the field is a summary of your package rather than advice about this mailbox — it reports the package's total storage, how much of it is in use, and how many mailboxes you've used of the number the package allows. A cap larger than the package's total storage is refused when you submit.

  7. Turn on two-factor authentication, if you want it. Optional, and off unless you ask for it: require a rotating code from an authenticator app at sign-in. Click Set up two-factor authentication to reveal a QR code to scan, plus the same key in text for apps that want it typed. Save it before you submit — it won't be shown again after the mailbox is created. Cancel 2FA setup backs out.

    App passwords shows only Only available after creation here; they're minted against an address that doesn't exist yet.

  8. Add memberships, if you want them. Three cards at the bottom — Groups, Aliases and Mailing lists — let you attach the new address as you create it. A card with nothing to pick offers to create one instead (for example No groups on this domain yet. with Create a group).

  9. Create it. Create mailbox saves and returns to the mailboxes list with a confirmation naming the address. Create and add another saves and hands you a fresh blank form, which is the quicker path when you're setting up a whole team. Cancel leaves without saving.

Change a mailbox

  1. Open the mailboxes list. From the mailspace, choose Mailboxes. The list is headed All mailboxesMailboxes with IMAP/SMTP access and webmail login. — with a filter box (Filter mailboxes by address…) and a row per mailbox showing Mailbox, Display Name and Storage. A Webmail button sits on each row; it's disabled until the domain's webmail record is in place, and its tooltip says where webmail will open. A suspended mailbox carries a Suspended badge.

  2. Open the mailbox. Open the row's actions menu (the ⋮ button at the end of the row) and choose Edit mailbox. The same menu holds Mail rules for that mailbox and Delete mailbox.

  3. Make your changes. The settings form covers:

    • Display name — the sender name.
    • PasswordLeave blank to keep the current password. Generate and the copy button work as they do on the create form.
    • Status — a switch between Active and Suspended. Suspending blocks sign-in and mail delivery without deleting the mailbox.
    • Quota — the same limit control, plus a line reporting how much the mailbox is using.
    • Two-factor authentication — set it up here if it isn't on, or Remove 2FA…, which asks to confirm and warns that the user will need to set it up again.
    • Sign-in IP restriction — one or more addresses or CIDR ranges that the mailbox's own password may be used from; empty allows any address.
    • App passwords — separate credentials for mail clients and apps.
    • Groups, Aliases and Mailing lists — the same three cards as on the create form, showing what this address currently belongs to.

    The Email address itself is fixed: This address can't be changed. To move mail to a different address, add an alias, or create the new mailbox and remove the old one.

  4. Save. Click Save changes. If the save is refused, the form comes back with the reason and keeps what you typed. A save that carries a new password also asks you to confirm your identity with your passkey or password, if you haven't recently — other saves don't.

The IP restriction is silent when it refuses

A sign-in from anywhere else is refused without being told the address is why — the person sees a permission or connection error, not a wrong password. Only set it for a mailbox on a fixed connection.

App passwords

Adding an app password asks you to confirm your identity, shows the secret exactly once, and reloads the page — so save any other pending changes first. Existing ones can be given their own IP restriction, or revoked, which stops any client signed in with it. See Connecting a mail client for when to use one.

Remove a mailbox

Deleting a mailbox is deliberately hard to do by accident. Nothing is erased the moment you click, and there are two chances to change your mind.

  1. Delete the mailbox. In the mailboxes list, open the row's actions menu and choose Delete mailbox. The confirmation is headed Delete {address}? and explains what happens: the mailbox is suspended immediately and scheduled for permanent deletion after a grace period — currently seven days, and the dialog names the exact number. You can restore it any time before then.

  2. Find it under Scheduled for deletion. The mailbox leaves the main list and appears in a Scheduled for deletion card below it: Suspended now — permanently removed after the {n}-day grace period. Restore any of them before then. Each row carries a countdown badge (Deletes in {n} days, or Deletes today) and two buttons.

    • Restore cancels the scheduled deletion and switches the mailbox back on straight away. Its password, email, aliases and memberships are unchanged. A restore can be refused if your package's mailbox limit is already full — the message says so, and names the package.
    • Delete now deletes the mailbox and all of its email immediately and permanently. It asks you to confirm your identity first. This is also how you free up a mailbox slot at once instead of waiting out the grace period.
  3. If the grace period runs out, the mailbox is deleted for you. It then moves to a Recently deleted card: These mailboxes were deleted, but the mail server still has their email. Restore one and it comes back with everything in it — you'll set a new password. Rows show when the mailbox was deleted and a countdown to when the mail server erases it (Erased in {n} days, or Erased today).

    If that check against the mail server can't be made, the card is still there and says so: We couldn't check with the mail server which recently deleted mailboxes can still be restored. Reload the page in a moment to try again. — and the same sentence appears as a banner at the top of the page. The card stays visible on purpose — a card that disappeared would read as "nothing left to restore", which is exactly what couldn't be established. The condition is temporary and doesn't mean the mail is gone; reloading the page is the right response.

  4. To bring one back from Recently deleted, click Restore. The page that opens is headed What comes back and tells you the date until which the mail is still held. It lists the address, display name, mailbox size, aliases, and groups and mailing lists — memberships are re-added where they still exist, and the size is restored as it was or trimmed to fit your current plan. A recovered mailbox comes back with no password, so set a New password on that page (or Generate one), then click Restore mailbox.

    Once the mail server has erased it, the restore is gone: the attempt is refused with That mailbox can no longer be restored — the mail server has erased it. If a new mailbox has since taken the address, you're told to delete or rename that one first.

Delete now has no second chance

Delete now expedites the erase, so a mailbox removed that way never appears under Recently deleted and cannot be recovered. Waiting out the grace period leaves you the second window; Delete now doesn't.

Next steps

  • Hand out the new addresses and have people sign in — see Connecting a mail client.
  • Add the shared addresses your team needs: aliases, groups and mailing lists all sit in the mailspace's own sidebar.
  • Set up per-mailbox mail rules and an out-of-office reply from the mailbox's row menu, once the mailbox is in use.
  • Watch the Mailboxes figure on the Overview page as you go — it shows how many of the mailboxes your package allows are in use, and Upgrade Package on the Package card is where you go for more.