Arrow keys or j and k move, Enter opens, x ticks the box, e archives, ! files as junk, # deletes. ? lists every shortcut; Ctrl+K opens the palette.
Held mail
Contacts
Address books
Your contacts are kept in address books. Share one with a colleague, or with your whole domain, and they see it in their webmail and on their phone.
Everyone you write to is offered under Other contacts; the To, Cc and Bcc fields complete from both as you type.
| Name | Address | Details |
|---|
Groups
A group stands for its members: type its name in To, Cc or Bcc and choose it, and every member is addressed. A phone that syncs your contacts sees the group too.
| Group | Members |
|---|
Other contacts
People you have written to but not kept. Keep one to have it in your address book and on your phone.
| Name | Address |
|---|
Directory
Everyone at your organisation. The To, Cc and Bcc fields complete from this as well as from your own contacts.
Tasks
Nothing to do. Add a task above; what your phone adds over CalDAV appears here too.
Recover deleted items
| Subject | From | Folder | Deleted |
|---|
Messages that expire
| Subject | To | Expires | Opened |
|---|
Password-protected messages
| To | Sent | Expires | Opened |
|---|
Scheduled
Drafts waiting to be sent, and messages snoozed until later. Cancelling a send keeps the draft; cancelling a snooze brings the message back now.
| What | Subject | When |
|---|
Settings
Folders
A folder made here is a folder in your mailbox: your mail program will see it too. A name may be a whole path - every part of it that is not there yet is made. Renaming a folder to a different path moves it, and what is inside it goes too. Deleting one deletes what is in it, and the folders inside it; the folders the server keeps for a purpose of its own cannot be deleted at all.
Out of office
Forwarding
Addresses that reach this mailbox
Your own address, every alias that points here, and every mailbox that has let you write as it. The From picker on a new message offers the same list.
Your data
Everything the server holds for you, as one file: your mail as mbox per folder, your contacts as vCard, your calendars, your settings, rules and filters, and the log lines that name you. Up to 500 MB here; for more, ask your administrator.
Download everything (.zip)Name and signature
Your directory entry
What everyone else at your organisation sees beside your name in the directory and in their To field. Your name and address are already there; this is the rest.
Your administrator keeps these for this server, so only the choice below is yours.
Out of the list, out of everybody's To field and out of the address book a phone syncs. It does not hide your mailbox: mail still arrives and anybody who knows your address can still write to you.
Preferences
Kept with the account, so they follow you between browsers.
Offline in this browser
The mail of the last days you choose - the text, the formatting and the attachments - is kept in this browser's own storage, so it can be read and searched with no connection, and a message written then is sent when one is back. It lives in this browser and nowhere else: anyone who can open this browser can read it, and signing out removes it.
Your administrator has switched offline mail off for this server. The inbox listing and the last messages you opened are still kept for reading without a connection.
Notifications on this device
A notification can reach this phone or browser even when the page is closed. What it may say is your choice, and each device is asked separately.
| Name | Created | Last used |
|---|
Templates
Written in a new message and saved from there. In a template, {first_name} becomes the first name of the first recipient, {subject} the subject, {date} today's date.
| Name | Subject |
|---|
Quick steps
A button of your own that does several things at once to the ticked messages, or to the one under the cursor - and a key from 1 to 9 for it.
| Name | Shortcut | What it does |
|---|
Labels
A label is an IMAP keyword on the message, so every mail program sees it as a flag of the message. The colour is yours alone.
Rules
When a message arrives: a condition, an action. Written into the filter script below as Sieve, and read back from it; a script written by hand is left alone.
| When | Then |
|---|
Colour rows
Rows from, to or about this text get the colour.
Filter script
A Sieve script, run on every message as it arrives. It is checked before it is saved.
Storage
| Folder | Messages | Size |
|---|
Largest messages
| Subject | From | Folder | Size |
|---|
Files sent as links
| File | Size | Downloads | Expires |
|---|
Clean up
Safe senders and blocked senders
An address, or a whole domain and everything under it. Mail from a safe sender skips the spam filter for you and for nobody else. Mail from a blocked sender is held for review where your server holds suspected spam, and marked as junk where it does not - it is never thrown away.
Your own list is consulted first. If it says nothing, your domain's is, and then the server's; the nearest one that has an opinion is the one that decides.
| Address or domain | Treatment | Note |
|---|
Digest of held mail
One message listing what was held for you since the last one, each entry with a link that delivers it. A link works once and stops working after a few days. Your server decides whether a digest is sent at all; you decide whether it reaches you.
Subscriptions
The senders whose mail says how to stop it - newsletters, shops, notifications, mailing lists - with how much each has sent you. Unsubscribe asks the list to stop in the way it offers: a request your server makes for you, or a message it sends. Nothing is deleted unless you ask.
| Sender | Latest |
|---|
Lists on this server
The mailing lists run by this server that you are a member of. Choose how each one's mail comes to you, or leave it.
| List |
|---|
Masked addresses
An address of your own for one shop, one sign-up or one newsletter. Mail to it comes to your inbox, you can reply from it, and the day it starts to bring spam you switch it off: mail to it is then refused, and nothing else of yours is given away.
Your server does not offer this. Ask whoever runs it.
| Address | For |
|---|
A second account beside this one
Another mailbox on this server, side by side with this one, as Outlook shows two accounts: both appear at the top of the folder column with their unread counts, and one press switches everything - the folders, the mail, the reading pane, a new message's From, the contacts and the settings - to the other. Mail is not collected from it and nothing is copied: each mailbox stays its own.
Sign in to it here with its address and password. The session that starts lives in this page and nowhere else - not in a cookie and not in this browser's storage - so reloading the page forgets it and you add it again; it ends after the same idle time as any session, and it is listed on that account's Security page as a second account in a webmail page, where it can be ended too. Notifications on this device, mail kept for reading offline and the installed app stay with the account you signed in as, and a message opened in one account is answered from that account only.
Other accounts
Mail from another mailbox - an old provider, a second address - collected into this one on a schedule. Your server signs in there with the password you give it and brings new mail here through the same spam and virus filters as everything else. Leave a copy there while you try it. When you are moving for good, bring the folders over: what is already there arrives as it is, in folders of the same names, with its flags and dates.
Your server does not offer this. Ask whoever runs it.
Moving from Gmail or Outlook.com
Sign in there, and your server collects with the permission you give it. No password is kept here, and you can take the permission back there at any time.
Folders to bring over
What is not ticked stays where it is. A folder that only shows mail kept in the others - All Mail, Starred, Important - starts unticked, so nothing arrives twice.
| Account | Server | State |
|---|
Send mail as
An address you have at another provider, to write from here as well. A code is mailed to it: type it here to show the address is yours.
Passkeys
A passkey signs you in with the device in your hand - its fingerprint reader, its face or its PIN - instead of a password. The key stays on the device and never reaches this server, and it stands in for your one-time code as well.
Adding one asks for your own password again, so a session somebody else is holding cannot add a way in that outlives it.
Passkeys are switched off on this server.
| Device | Added | Last used |
|---|
App passwords
A password for one program or phone, separate from your own. Revoke it here when the device goes; your own password stays as it is.
Making one asks for your own password again, so a program that holds one of these cannot make another.
| For | Created | Last used |
|---|
If you forget your password
An address at another mailbox of yours, and ten one-time codes. Either of them gets you back in without asking an administrator.
A recovery address is only as safe as the mailbox that receives it: anybody who can read that mailbox can reset this password. Nobody, an administrator included, is ever shown the whole of it once it is set.
One-time codes
Ten codes, each good once. Type one wherever a code from your authenticator app is asked for: when you sign in, when you change your password, and when you make an app password. Keep them somewhere that is not this mailbox.
Support access
Off, an administrator cannot open this mailbox as you. On, they can - for support, on request - and every such session is listed here, marked, and written to the server's log; the last one is noted below.
S/MIME
Sign and encrypt mail in this browser. Your private key is wrapped with your password here before it is stored; the server cannot open it. Import a PKCS#12 (.p12, .pfx) or PEM file with its passphrase.
| Address | Certificate | Expires |
|---|
From your organisation
Your domain has no S/MIME authority: a certificate has to come from elsewhere and be imported above.
The key is made in this browser and wrapped with your password before it is stored; only the request goes to the server. A P-256 key signs, and nothing can encrypt to it - this webmail has no elliptic-curve encryption, for you or for a colleague writing to you - so choose RSA unless you only sign.
| Address | Expires |
|---|
Correspondents' certificates
Kept from the signed messages they sent, so a message to them can be encrypted.
| Address | Certificate | Expires |
|---|
OpenPGP
OpenPGP is switched off in the webmail on this server.
End-to-end encryption in the format every other client speaks - Thunderbird, GnuPG, Mailvelope, Proton. The key is made in this browser and stored encrypted under a passphrase this server never sees, so nobody here can recover it, or the mail encrypted to it, if you forget it.
This browser has no Ed25519 or X25519, so a Curve25519 key cannot be made or read here; RSA works. Chrome 137, Firefox 130, Safari 17 and later have both.
| Address | Fingerprint | Expires |
|---|
Make a key
Import a key
A secret key is opened with its own passphrase and stored again under the one you unlock with here. A public key is kept as a correspondent's.
Correspondents' keys
Learned from the Autocrypt header of a message, looked up in the correspondent's own domain, or imported. Nothing is trusted because it arrived: read a fingerprint back to its owner before you rely on it.
A key that arrives for an address whose key is already here is a change, and is neither encrypted to nor shown as good until you accept it: compare the two fingerprints with the key's owner first. A key you have read back to its owner can be marked verified in person, and every good signature by it shows the mark from then on.
| Address | Fingerprint | Where from |
|---|
Zero-access mailbox
This server does not offer zero-access mailboxes.
Every message that arrives is encrypted to your own OpenPGP key once the spam and virus filters and your rules have seen it, and this server keeps only what it cannot read. Know what that costs before you switch it on: the administrator cannot read, search, export or recover your mail; search finds the sender, the subject and the date, never the text; IMAP and POP clients receive the encrypted messages, so until one of them holds your key this is a webmail mailbox; and if you forget your password and have lost the recovery key, the mail is gone. Nobody can help.
Only what is delivered to you is sealed, and the copy of what you send from here; your drafts and anything a mail client uploads are stored as they are.
Make or import an OpenPGP key that does not expire first.
Switching it off changes nothing already stored: mail that arrived encrypted stays encrypted and opens with your key. New mail is stored as it arrives.
Sessions
Every browser signed in as you. End one you do not recognise, or all the others at once.
| Started | Last seen |
|---|
Devices
Everything that has signed in as you, whatever it was: a mail program fetching over IMAP or POP3, one sending over SMTP, a calendar or address book, this page. Revoking one ends what it holds now - its session here, and any mail connection it has open - and can turn off the app password it was using, which is what to do about a phone you no longer have. It is not a block: anything with a password that still works can sign in again.
| What | Where from | Program | Signing in with | Last used |
|---|