@@PRODUCT@@

Setting up email

Everything to do with email lives on one page: mailboxes, aliases, forwarders, vacation replies and the button to webmail. This page walks through them one by one.

Written for: Customer, Reseller, Administrator

Everything to do with email lives on one page: mailboxes, aliases, forwarders, vacation replies and the button to webmail. This page walks through them one by one.

If what you want to know is why mail sometimes lands in the spam folder, and what SPF, DKIM and DMARC are, that has a page of its own: Making sure your email arrives.

Screenshot — Panel → Hosting → Accounts → your account → Mail. At the top is the Email for picker: if your account has more than one domain, that is where you choose the one you are working on. Screenshots of this page are captured with openwolf designqc into .wolf/designqc-captures/.

First: does this server deliver your mail at all?

At the top of the mail page there is one switch: Deliver this domain's mail here.

  • On — this server accepts mail for your domain and drops it into the mailboxes below. This is what you want if you read your mail here.
  • Off — your mail goes somewhere else (Google Workspace, Microsoft 365, your old provider). The server accepts nothing for this domain, and the mailbox list is empty because there is nothing to deliver.

Turning it on makes the server generate a DKIM key for your domain right away. If the DNS zone is here too, the matching records are written into it for you.

# on the server
corectl mail status                 # per domain: delivered here, or elsewhere
corectl mail enable yoursite.com    # deliver here (generates the DKIM key)
corectl mail disable yoursite.com   # mail follows the MX records elsewhere

Creating a mailbox

  1. Click Create mailbox.
  2. Fill in the address — only the part before the @; the domain is already there.
  3. Fill in a quota, in MB. 0 means no limit of its own: only the disk quota of the whole account counts.
  4. Click Create.

The password is generated by the server and shown once, on a card with a copy button. CoreCP keeps it nowhere — not even in the task log. Put it in your password manager straight away; if you lose it, you simply generate a new one.

corectl mailbox add anna@yoursite.com --quota 2048
corectl mailbox list yoursite.com
corectl mailbox quota anna@yoursite.com --quota 5120
corectl mailbox remove anna@yoursite.com --purge   # --purge throws the messages away too

Leave --password out and the server generates one and prints it once. That is the recommended way. If you do want to pick a password from the command line, feed it in over stdin rather than as an argument — an argument is briefly visible in the process table on a shared server:

printf '%s' 'YourChosenPassword' | corectl mailbox add anna@yoursite.com --password-stdin

The same form exists for corectl mailbox passwd.

Changing a mailbox password

Click the mailbox in the list; the panel slides open a panel with New password. Same rule: the server makes it, you see it once.

corectl mailbox passwd anna@yoursite.com

Anybody signed in on a phone or in Outlook at that moment is thrown out until the new password is entered there as well. Which is exactly what you want when you suspect somebody is reading along.

Settings for your mail program

In Outlook, Apple Mail or Thunderbird, fill in:

value
Usernameyour full address, so anna@yoursite.com
Incoming (IMAP)mail.yoursite.com, port 993, SSL/TLS
Outgoing (SMTP)mail.yoursite.com, port 465 (SSL) or 587 (STARTTLS)
Authenticationpassword, for outgoing as well

POP3 (port 995) works too, but IMAP is nearly always better: it keeps your mail on the server, so your phone and your laptop see the same thing.

Is there a server name at the top of the page? Then this domain's mail runs on a different machine from your website, and that name is what goes into incoming and outgoing — not mail.yoursite.com. The screen names it only when that is the case; if nothing is shown, the table above is right as it stands.

Aliases and forwarders

Under Aliases and forwarders are the addresses that have no mailbox of their own but pass mail on.

  • An alias is a second name for a mailbox that lives here: info@yoursite.com → anna@yoursite.com. The mail stays on this server.
  • A forwarder sends it outside: info@yoursite.com → anna@gmail.com.

The list holds one row per forwarder, with every destination hanging off it. So info@yoursite.com going to three people is one row with three addresses, not three rows that look like three forwarders.

Making a forwarder with several destinations

  1. Click Add forwarder.
  2. Under Address, fill in who receives the mail (or @ for the whole domain — see Catch-all below).
  3. Fill in the destinations. There are two ways to type them, and the Rows / One per line switch moves between them:
  • Rows — one field per address, with Add a destination underneath. Handy when you are adding one.
  • One per line — a text box you paste a list into. Handy when you are lifting six addresses out of a mail signature. It is the same list either way: what you type in one shows up in the other, so you can switch halfway through.
  1. Click Save forwarder.

Every destination gets a copy of the mail.

Editing: one on, one off

Click the row in the list. The panel slides open with the destinations it has today. Take one away, add another, and the bar at the bottom says what saving will do before you press it: "Saving adds 1 and removes 1." It happens in one go — there is no moment where the address is half changed.

When one line is refused

If one address is wrong, the whole save is refused and nothing changes. The reason sits with the address it is about rather than as one red bar over the list, so you can see straight away which line to fix:

  • not-an-address — not an e-mail address (expected user@domain)
  • dmarc-reports@yoursite.com — reserved — it receives this domain's DMARC and TLS reports

Why all or nothing? A forwarder is one thing you set up. If half of it were saved anyway, the list on your screen would disagree with what the server has.

From the command line

# three destinations in one go (--to may be repeated or comma-separated)
corectl alias add info@yoursite.com anna@yoursite.com \
  --to accounts@yoursite.com --to backup@example.com

# the list: one row per (address, destination)
corectl alias list yoursite.com
# SOURCE                DESTINATION                KIND      STATE
# info@yoursite.com     accounts@yoursite.com      alias     active
# info@yoursite.com     anna@yoursite.com          alias     active
# info@yoursite.com     backup@example.com         forward   active

# editing is naming the whole list again with --replace
corectl alias add info@yoursite.com --to anna@yoursite.com,new@example.com --replace
# [corecp] forward info@yoursite.com → +new@example.com -accounts@yoursite.com
#          -backup@example.com (anna@yoursite.com, new@example.com)

# a line that is refused refuses the whole save, with a reason per line
corectl alias add info@yoursite.com --to ok@example.com,dmarc-reports@yoursite.com --replace
# corectl: dmarc-reports@yoursite.com: reserved — it receives that domain's
#          DMARC and TLS reports

corectl alias remove info@yoursite.com anna@yoursite.com

Leave the destination off alias remove and every destination of that address goes. Remove on the row in the panel does exactly that, and the message that follows carries an Undo that puts the whole list back in one save.

Forwarding to Gmail or Outlook.com has a known sharp edge: those providers see a forwarded message as post from your server while the sender inside the mail is somebody else. Forward a lot of spam and your server gets the bill for it. For an address that receives a lot, a real mailbox over IMAP is a quieter answer than forwarding.

When your package is full

Your package can set a maximum for mailboxes and, separately, one for forwarders. Once you are at either, that button is greyed out with the reason beside it: "Your package allows 50 mailboxes, and all of them are in use."

The two are counted separately. You can be out of mailboxes and still make forwarders, or the other way round. A forwarder with no mailbox behind it — info@ that only forwards — counts towards the forwarders like any other.

What you can do: remove a mailbox or a forwarder you no longer use, or ask your hosting provider for a larger package. If your package sets no maximum, there is no limit.

Catch-all: collecting what does not exist

If you want post to an address that does not exist to arrive somewhere anyway, use @ as the address. That is the catch-all for the whole domain.

corectl alias add @yoursite.com anna@yoursite.com

Think about it twice. A catch-all also collects every typo and every guessed address spammers try (info@, sales@, admin@, and a thousand more), so in practice it is mostly a spam funnel. A handful of aliases for the addresses you actually use is nearly always better.

Removing it again is the same line:

corectl alias remove @yoursite.com

Vacation reply (out of office)

Click a mailbox and choose Vacation reply. You fill in:

  • Subject and Message — what the sender gets back.
  • From and Until — outside that period nothing happens. Leave them empty and the reply stays on until you switch it off.
  • Interval — how many days the same sender goes without a second reply. The default is 1 day, which stops a colleague you are mailing back and forth with from receiving your vacation note ten times.

The reply is sent by Pigeonhole, the mail server's sieve engine. It knows the rules of replying politely: never to mailing lists, never to bounces or other automated post, and never twice to the same sender inside the interval.

What the screen tells you

Above the form, one line says whether the reply is actually being sent right now:

  • Replying, with an Active until … badge — it is running.
  • Not replying yet — you set a start date in the future; nothing happens before then.
  • The period has passed — the end date is behind us, so nothing is being sent. Change the date, or switch the reply off.

That distinction is deliberate. "On" and "replying right now" are two different things, and a screen that only said "on" would give you exactly the reassurance you act on while your mail goes unanswered.

No attachment

An automatic reply cannot carry a file. That is not our choice: the vacation feature in the mail standard (RFC 5230) has no notion of attachments. Put an address or a link in the text instead — a price list on your site, or the colleague covering for you.

corectl autoresponder set anna@yoursite.com \
  --subject "Away for a bit" \
  --message "I am back on 2 September. Anything urgent: info@yoursite.com." \
  --start 2026-08-15 --end 2026-09-01 --interval 1

corectl autoresponder show anna@yoursite.com
corectl autoresponder list yoursite.com
corectl autoresponder clear anna@yoursite.com

Opening webmail

Every mailbox has a Webmail button. It opens the webmail in a new tab and signs you in as that mailbox — you do not type the password again. The ticket behind it is single-use and expires within ninety seconds.

"The server is busy" — and it says so at once

Signing in is a change on the server too, so it stands in the same queue as every other change on that machine. If the server happens to be busy with something else you get an amber message within a second: the server is busy with another change, so signing in did not start; nothing was changed. Try again in a moment — usually it is finished by then.

Amber and not red, because nothing is broken: the machine is doing something and will be done with it shortly. Until recently you watched "signing you in…" for up to a minute in that case and then got the same answer. The same answer, a minute earlier, is the whole difference. The phpMyAdmin button says the same thing.

"You are not signed in", right after you clicked

For a while that button ended on a login screen: you clicked, the tab opened, and the webmail said you were not signed in. That was not your password and not your browser. The webmail set the session correctly and then redirected you to its own front page — and a browser does not send a fresh session cookie along with a redirect that continues a visit from another website, which is what the panel is to webmail.yoursite.com.

That is fixed: the sign-on page no longer redirects, it shows you the webmail straight away. You notice nothing except that it works. The same goes for the phpMyAdmin button.

What that button actually hands over

Nothing you could use afterwards, and that is on purpose:

  • The panel does not know your mailbox password — it is only ever stored hashed — so it cannot pass one on.
  • What is created instead is a temporary key that opens only that one mailbox and does not work as a password in Outlook, Apple Mail or any other mail client.
  • The ticket in the tab is good for one use and ninety seconds. Refresh the tab or open the link again later and you are told the link has already been used. That is not a fault.
  • By default the link only works from the network you were on when you clicked. Click at the office and open the tab at home and it will not work.

Webmail is also reachable on its own at https://webmail.yoursite.com, where you sign in with your full address and your mailbox password.

Which webmail this domain is served

Every mail domain has one webmail. Administrators and resellers choose it per domain, in the Webmail block at the bottom of the mail page:

ChoiceWhat people get
The server's defaultWhatever the administrator set as the default; follows along when that changes.
SnappyMailFast and light. The CoreCP default.
RoundcubeFamiliar to anyone coming from DirectAdmin.
Another webmailAn address we do not run. The button opens it in a new tab; signing in happens there.
No webmailThis domain gets no webmail button.

Two domains on the same server may make different choices: one on SnappyMail, the next on Roundcube, both with a working Webmail button.

Choose Another webmail and the button on the mailbox becomes a plain link with the sentence "Opens in a new tab. Signing in happens there." That is not a limitation but an honest statement: we can only sign somebody into a webmail we run ourselves.

# what does each mail domain on this node serve?
corectl webmail domains
# DOMAIN                CHOICE       SERVES       SIGN-ON
# yoursite.com          default      snappymail   yes
# othersite.com         roundcube    roundcube    yes

# put this domain on Roundcube
corectl webmail domain set othersite.com roundcube
corectl reconcile           # the vhost then points at Roundcube

# register an external webmail (https, and with no sign-on promise)
corectl webmail domain set third.com external --url https://webmail.example.com/

# back to the server's default
corectl webmail domain set third.com default

The server's own default stays corectl webapps set --webmail snappymail|roundcube. A domain chooses which webmail it gets and may switch it off; it cannot switch webmail on for a server that serves none.

# a single-use webmail sign-on from the command line
corectl webmail sso anna@yoursite.com

# is webmail served on this node at all?
corectl webapps status
corectl webapps set --webmail on

No Webmail button at all?

Then the server your mail lives on does not serve webmail. The panel only shows the button when the machine actually offers it — switched on is not the same as served. A server that changes webserver keeps the setting while nothing answers on webmail.yoursite.com any more; the button would then take you to the parked page, and that is exactly what the panel no longer does.

Your administrator sees the difference like this:

# 'served' is the question that counts: is it actually offered?
corectl --json webapps status | grep served
#   "served": false

# the text view says it in plain words
corectl webapps status | tail -1
#   the litespeed provider does not render the webapps vhost yet; nothing is served

# and the sign-on refuses honestly instead of opening a dead tab
corectl webmail sso anna@yoursite.com --account youraccount
#   webmail_not_served: webmail is configured but the litespeed provider does not
#   render its vhost; nothing is served

Your mail itself keeps working: IMAP, SMTP, forwarding, filters and vacation replies are independent of this. Only reading it in a browser through this server is missing.

What else is on this page

  • Status per mailbox: how much of the quota is in use, whether it has forwarders and whether a vacation reply is on.
  • DNS for this domain — a direct link to the DNS zone, where the mail records live.
  • Read again — the panel shows what it last heard from the server; this button fetches it again now.

When something is not right

What you seeWhat it usually is
The mailbox list is empty and the page says mail is delivered elsewhereThe switch at the top is off. Turn it on if you want to read your mail here.
New mailbox created, but nothing arrivesYour domain's MX records still point at your old provider. See Making sure your email arrives.
You can send, but everything lands in spamSPF/DKIM/DMARC. See Making sure your email arrives.
The webmail button does nothingYour browser blocked the new tab. Allow pop-ups for the panel, or go straight to https://webmail.yoursite.com.
"That sign-in link has already been used"You refreshed the tab or reopened an old link. Just click Webmail again.
"That sign-in link was opened from a different network"You clicked on one connection and opened the tab on another. Click Webmail again from the network you are on now.
"The server did not answer in full"The node was briefly unreachable. Click Read again; if it stays, tell your hosting provider.

If the webmail button seems to do nothing

Webmail opens in a new tab, and that tab is requested at the moment you click. For a while it happened a fraction too late — only after the server had returned a one-time ticket — and a browser refuses a tab it cannot attribute to your click, without saying so. The button really did nothing. That is fixed: the tab is now reserved on the click itself and sent to webmail afterwards.

If nothing still happens, your browser is blocking pop-ups for the panel's address altogether. Allow them for that one address — in Safari under Settings → Websites → Pop-up Windows, in Chrome through the icon at the right of the address bar right after you click.

If you would rather not go through the panel, the server prints the same address:

ssh root@stck1.corecp.dev 'corectl mail webmail-url info@test100.nl'

Mail for one of your website's extra names

If your website has an extra name — mycompany.co.uk beside mycompany.com, say — mail to that name arrives in your main domain's mailboxes by default. info@mycompany.co.uk lands in info@mycompany.com, and the same goes for every other address. There is nothing to create for it.

If you do not want that, switch it off per name in the panel under the website's Extra names, or from the command line:

corectl domain alias set mycompany.com mycompany.co.uk --mail off

The server then refuses mail to that name right at the door, with a message the sender sees. That is on purpose: mail that quietly disappears is worse than mail that is refused, because at least a refusal tells the sender to look elsewhere.

Spam, and how much you may send

Every mailbox on this page is filtered from the moment it exists. Click a mailbox and open the Spam tab to change how hard the filter looks, what it does when it finds something, and which senders must always get through or never get through.

There is also a ceiling on outgoing mail — 100 messages an hour per mailbox by default — which exists to keep the whole server off blocklists when a website gets broken into. Mail over it is held and delivered later, not refused.

Both have a page of their own: Keeping spam out.

Too many wrong passwords

The server watches for failed sign-ins. Five wrong mail passwords within ten minutes and the address is refused for an hour — and that applies to everything from that address, so the website and FTP go with it. A mail program retrying an old password in the background collects those five attempts in a few seconds.

If that happens: change the password in every device that fetches the mailbox (phone, laptop, that one old program), and ask your administrator to lift the block. They can see on the server's firewall screen exactly which address is blocked and why.

Webmail counts towards this too now. It used to be that you could get it wrong in webmail for ever without consequence — the server saw itself as the visitor there and never blocks its own machine. Webmail now passes your real address on, and the same five attempts apply. Worth knowing if you work from an office or over a mobile network: you share that address with other people, so a colleague getting it wrong five times can lock the whole office out. Lifting it is one action for your administrator.

"No website yet" — and what to do about it

Email belongs to a website: a mailbox is something@yourdomain.com, so without a domain there is no address to create. On an account that has no website yet, the mail screen says so — it does not keep loading.

  1. Go to Accounts → your account → Mail. You get one explanation with an Add website button.
  2. Press it. You land on Websites of the same account.
  3. Add the website: its name and its PHP version. Where a website runs describes what else is involved.
  4. Go back to Mail. The domain switcher is now above the page with your new website in it, and you can create the first mailbox.

If you may not add a website yourself — that is your hosting company's right — you get the same explanation with a View websites link and a note to ask your administrator.

Until there is a website, the SSL, Mail and DNS tabs are dimmed. They stay clickable: each of the three explains what is still missing.

See also

  • Making sure your email arrives — SPF, DKIM, DMARC and the MX records.
  • Managing DNS records — where those records live and how you change them.
  • What you can arrange yourself — what is yours to do and what you ask your hosting company for.

A new password: where it appears

Passwords the server makes for you are shown once. So they always appear where you asked for them, and not somewhere else on the screen:

  • Ask for a new password in a mailbox's own panel and that panel stays open, with the card carrying the password in the middle of it, above the button you just pressed.
  • Create something new and that panel closes itself the moment it worked, and the card is on the page underneath — which is what you are looking at by then.

Copy it or write it down straight away. If you lose it there is no way to get it back; there is only a way to have a new one made.

If something goes wrong you see it in exactly the same place: the message is in the panel where you pressed the button, not on the page behind it.

When your administrator moves the server to a store of its own

The server keeps its own small list of who receives mail on which domain: your domains, your mailboxes, your aliases and your out-of-office replies. That list used to live in the same database server that holds websites' databases; on servers your administrator has converted it now lives in a store that belongs to the server itself.

Nothing about setting up email changes for you. Your mailbox keeps the same password, your aliases stay, and so does your out-of-office reply. Two things are worth knowing:

  • During the move Postfix and Dovecot are reloaded once. A mail program that is connecting at that moment retries on its own, and no mail is lost — a sender that finds nobody home offers the message again later.
  • Your webmail address book and sender identities come along. Afterwards they are in a file beside the webmail instead of in a database.

If a mailbox stops signing in, first check that you are typing the full address, domain included. Capitals make no difference, before or after the move:

# both forms are the same mailbox
you@example.com
YOU@EXAMPLE.COM

If it keeps failing, tell your administrator it started after the server's storage was moved. They can put the server back on the old location with one command while they look into it.