Where this lives. Sign in and open /mail/admin in the app.
What it does
A workspace can serve mail that actually lives in a real Gmail or Google Workspace account through the door, instead of on our own mail server. There are two ways this happens: an administrator connects a Google account as one of the door's mailboxes, so a colleague signs in with a password issued here and never sees the real Google password; or a person who signed in to the door with their own Google or Microsoft identity connects their own Gmail or Outlook so it opens inside the same client. Either way, mail is fetched when it's opened and never copied to our servers.
A linked mailbox follows the workspace's address privacy setting like any other. If it's Masked, anyone reading the mailbox, including the person it belongs to, sees people outside the workspace by name only, never the raw address: "Contact at theirbrand.com," or just a code if company names are hidden too. Colleagues on the same door always show normally; masking only applies to people outside it, and an administrator can give any of them a real name under "Names and pictures for outside contacts" so they show that instead of a generic label.
Before you start
For the administrator flow, you need the Google or Microsoft account's own credentials in hand, since you're the one who signs in to Google, not your colleague. For the guest flow, the person just needs their own Google or Microsoft account.
Set it up, step by step
- As the door's administrator, open the administration console and, under "People with a mailbox," click "Connect a Google account." Sign in to that Google account when Google asks. You'll do this once, not the colleague who'll use the mailbox.
- On Google's consent screen you're asked to allow sign-in (your name and email) and full access to that Gmail mailbox, the same permission a mail app needs to read, send, and manage mail over IMAP. Approve it.
- Back on the console, a mailbox is created for that Google address. Click "Create the app password." The password is shown once. Hand over exactly that address, that password, and the sign-in link, and hand them over some way other than email.
- To link Drive as well as mail, use "Connect Drive" on an existing connection, or the same Connect button asks for both when Google's review allows it. Until then, connecting only links mail, and the console says so: "Google is still reviewing this app's Drive permission. Drive can be added later without disconnecting." Per person, "Drive on" and "Drive off" toggle it without touching the mail connection.
- If the connection ever needs re-proving, Disconnect returns that mailbox to reading and sending through our own mail server; the address and its mail stay as they were, and you can connect it again any time.
- For the other direction, a person who signed in at the door with their own Google or Microsoft account, rather than a mailbox, opens Settings → Security and clicks "Connect Gmail" (or "Connect Outlook"). One consent screen, and it's revocable any time from the same card with "Disconnect." On a personal Google account, Google may show an "unverified app" warning while our access is still under Google's review. Choosing Advanced, then "Go to emailcampaign.ai," continues past it.
[VERIFY: whether Drive is currently enabled for newly connected Google mailboxes on this server. It is gated by a server setting this review could not read, and the product code describes it as off in production and on in staging while Google's review is pending]
What you should see
A connected mailbox shows "Mail + Drive" or "Mail only" next to its name in the console, along with the real Google address it's connected to. If the connection needs attention, it's marked "needs reconnecting." On a masked mailbox, anyone reading it can still ask to see the real address behind one contact at a time.
Common problems
"Google did not return a lasting sign-in, so nothing was connected" means press Allow on the consent screen rather than closing it early. "Google was connected without the email permission" means the same thing: try again and leave every permission ticked. If the account has no domain here yet, verify one of your domains first, since the mailbox behind the Google account needs an address on it.
Related
Does this need my Google password?
No. Google's own consent screen grants access, and the password never reaches this platform. You can withdraw the grant from your Google account at any time.
What can the connected mailbox see about me?
Only what the consent screen listed. Address masking controls what your correspondents see in return, so a shared workspace does not expose every address to everyone.
Read next
Common questions
Does this need my Google password?
No. Google's own consent screen grants access, and the password never reaches this platform. You can withdraw the grant from your Google account at any time.
What can the connected mailbox see about me?
Only what the consent screen listed. Address masking controls what your correspondents see in return, so a shared workspace does not expose every address to everyone.
Read next
Last updated September 19, 2026. Written by the team that operates the platform.