| document_id | how-to-use |
|---|---|
| title | How to Use MailStack |
| document_type | how-to |
| audience | mailbox-users-and-administrators |
| status | active |
| version | 1.3.0-rc.1 |
| last_reviewed | 2026-07-25 |
- Open the configured MailStack application URL.
- Enter the administrator-provided username and password.
- Select Sign in.
- Confirm that the dashboard shows only the mailboxes assigned to the account.
- Use the persistent sidebar on desktop. On tablet or mobile, select the menu button to open the navigation drawer and close it with the backdrop, Escape key, or a selected destination.
- Open the account menu in the top bar and select Log out when finished.
At desktop widths of 1200 pixels or more, the sidebar control can collapse or expand the navigation. That preference is stored only in the current browser. There is no public registration or in-application password-change workflow in this release.
- Select Create mailbox.
- Enter the local part that will appear before the configured mail domain.
- Administrators may select active ordinary users to assign; ordinary users are assigned to their own new mailbox automatically.
- Select Create mailbox and Maildir.
- Confirm that the address appears in Mailboxes with an active status.
A deleted or previously reserved address cannot be reused. Administrators can disable or enable a mailbox from the mailbox list.
- Open Mailboxes and select Open inbox.
- Search by sender address or subject when needed.
- Use the read-state filter for Unread or Read messages.
- Use the attachment filter for messages with or without attachments.
- Open a message to view its metadata, plain text, safe HTML, and attachments.
- Select Mark unread when the message should return to the unread queue.
Opening a message marks it read. Live updates are available on an unfiltered first inbox page and on the dashboard.
- Open the authorized message.
- Review the attachment filename, detected MIME type, and size.
- Select Download.
- Scan the downloaded file with approved endpoint protection before opening it.
MailStack enforces mailbox and attachment authorization, protected paths, private caching, and forced-download headers. The interface explicitly states that attachments are not antivirus scanned by MailStack.
- Select Enable notifications in the Mail section of the authenticated sidebar.
- Approve the browser permission prompt.
- Leave MailStack open in a supported browser to receive new-message notifications.
- To disable notifications later, change the permission in the browser site settings.
Notifications are scoped to messages the signed-in user can access.
A delete action is visible only when the administrator has granted the required permission. Message deletion preserves the source email under the current retention design. Mailbox deletion requires typing the full address, soft-deletes the mailbox, and permanently reserves the address. Use destructive actions only after confirming retention and operational requirements.