White-label webmail

Webmail administration

What a client's own administrator controls in their mail door.

Where this lives. Sign in and open /mail/admin in the app.

What it does

This is the client's own administration screen, reached at their own address, wearing their own brand: everything a company running its mail here needs, without ever signing in to a screen with our name on it. It covers people (mailboxes and self-signed-up guests), what the security check stopped, who may join, privacy and masking, forwarding approval, Drive sharing, storage, and an activity log. Anyone signed in as a mailbox with the admin role sees a Shield icon in the top bar linking here; everyone else never knows the screen exists.

Before you start

You need to be signed in to a mailbox with the admin role. If you're not, the page tells you plainly: "This mailbox does not administer this workspace."

Set it up, step by step

  1. Read the counts at the top: Mailboxes, Signed up, Waiting, To review, and Blocked, plus a link to "Review deleted mail" showing how many copies are kept.
  2. Under "People with a mailbox," click "Add a mailbox" (Name, Address, Domain) for a direct mailbox, or "Connect a Google account" to link a real Gmail or Google Workspace mailbox instead; see Connect a Google account for that flow. Each row offers New password, Make admin or Remove admin, Suspend or Restore, "Many mailboxes" or "One mailbox" (lets that person attach others with their own app passwords), Sign out everywhere, Archive (keeps the mail, stops the sign-in), and Close (signed out everywhere, cannot sign in again, mail and address kept).
  3. Anyone waiting under "Waiting for you" proved their address already; click "Let them in" or "Refuse." Everyone who joined themselves shows further down with the same "Many mailboxes"/Block/Restore controls.
  4. Under "Stopped for review," a sign-in or sign-up the security check refused shows its signals and a reference; click "Let them in" or "Keep out."
  5. Under "Blocked," type an address, domain, or network with a Reason and click Block; remove any entry the same way.
  6. Under "Joining and safety," choose "Only I add people," "Named domains," or "Any work email"; for named domains, list them and click "Save domains." Toggle "I approve each one," "Personal Gmail/Outlook allowed," "Two-factor required," and "Files on" or "Files off."
  7. Below that, "Who your team can see" sets address privacy: toggle "Addresses hidden"/"Addresses visible," and when hidden, "Company hidden too"/"Company still shows" and "Given name only"/"Full name."
  8. Under "Forwarding out of your mailboxes," choose which forwards wait for you: Every forward, Only forwards to addresses outside the company, None, or the platform default. A parked forward shows who sent what to whom; click "Approve and send" or type a reason and click "Decline."
  9. Under "Names and pictures for outside contacts," give a contact a name and optional picture so masked people see that instead of a generic label. Under "Contacts you decide about," unhide one address for everybody or specific mailboxes, or add a shared contact everyone can write to even without corresponding before.
  10. If Drive is connected, approve or decline share requests under "Waiting to be shared," and set each person's storage allowance under "Files."
  11. Filter "What has been happening" by Everything, People, Security, or Files to see the activity log.

What you should see

A connected Google mailbox shows "Mail + Drive" or "Mail only" next to its name. A new password appears once in a highlighted panel with a Done button. Write it down or copy it before dismissing it.

Common problems

A colleague signed in with Google sees "Google did not return a lasting sign-in" if they closed the consent screen early; ask them to try again and press Allow. Withdrawing "Many mailboxes" from someone also revokes the other mailboxes they'd connected, so access stops with the permission.

Who should be the administrator?

Someone at the client, not at the agency. The point of a client door is that the client's own administrator decides privacy, forwarding and who has a mailbox.

What does forwarding approval do?

It parks a forwarding rule that would send mail outside the organisation until an administrator approves or declines it. Silent forwarding out of a company mailbox is one of the oldest ways data leaves a business.

Common questions

Who should be the administrator?

Someone at the client, not at the agency. The point of a client door is that the client's own administrator decides privacy, forwarding and who has a mailbox.

What does forwarding approval do?

It parks a forwarding rule that would send mail outside the organisation until an administrator approves or declines it. Silent forwarding out of a company mailbox is one of the oldest ways data leaves a business.

Last updated September 19, 2026. Written by the team that operates the platform.

Webmail Admin Console: People, Privacy, Forwarding and Access