Hosted email
Mailboxes on your own domain, hosted by Shop Commander — enabling a domain, setup links and resets, aliases, catch-all, DMARC and removal.
Hosted email gives your shop mailboxes on its own domain (for example info@yourshop.ca), run by Shop Commander. It appears as Settings → Email when the Hosted Email feature is on.
What it needs
Hosted email needs Shop Commander to manage the domain's DNS. Where the domain is registered does not matter: a domain you keep at your current registrar works as soon as its DNS is managed by Shop Commander (see the Domains tab). A domain whose DNS you manage yourself shows a reason instead of an Enable email button; use Switch DNS management in the Domains tab first. Moving the registration is never required.
Enabling a domain
Pick a ready domain and choose Enable email. Shop Commander creates the mail records (MX, SPF, DKIM, DMARC and the autoconfig entries) in the domain's DNS, sends the domain to the mail server, and waits until public DNS shows every record. The domain reads Waiting for DNS during that time and Active afterwards; Check now re-checks immediately. If a required record later disappears, the domain reads Sending paused — incoming mail still arrives, and sending resumes when the record is back.
Mailboxes
New mailbox asks for the address, an optional display name, storage, a daily send limit and, optionally, the team member the mailbox belongs to. Choose how the password is set:
- Send a setup link (recommended) — a single-use link is shown once so you can hand it to the person. They open
/mailbox-setup, choose their own password, and see the mail-app settings. Nobody at the shop or at Shop Commander ever sees the password. - Set an initial password now — you type a password of at least 12 characters; it is hashed immediately and cannot be recovered later.
Per mailbox you can:
- Setup link — issue a fresh link while the mailbox is still waiting for a password (any older link stops working).
- Reset password — the current password stops working immediately; the person needs the new link. Mail keeps arriving.
- Lock / Unlock — locking stops sign-in within about a minute but keeps receiving mail. A lock applied for suspicious activity is cleared only by a password reset.
- Disable / Enable — a disabled mailbox neither signs in nor receives mail.
- Edit — display name, storage and daily send limit.
- Remove — type the address to confirm. The mailbox is disabled at once and its mail is deleted after a 7-day hold; Cancel removal is available until then.
A team member with a linked mailbox can change its password from their own Profile page.
Aliases and catch-all
An alias forwards an address to one or more mailboxes or outside addresses (outside forwards are limited more strictly). postmaster@ and abuse@ are created automatically, are required by the mail system, and cannot be deleted — change where they go instead. A catch-all mailbox receives mail sent to any address on the domain that does not exist; leave it unset to bounce unknown addresses.
DMARC and sending limits
The DMARC policy defaults to quarantine; reject becomes available after 14 days of verified quarantine reporting; monitor only exists for troubleshooting. Changing it rewrites the DNS record for you. Daily send limits exist per mailbox and per domain; exceeding one defers mail rather than rejecting it.
Turning email off
Turn off email (type the domain name to confirm) disables every mailbox now, deletes their mail after a 7-day hold, and publishes "no mail here" records so nobody can pretend to send from the domain.
What Shop Commander staff can and cannot do
Platform staff can suspend a domain, lock or unlock a mailbox, schedule a purge and allow email on a domain with external DNS — every action needs a reason and a re-authentication, and is recorded. They cannot read mail, set or see a password, or issue a setup link.