White-label webmail

Signing in to webmail

How a client's staff sign in to their mail door, and what each sign-in option does.

Where this lives. Sign in and open /mail/login in the app.

What it does

This is the sign-in page at your mail door (mail.theirbrand.com once you've set that up, or the shared address otherwise). It asks for an email address first, then works out what to do next: a mailbox signs in with its own password, a Google or Microsoft account signs in with one click, a colleague who joined with a work address gets a one-time code, and a stranger is either invited to join or told plainly that they can't. The page is server-rendered with your brand, so a client's people never see anything with our name on it.

Before you start

You need the email address you sign in with. If your administrator created your mailbox directly, they gave you the address and a password. If your workspace allows people to join themselves, you only need a work email address. Throwaway and temporary addresses are always refused.

Set it up, step by step

  1. Go to the door's sign-in address and type your Email address, then click Continue. You can also skip straight to "Continue with Google" or "Continue with Microsoft" below the form.
  2. If your address is a mailbox, you land on a Password field. Type it and click "Open my mailbox." Check "Keep me signed in on this device" to skip sign-in next time on that device. Leave it unchecked on a shared or borrowed computer, since the session ends when you close the browser.
  3. If your address signed in with Google or Microsoft before, you see "Continue with Google" or "Continue with Microsoft." Click it and pick the account on the provider's own page.
  4. If you're a colleague with no password, the door emails a six-digit code to your address ("We sent a code to jane@theirbrand.com"). Type it and click Sign in. The code expires in ten minutes. Nobody, not your administrator, not support, will ever ask you for it directly.
  5. If your address isn't known yet and your workspace allows self sign-up, type Your name and click "Email me a code." Enter the six-digit code and choose a password (12 characters minimum), then click "Create my account" to finish. If your workspace requires an administrator's approval, you instead see a message that your account is waiting for one. You'll be able to sign in the moment it's approved.
  6. If two-factor sign-in is required for your mailbox, you're sent to set up an authenticator app the first time: scan the QR code (or type the key by hand) with Google Authenticator, Microsoft Authenticator, 1Password, or similar, enter the six-digit code it shows, click "Turn on two-factor," then save the recovery codes shown once. Each one signs you in a single time if you lose your phone. After that, every sign-in asks for a fresh code, or one recovery code if your phone is gone.
  7. To add a second mailbox from the same sign-in, open the mailbox switcher in the top bar and choose "Add another mailbox." A Google or Microsoft identity adds it through the provider; a mailbox sign-in adds it under Settings → Security, where you type the other mailbox's address and the app password your administrator issued for it.

What you should see

A successful sign-in lands you in your inbox. If your mailbox is suspended or blocked, you see the reason your administrator gave and a form to ask for it to be reactivated. It's filed as a support request they see next to your mailbox.

Common problems

"That address has a mailbox here — sign in with its password" means don't use Google or Microsoft for that address. "That address is already signed in another way" means try the button you used the first time. "That email domain cannot join this workspace" or "Accounts here are created by an administrator" means self sign-up is closed or restricted to certain domains, so ask your administrator for an invitation. A sign-in stopped for review shows "This sign-in was stopped for review. Your administrator can unlock it." See the administrator's console for how that's cleared.

Common questions

I did not get my one-time code. What now?

Check the junk folder first, then ask your administrator to resend it. Codes are short-lived by design, so an old one will not work.

Can I use one sign-in for two mailboxes?

Yes, when your administrator has granted it. Adding a mailbox asks for that mailbox's own permission, so nobody can attach an address they do not control.

Last updated September 19, 2026. Written by the team that operates the platform.

Signing In to Your Branded Webmail: Password, Google or Microsoft