Skip to content

Company mailboxes

A company mailbox is a full SingleSign mailbox — its own inbox, Screener, tags, storage, calendar, documents and phone credentials — at an address on one of your organization's domains — its free SingleSign subdomain, such as ana@acme.singlesign.com, or a domain of its own, such as ana@acme.com. Each member holds one company mailbox per organization, and the organization owns it: admins create it, watch its storage, and can suspend, transfer, forward or delete it. The member's personal @singlesign.com mailbox is a different mailbox entirely, and nothing on this page touches it.

Every action here needs the Manage member addresses permission — Owners and Admins have it, and so does the User management admin role (see Admin roles and permissions). The console's Mailboxes section lists every company mailbox with its owner, address, storage use and status; a member's own mailbox is also managed from their member details.

Giving someone a company mailbox

Once a person has accepted their invite, open them from Members. Under Addresses, choose "Give them a company address", type the part before the @, pick the domain, and click "Create mailbox". That does three things at once:

  • Creates their company mailbox on that domain — "its own inbox, storage and calendar, beside any personal mail. They are told right away."
  • Tells them: a notification under the bell in every mailbox of theirs, and an email — "You've been given ana@acme.com at Acme Inc." The mailbox appears in their account menu the moment it exists.
  • Makes the address a sign-in alias for their SingleSign account, for as long as they're a member.

The owner's own mailbox is created the same way in the wizard's Your address step ("Create my mailbox"), or with "Give yourself you@acme.com" on a live domain's card.

A few rules: the address goes on your free subdomain or on a verified domain of your own (an organization started before free addresses, with neither, sees "Get your free SingleSign address or verify your own domain first — company addresses live on a domain."); the name uses letters, numbers, dots, hyphens or underscores, up to 64 characters; role names like postmaster and abuse are reserved ("That name is reserved (postmaster, abuse and friends)."); and an address already in use — including one a previous holder still has — answers "That address is already in use." A member whose mailbox here is suspended gets it restored rather than a second one.

Storage: every plan includes 5 GB per user (see Plans and pricing); the Mailboxes section shows what each mailbox uses.

Addresses and aliases

A company mailbox has one primary address — the one it was created with — and can carry aliases: further addresses on the free subdomain or any verified domain that all land in the same mailbox. That's how someone who started on ana@acme.singlesign.com gets ana@acme.com once your own domain is verified: add it as an alias, then "Make default" so their mail goes out from it. A company mailbox can carry up to 30 addresses in total, the primary included.

In the member's Addresses block, "Add an alias" → "Add alias" adds one: "Aliases receive mail automatically and can be picked as From." Each row shows its chip — Primary or Alias, Default From — and its status (Active, Suspended, Removed), with:

  • "Make default" — the address mail goes out from unless the member picks another while composing. Members can change their own default under Settings → Your addresses.
  • "Suspend" / "Resume" — an alias stops receiving and sending while suspended; mail to it is held, not bounced.
  • "Remove" → "Remove address" — with "Forward its mail to" one of the mailbox's other active addresses, or "Don't forward — hold it". "Mail sent to it is held (never bounced) unless you forward it below." A removed address can later be given to someone else — a new hire inheriting sales@, say — which ends the old forward.

The primary address can't be suspended or removed on its own: "The primary address is the mailbox itself — use the mailbox actions above".

From the member's side, every active address is available in the From picker when composing, replies default to the address the message was sent to, and on a phone the username is the company address itself — see SingleSign Mail on Your Phone.

Role addresses

support@, sales@, billing@ and the like can be an alias on someone's company mailbox — but usually you want a forwarder instead: an address with no mailbox behind it that delivers to one or more people — a colleague's company mailbox, their personal mailbox, or an address outside SingleSign — and can be re-pointed when responsibilities move, without touching anyone's mailbox. Forwarders are set up under Forwarders in the console; see Forwarders and parked domains. A name is one or the other: a forwarder holds its name on that domain, so it can't also be given as an address ("That address is already in use."), and a name a mailbox or alias holds can't become a forwarder. The difference in daily use — someone with an alias can answer as support@; someone reached through a forwarder replies from their own address.

The mailbox lifecycle

The Mailboxes section (and the Company mailbox block in member details) shows each mailbox's status:

StatusWhat it means
ActiveReceiving mail — or Inbound also goes to … when a forward is set.
SuspendedLocked out · inbound is held, nothing bounces. An admin suspended it; the member is still a member.
Access endedMember removed · inbound is held, nothing bounces. The person left or was removed; the organization decides what happens next.
DeletingDeletes in 14 days — restore to keep it. Scheduled for purge at the end of the 20-day window.

Suspend and restore

"Suspend" → "Suspend mailbox": "Ana is locked out right away — web, phone and app passwords. Their mail, files and calendar stay exactly as they are, new mail is held (never bounced), and colleagues are not affected. You can restore it any time." Suspension costs nothing and changes nothing but access. "Restore" reverses it — "restored — Ana can sign in again".

Transfer

"Transfer" → "Transfer mailbox" hands the whole mailbox — "its address, mail, files and calendar" — to another member. Pick the "New owner": only active members who don't already have a company mailbox in this organization can receive one ("Every other active member already has a company mailbox here." when nobody qualifies). The previous owner's sessions and app passwords on it end; the new owner sees it in their account menu right away, the mailbox becomes active, and any forward or pending deletion is cleared. This is the offboarding step Google doesn't have — the mailbox survives the person.

Forward

"Forward" (or "Change forward") → "Forward mail for ana@acme.com": "Inbound mail to this mailbox and its aliases is also delivered to another company mailbox — useful while someone is away or after they leave. Pick none to stop forwarding." Choose "Deliver to" another company mailbox of the same organization, then "Forward mail"; "Stop forwarding" turns it off. Forwarding works on suspended and ended mailboxes too, so a departed colleague's mail keeps reaching the person who took over. Mail can only be forwarded to another mailbox of this organization.

Delete

"Delete" → "Delete mailbox": "The mailbox is locked right away and kept for 20 days — restore it any time in that window. After that its messages, files and calendar are purged and the address becomes available again." Deleting an active mailbox suspends it first. While it reads Deleting, "Restore" cancels the deletion. After the window a daily job purges it for good — "That mailbox was purged after its 20-day restore window — it cannot be restored." — and its addresses can be reused. Removing a domain purges any already-deleted mailbox on it immediately; see Domains and DNS records.

When someone leaves

Removing a member from Members (or their membership ending on singlesign.com) suspends their company mailbox immediately — web, phone and app passwords all stop — and its status reads Access ended. Nothing is deleted: the organization keeps the mailbox with its mail, files and calendar, and new mail to its addresses is held, never bounced. Colleagues aren't affected. The person sees the mailbox as "Acme Inc. — access ended" in their account menu until they click "Remove"; their personal mailbox is untouched.

From there, the organization chooses:

  • Transfer it to the person taking over — address and all.
  • Forward its mail to a colleague while you decide.
  • Delete it — 20 days to change your mind, then it's purged and the address is free.
  • Restore it if the person comes back — they'll need a fresh invite to be a member again; the mailbox is waiting for them.

The console puts it in one line: "Suspending locks Ana out instantly and keeps everything; deleting keeps a 20-day restore window. Neither touches their personal mail."

Sign-in security

In a member's details, Sign-in security shows how many app passwords and sessions their company mailbox has. "Revoke app passwords" disconnects their phone and mail apps within seconds until they set up new ones; "Force sign-out" ends their web sessions (within 15 minutes). Both act only on their mailbox in this organization — never on their personal mail or other organizations — and neither touches their mail.

What the organization owns — and what it never sees

The organizationThe member
Owns every company mailbox and every address on its domains.Owns their personal @singlesign.com mailbox outright — no organization can suspend, transfer or take it.
Sees each company mailbox's address, storage use, status, and app-password and session counts.Sees their own Screener, contacts, tags, mail and files — admins never can.
Can suspend, restore, transfer, forward and delete company mailboxes, and reset sign-in security on them.Chooses their default From address, sets up their own phone, decides their own Screener.
Records every one of those actions in the audit log.Sees in Mail settings what the organization's admins can and cannot do.

No role in SingleSign Business can read anyone's mail — see Admin roles and permissions.

Last updated: 2026-09-28