Zomail admin console basics

A tour of the Zomail admin console: roles, users, aliases, groups, shared mailboxes, password and 2FA resets, SSO, mail restores, audit log, trace, branding.

On this page
  1. Signing in and finding your way
  2. Roles
  3. Users
  4. Aliases, groups and catch-all
  5. Shared mailboxes and delegation
  6. Password resets and 2-step verification
  7. Single sign-on with Google or Microsoft
  8. Restore deleted mail
  9. Audit log and message trace
  10. Archive, retention and branding
  11. FAQ

The admin console at https://mail.zomail.io/admin is where owners and administrators manage the organisation: people, domains, security and billing. This page gives you a map of it and the everyday tasks you will do most.

Signing in and finding your way

Sign in with your own mailbox. Administrator accounts must have 2-step verification turned on before the console opens. Sensitive actions, such as resetting a password or deleting a mailbox, ask you to confirm your identity again with your password or a 2-step code.

The home page is a grid of tiles under "Manage your organisation":

TileWhat you do there
UsersAdd, suspend, delete and restore mailboxes; reset passwords and 2-step verification
DomainsAdd domains, DNS records, DKIM
AdministratorsGive people an admin role or take it away
Groups & aliasesExtra addresses, distribution lists, catch-all
Drive & storageStorage, Trash and Junk auto-clean, organisation settings
Data migrationBulk mail import from old systems
Message traceFind out what happened to a message
Archive & eDiscoveryCompliance archive, legal hold, search and export
BackupsRestore deleted mail
DMARC reportsWho sends mail as your domain
BillingPlan, users, invoices

Some settings live on the organisation page itself (open it from Administrators or Drive & storage): the Activity log, Branding, Mail security, single sign-on and the QR sign-in policy.

Roles

RoleCan do
OwnerEverything, including billing, granting admin roles, AI and Drive public-link settings
AdministratorDomains, mailboxes, aliases, delegation, migration, security, audit and archive; can view billing
HelpdeskView the organisation; reset passwords, sign out sessions, remove devices
BillingPlan, payments and invoices only

To grant a role: Administrators → choose the mailbox and the role → confirm → Grant. You can't revoke your own role.

Users

  • Add one: Users → Add user, then Create mailbox. Temporary passwords need at least 12 characters.
  • Add many: Users → Create from CSV, up to 200 rows per file, with a preview before anything is created. See getting started.
  • On a user's page: set a new password, Sign out all sessions, Remove all devices, change storage, suspend or delete.
  • Suspend blocks sign-in and rejects incoming mail, but keeps all data. Use it if you suspect the account is compromised.
  • Delete signs the user out everywhere and bounces new mail. The mailbox and its data are kept for 30 days under Users → Deleted users, where you can Restore it. App passwords must be created again after a restore.

Aliases, groups and catch-all

Open Groups & aliases → Add address and pick a type:

  • Alias: a second address for one person, for example anna.nguyen@ delivering to anna@.
  • Group: one address that delivers a copy to several people, for example sales@.
  • Catch-all: receives mail for any address on the domain that doesn't exist. One per domain.

Aliases and groups don't use a user seat.

Shared mailboxes and delegation

Open the organisation page → Domains section → Delegation & shared mailboxes.

  • Create a shared mailbox such as support@example.com, then Add member for each person. Shared mailboxes need no licence seat and have no password of their own. Members open them from the account menu in webmail or in the Zomail app; Outlook and other IMAP apps can't open them yet.
  • Policies: choose whether people may delegate their mailbox to colleagues and whether they may forward mail outside the organisation. Turning a policy off takes effect at once, including for existing delegations and forwarding rules.

Password resets and 2-step verification

  • Forgotten password: if the user has a confirmed recovery e-mail, they can use Forgot password? on the sign-in page. Otherwise open their page → Set new password and share it over a safe channel.
  • Lost phone and recovery codes: first confirm who is asking, by calling a number you already know (attackers also say "I lost my phone"). Then open the user → Reset 2-step verification. This removes the authenticator and recovery codes, signs out all sessions, app passwords and devices, and e-mails the user. They should turn it on again right away.
  • Administrators can reset 2-step verification only for people with a lower role. An administrator can't reset an owner.

Single sign-on with Google or Microsoft

If your staff already sign in with Google Workspace or Microsoft 365 (Entra ID), you can let them use that account for Zomail webmail and the Zomail app. You create an OAuth client at Google or an app registration at Microsoft, paste the client ID and secret on the organisation page → Configure SSO, and test it. Start in Optional mode, and switch to Required only after a successful test. Mailboxes must already exist in Zomail with the same address. When SSO is required, Outlook and phone mail apps use app passwords. Ask users to create them before you switch.

Restore deleted mail

Mail still in Trash can be restored by the user. For mail deleted for good:

  1. Admin → Backups → Restore mail.
  2. Enter the mailbox and, optionally, one folder.
  3. Pick a point in time before the deletion. Mail snapshots are taken every hour.
  4. Name the restore. A custom name must start with Restored . It becomes a label on the restored messages.
  5. Click Restore. Copies appear in the user's Archive with that label. Existing mail is never overwritten or deleted.

Audit log and message trace

  • Activity log (on the organisation page) shows who did what: admin sign-ins, mailboxes created or deleted, role changes, password resets and more. Export CSV downloads it. It never contains message content.
  • Message trace answers "I sent it, they didn't get it". Filter by direction, sender, recipient, subject or time, then open a message to see each delivery step, a plain-language explanation and the receiving server's original reply.

Archive, retention and branding

  • Archive & eDiscovery (on plans that include it): keep an unchangeable copy of every sent and received message for 1 to 100 years, put legal holds on people or the whole organisation, and search and export results as .eml files with a manifest. Every search, view and export is logged.
  • Trash and Junk auto-clean (owner, under Drive & storage): 7, 30 or 90 days, the platform default, or never.
  • Branding (organisation page): your logo, brand colour and display name in webmail, the sign-in page, system e-mails and the Zomail app. You can also add your own webmail address, such as mail.yourcompany.com, with a CNAME record.

More: anti-spam and anti-phishing settings, migration and the FAQ. For anything you can't do from the console, contact Zomail support.

FAQ

Does a shared mailbox cost a licence?

No. Shared mailboxes use storage but not a user seat.

Can I recover a user I deleted by mistake?

Yes, within 30 days: Users → Deleted users → open the mailbox → Restore.

Can I see a user's app passwords?

No. To cut off all app passwords at once, reset the user's password or suspend the mailbox.