Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / People

Shared access and delegation

Several people can work in one mailbox: a team in a shared support@ mailbox, an assistant in a manager's mailbox, a colleague keeping an eye on the mailbox of someone who left. Access is set on the mailbox being shared, on its page under Who else can use this mailbox.

The three kinds of access

AccessLets the personExchange name
Open and readOpen the mailbox, read and file its mail, and work in its calendar and contactsFull Access
Send asSend mail that looks exactly as if the mailbox sent it: the recipient sees only [email protected]Send As
Send on behalfSend mail from the mailbox that shows both names: "Alice Andersen on behalf of Support"Send on Behalf

Most shared mailboxes want Open and read plus Send as. An assistant working for a manager usually gets Open and read plus Send on behalf, so recipients can see who actually wrote.

Give someone access

  1. Open the mailbox's page in Users & groups.
  2. Under Who else can use this mailbox, start typing the person's name and pick them from the list.
  3. Tick the kinds of access and choose Add.

To change or remove access later, untick the boxes in that person's row; unticking all three removes them.

You can grant access to a group created with Also use for permissions: every member of the group gets the access, and people you add to the group later get it automatically.

How people use the access

  • Webmail: shared mailboxes appear under Mailboxes in the sidebar. Clicking one opens it; the From field when writing offers the addresses the person may send as or on behalf of.
  • Mail apps using IMAP (Thunderbird, Apple Mail with IMAP): add a separate account for the shared mailbox and sign in with the person's own address, a backslash, and the shared address, using the person's own password:
[email protected]\[email protected]
  • Phones and Macs with an Exchange account show the person's own mailbox. Open shared mailboxes in webmail, or add them as an IMAP account as above.

Sending from a shared address in other apps

When an app sends through the server (SMTP on port 587) with a From address that is not the person's own, the server allows it only if the person has Send as or Send on behalf for that address. With Send on behalf the server adds the person as the sender, so the recipient sees both names.

When someone leaves

  1. Disable their account so they can no longer sign in.
  2. Give their manager or a colleague Open and read on the mailbox, so nothing incoming is missed.
  3. For an automatic reply ("Alice has left, please write to ..."), set it in the person's own webmail under Settings > Automatic replies before disabling the account. If they are already gone, reset their password, sign in to webmail as them to set it, then disable the account.
  4. Remove the mailbox only once nobody needs its mail anymore; removal is permanent.

From the command line

sudo oms permission add [email protected] [email protected] FullAccess
sudo oms permission add [email protected] [email protected] SendAs
sudo oms permission list [email protected]