Guides

Shared Mailbox Security: Individual Logins, No Shared Passwords

Shared mailbox security for small teams: why a shared password for info@ or support@ is a risk, how to give people individual logins, and auditing who sends.

Almost every small business has one: the info@ or support@ mailbox whose password is known to four people, two of whom no longer work there. It cannot have two-factor authentication because everyone would need the same phone, nobody can tell who sent the reply that upset a customer, and when it is compromised nobody notices because logins from new places are normal. Here is how to keep the role address customers rely on while removing the shared credential behind it.

Quick answer

Keep the role address, drop the shared login. Have the role address deliver to the individual mailboxes of the people who handle it (through an alias, group, or forward), let those people reply from the role address as a sending identity in their own mail app, and put two-factor authentication on each individual account. If the role mailbox must remain a real mailbox, give it a generated password held in the password manager and shared with named people only, and change it whenever one of them leaves.

Why a shared password is a security problem

  • It cannot be paired with two-factor authentication in any practical way, so it is protected by the password alone.
  • It is the credential most likely to be written down, texted, or emailed, because it has to be handed around.
  • It never gets changed, because changing it means telling everyone, so leavers keep access.
  • There is no accountability. A reply that promised a refund, or an attachment sent to the wrong customer, cannot be traced to a person.
  • Suspicious-login alerts are useless when logins from five devices in three cities are normal.

The three ways to run a role address without sharing a login

  1. Alias or group delivery. The role address is not a mailbox at all; mail to it is delivered to each handler's own mailbox. Each person replies from their own account, choosing the role address as the From identity if your provider permits it. Simplest and most secure; the trade-off is no single shared history.
  2. Real mailbox, individual access. Some providers let you grant named users access to a shared mailbox without sharing its password, and log who did what. Use this where the shared history matters and your provider supports it.
  3. Real mailbox, managed credential. Where neither of the above is available, the mailbox has a generated password stored in the password manager, shared with a small named group, rotated on every leaver, and read through IMAP in each person's own mail app so that at least device-level accountability exists.

Setting it up on your domain

On OquMail you can create the role address as one of your 15 free mailboxes and connect it over IMAP (mail.oqumail.com, port 993) to each handler's mail app as an additional account, so nobody needs the webmail password on a shared screen. Give each team member their own mailbox as well; with 15 available on the free plan there is no reason for two people to share one. Whichever approach you use, write down which people currently hold access and review that list monthly.

Auditing who sends what

  • Require a personal sign-off in every reply from a role address: "Best regards, Amira, Support Team". Customers appreciate it and it creates accountability without technology.
  • Where the mailbox is read through individual mail apps, the Sent folder on each device shows what that person sent; encourage a shared "Sent" folder on the IMAP server so the team sees each other's replies.
  • Use your provider's delivery logs to confirm what actually left the domain from the role address and when. OquMail's per-message delivery logs are useful here for disputes about whether a message was sent.
  • For shared mailboxes with a managed credential, keep a simple change log of when the password was rotated and why.

Rules for the team

  1. The role mailbox password, if one exists, lives only in the password manager. Never in chat, never in a note.
  2. When someone stops handling the mailbox, remove their access or rotate the password that day.
  3. Do not use the role mailbox as the recovery address for other services; recovery mail for the company should go to a protected individual or admin account.
  4. Do not sign up for software with the role address unless the whole team is meant to control that software.
  5. Check the role mailbox for unfamiliar rules and forwards monthly; shared mailboxes are a favourite place for attackers to hide a silent forward.

Common questions

We only have two people. Does this still matter?

Yes, because the risks are about the credential, not the head count. Two individual mailboxes plus an alias take five minutes to set up and give both of you two-factor authentication.

Customers reply to the person, not the role address. How do we keep continuity?

Set the Reply-To on outgoing role mail to the role address so replies flow back to the team, and include the role address in the signature.

Can a shared mailbox have two-factor authentication?

Technically yes, if one person holds the second factor, but that defeats sharing. The alias approach gives every handler their own second factor and removes the problem.

Free business email on your own domain

OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.

Get started free

Ready for business email on your domain?

Up to 15 free mailboxes, guided DNS, webmail, and a transactional API — start in minutes.

Create your free workspace