Skip to content

Administration

This page shows you how to look after your mail server from inside INBUXA Webmail: adding people, resetting passwords, setting up shared addresses, and getting a domain's DNS records.

Who sees Administration

Administration is in the account menu, top right. It appears only if your account's role lets you look after the server. A role is a named set of permissions on INBUXA Server. Three kinds of role usually have it:

  • a system administrator, who looks after the whole server;
  • a tenant administrator, who looks after one organization on it;
  • a helpdesk role that someone has built for everyday account work.

Everybody else never sees the menu entry.

What you see follows your role, section by section and button by button. A role that can read accounts but not create them gets the list with no New account button. A role that cannot read domains gets no Domains section at all.

Hiding a button is not what protects the server

Shaping the page is a convenience. The protection is INBUXA Server itself: it checks every change against your role, and keeps a tenant administrator to their own tenant's domains and people.

If Administration is grayed out or missing

Two things turn it off:

  • You signed in on a device you did not mark as your own. Administration only works when This is my own device was ticked at sign-in. If you signed in without it, the menu entry is grayed out and says why. Sign out, then sign in again with the box ticked.
  • Whoever runs the webmail switched it off for everyone. It is a setting on the webmail service, not on your account.

Dashboard

Administration opens on a grid of cards. You see one card for each number your role can read:

Card What it shows
Users How many people have accounts. Opens Accounts
Domains How many mail domains there are. Opens Domains
Pending Messages waiting in the delivery queue
Server memory From the server's history of the last 24 hours
Received From the server's history of the last 24 hours
Sent From the server's history of the last 24 hours

The cards do not update on their own. Press Refresh to read everything again.

Below the cards is a link to INBUXA Admin, the console. Go there for detailed metrics, the delivery queue, logs and server settings. It runs as its own service: the mail server itself serves no web interface.

What each role sees on the dashboard

  • A tenant administrator sees their own tenancy: its users, its domains, and the queued mail that touches them. The server's history has no tenant in it, so a tenant's dashboard stops at those three cards.
  • A helpdesk role that reads accounts and domains sees two cards.
  • The last three cards also need a server that keeps a history. INBUXA Server does, and it is on in every install — see Monitoring for what is recorded.

Accounts

An account is one person's mailbox and sign-in.

Add an account

  1. Press New account.
  2. Fill in a display name and an address on one of your domains.
  3. Copy the generated password and pass it on to the person. Do not send it by email to the new address — they cannot read it yet.
  4. Choose a role and a storage limit.

Find and change an account

Search by name or address, then open the account. An open account shows:

  • its other addresses;
  • its groups;
  • its role;
  • its tenant, on a server that has tenants;
  • how much of its storage it uses.

Changes are saved when you press Save changes. Only what you changed is sent.

Reset someone's password

Press Set a new password. This signs that person out of every app and device still using the old password.

To change your own password, use Settings › Security & sessions instead. Changing it here would sign you out of the session you are using.

Delete an account

Press Delete account and type the address to confirm. The server then removes the mailbox and everything in it — mail, calendars, contacts and files — in the background. It cannot be brought back.

Two limits on purpose

  • An account that can do more than yours opens read-only. You can look, but not change its password or delete it.
  • You cannot change your own role, or delete the account you are signed in with.
Why accounts that outrank you are read-only

INBUXA Server checks your role when you hand out permissions. It does not check your role on a password change or a delete. So INBUXA Webmail makes that check itself. Otherwise an account that can edit people could take over an account that runs the server.

Groups

A group is a shared address and mailbox, and the people who share it — for example [email protected].

Add a group

  1. Press New group.
  2. Fill in a display name and an address on one of your domains.
  3. Choose a role and a storage limit.

To find a group, search by name or address.

Add or remove members

  • To add someone, search for the person.
  • To remove someone, remove them one at a time.

Each change applies straight away. You cannot add or remove yourself, and a group cannot contain another group.

Being in a group gives a person whatever has been shared with the group — its mailbox, or a calendar. It does not give them the group's role. A person's permissions always come from their own role.

Delete a group

Press Delete group and type the address to confirm. Its members are taken out first. They keep their own accounts.

Mailing lists

A mailing list is an address that passes mail on to everyone on it. The people on it can be on this server or anywhere else.

Add a mailing list

  1. Press New mailing list.
  2. Fill in its recipients.

Add recipients

You can paste several recipients at once. Any of these work:

  • a column copied from a spreadsheet;
  • a line of addresses separated by commas;
  • Name <address>.

If something looks meant as an address but is not one, it stays in the box with a note. Nothing is dropped. Once a list has more than a dozen recipients, a filter appears to narrow them down.

Saving sends only the recipients you added and removed. So if somebody else added a recipient while you had the panel open, it is not lost.

A list is only that: there are no owners, moderators or posting rules to set.

Tenants

A tenant is a separate organization on the same mail server. It has its own people, domains and limits, and an administrator who manages only what is in it.

Tenants are in every INBUXA install

There is one edition and tenants are part of it. Nothing here waits for a license key.

Add a tenant

Press New tenant and give it a name. An open tenant then has:

  • a logo;
  • a role — the most that anyone inside the tenant can be allowed;
  • limits on accounts, groups, mailing lists, domains, roles, DKIM keys and storage. An empty limit means no limit.

What it holds counts what is in the tenant, each against its limit.

Give a tenant its domains

Add domains from the tenant's panel.

  • You can only add a domain that is in no tenant.
  • A domain comes out of a tenant only once none of the tenant's accounts are on it.

Give a tenant its administrator

  1. Open the person's account.
  2. Choose the tenant. It has to be the tenant of the account's domain.
  3. Give the account an administrator's role.

Inside a tenant, that account administers the tenant and nothing else.

Rules to know

  • Only an administrator outside every tenant can put anything into one.
  • Delete tenant is offered once the tenant holds nothing.

Roles

A role is a named set of permissions. You give roles to accounts, groups and tenants.

Add a role

  1. Press New role and give it a name.
  2. Choose what it builds on. It gets everything those roles grant.
  3. Choose its own permissions.

Choose permissions

The permissions are INBUXA Server's own list. They are grouped under headings, you can search them, and you can filter to the ones this role sets.

Each permission is not set, allowed or denied. One the role inherits says which role it comes from.

  • A denial wins over anything allowed, on this role or on any role underneath it.
  • You can only allow permissions you hold yourself.

Roles you cannot change

  • A role carrying permissions you lack opens read-only.
  • A role INBUXA Server hands out by default says so before you change it, and cannot be deleted from here.
  • A role still in use is kept by the server, which names what uses it.

Domains

A domain is the part of an address after the @, such as example.com.

Add a domain

Press Add domain and type the name. INBUXA Server gives a new domain its signing keys straight away.

The list shows each domain's accounts. It also shows whether three things are handled by the server automatically or by hand: its DNS records, its DKIM keys (the keys that sign outgoing mail so other servers can trust it), and its certificate.

Change a domain's settings

An open domain has:

  • its description;
  • its other names;
  • a catch-all address: a full address that receives mail sent to people who do not exist on the domain;
  • plus addressing: mail to name+anything@ is delivered to name@.

Copy the DNS records

This is the reason most people open a domain. DNS records are the entries you publish with your domain provider so mail reaches your server and is trusted.

  • Each record is a row with its own copy button, because a DNS provider's form takes one record at a time. A long DKIM key is copied as the single value the form wants.
  • Copy all as a zone file copies every record at once. A zone file is the plain-text format for pasting a whole set of records into a DNS zone.
  • If the server publishes the records itself through a DNS provider, the page says so and there is nothing to copy.
Why a long DKIM key copies as one value

A zone file wraps a long DKIM key across several lines. A provider's form wants it as one value, so each row gives you the key joined back together, however the zone file wraps it.

Check the DKIM keys

DKIM keys are listed with where they are in their life: signing, published and waiting, or retiring. When DKIM is automatic, the server creates and rotates them itself.

Remove a domain

Remove domain is offered once no accounts use the domain. Type its name to confirm. The domain's DKIM keys go with it, because the server will not remove a domain its keys still name.

Moving a domain's DNS, DKIM or certificate handling between automatic and manual is done in INBUXA Admin for now.