Zomail admin console basics
A tour of the Zomail admin console: roles, users, aliases, groups, shared mailboxes, password and 2FA resets, SSO, mail restores, audit log, trace, branding.
On this page
The admin console at https://mail.zomail.io/admin is where owners and administrators manage the organisation: people, domains, security and billing. This page gives you a map of it and the everyday tasks you will do most.
Signing in and finding your way
Sign in with your own mailbox. Administrator accounts must have 2-step verification turned on before the console opens. Sensitive actions, such as resetting a password or deleting a mailbox, ask you to confirm your identity again with your password or a 2-step code.
The home page is a grid of tiles under "Manage your organisation":
| Tile | What you do there |
|---|---|
| Users | Add, suspend, delete and restore mailboxes; reset passwords and 2-step verification |
| Domains | Add domains, DNS records, DKIM |
| Administrators | Give people an admin role or take it away |
| Groups & aliases | Extra addresses, distribution lists, catch-all |
| Drive & storage | Storage, Trash and Junk auto-clean, organisation settings |
| Data migration | Bulk mail import from old systems |
| Message trace | Find out what happened to a message |
| Archive & eDiscovery | Compliance archive, legal hold, search and export |
| Backups | Restore deleted mail |
| DMARC reports | Who sends mail as your domain |
| Billing | Plan, users, invoices |
Some settings live on the organisation page itself (open it from Administrators or Drive & storage): the Activity log, Branding, Mail security, single sign-on and the QR sign-in policy.
Roles
| Role | Can do |
|---|---|
| Owner | Everything, including billing, granting admin roles, AI and Drive public-link settings |
| Administrator | Domains, mailboxes, aliases, delegation, migration, security, audit and archive; can view billing |
| Helpdesk | View the organisation; reset passwords, sign out sessions, remove devices |
| Billing | Plan, payments and invoices only |
To grant a role: Administrators → choose the mailbox and the role → confirm → Grant. You can't revoke your own role.
Users
- Add one: Users → Add user, then Create mailbox. Temporary passwords need at least 12 characters.
- Add many: Users → Create from CSV, up to 200 rows per file, with a preview before anything is created. See getting started.
- On a user's page: set a new password, Sign out all sessions, Remove all devices, change storage, suspend or delete.
- Suspend blocks sign-in and rejects incoming mail, but keeps all data. Use it if you suspect the account is compromised.
- Delete signs the user out everywhere and bounces new mail. The mailbox and its data are kept for 30 days under Users → Deleted users, where you can Restore it. App passwords must be created again after a restore.
Aliases, groups and catch-all
Open Groups & aliases → Add address and pick a type:
- Alias: a second address for one person, for example
anna.nguyen@delivering toanna@. - Group: one address that delivers a copy to several people, for example
sales@. - Catch-all: receives mail for any address on the domain that doesn't exist. One per domain.
Aliases and groups don't use a user seat.
Shared mailboxes and delegation
Open the organisation page → Domains section → Delegation & shared mailboxes.
- Create a shared mailbox such as
support@example.com, then Add member for each person. Shared mailboxes need no licence seat and have no password of their own. Members open them from the account menu in webmail or in the Zomail app; Outlook and other IMAP apps can't open them yet. - Policies: choose whether people may delegate their mailbox to colleagues and whether they may forward mail outside the organisation. Turning a policy off takes effect at once, including for existing delegations and forwarding rules.
Password resets and 2-step verification
- Forgotten password: if the user has a confirmed recovery e-mail, they can use Forgot password? on the sign-in page. Otherwise open their page → Set new password and share it over a safe channel.
- Lost phone and recovery codes: first confirm who is asking, by calling a number you already know (attackers also say "I lost my phone"). Then open the user → Reset 2-step verification. This removes the authenticator and recovery codes, signs out all sessions, app passwords and devices, and e-mails the user. They should turn it on again right away.
- Administrators can reset 2-step verification only for people with a lower role. An administrator can't reset an owner.
Single sign-on with Google or Microsoft
If your staff already sign in with Google Workspace or Microsoft 365 (Entra ID), you can let them use that account for Zomail webmail and the Zomail app. You create an OAuth client at Google or an app registration at Microsoft, paste the client ID and secret on the organisation page → Configure SSO, and test it. Start in Optional mode, and switch to Required only after a successful test. Mailboxes must already exist in Zomail with the same address. When SSO is required, Outlook and phone mail apps use app passwords. Ask users to create them before you switch.
Restore deleted mail
Mail still in Trash can be restored by the user. For mail deleted for good:
- Admin → Backups → Restore mail.
- Enter the mailbox and, optionally, one folder.
- Pick a point in time before the deletion. Mail snapshots are taken every hour.
- Name the restore. A custom name must start with
Restored. It becomes a label on the restored messages. - Click Restore. Copies appear in the user's Archive with that label. Existing mail is never overwritten or deleted.
Audit log and message trace
- Activity log (on the organisation page) shows who did what: admin sign-ins, mailboxes created or deleted, role changes, password resets and more. Export CSV downloads it. It never contains message content.
- Message trace answers "I sent it, they didn't get it". Filter by direction, sender, recipient, subject or time, then open a message to see each delivery step, a plain-language explanation and the receiving server's original reply.
Archive, retention and branding
- Archive & eDiscovery (on plans that include it): keep an unchangeable copy of every sent and received message for 1 to 100 years, put legal holds on people or the whole organisation, and search and export results as
.emlfiles with a manifest. Every search, view and export is logged. - Trash and Junk auto-clean (owner, under Drive & storage): 7, 30 or 90 days, the platform default, or never.
- Branding (organisation page): your logo, brand colour and display name in webmail, the sign-in page, system e-mails and the Zomail app. You can also add your own webmail address, such as
mail.yourcompany.com, with a CNAME record.
More: anti-spam and anti-phishing settings, migration and the FAQ. For anything you can't do from the console, contact Zomail support.
FAQ
Does a shared mailbox cost a licence?
No. Shared mailboxes use storage but not a user seat.
Can I recover a user I deleted by mistake?
Yes, within 30 days: Users → Deleted users → open the mailbox → Restore.
Can I see a user's app passwords?
No. To cut off all app passwords at once, reset the user's password or suspend the mailbox.