Qboxmail features

Antispam and Antivirus service policy

All email accounts hosted on our servers are protected by multiple levels of Antispam and Antivirus. The protection concerns both incoming and outgoing emails. Our Antispam analysis systems are based on algorithms for calculating the reputation (positive and negative) of the sender IP, of the URLs contained in the messages and a series of commercial third-party filters capable of intercepting and blocking the new trends of Spam and Virus in real time. In particular, Qboxmail users are protected by specific Antivirus signatures dedicated to blocking 0-day Ransomware, or new variants of previously known attacks.

The first layer of protection is at the SMTP connection level.

All remote servers that connect to our MXs must have the following requirements:

  • A valid and qualified (FQDN) reverse DNS
  • Not be present in the main DNSBLs
  • Introduce yourself with a valid HELO FQDN

If your server or its configuration does not comply with these Best Practices you will hardly be able to deliver your emails around the network.

ANTIVIRUS Scan: The first scan is aimed at understanding if the message contains a potential threat (Virus, Malware, Phishing, Ransomware). In case our Antivirus discovers a danger, the email is silently discarded as the sender of these emails is almost always non-existent so sending a notification does not make sense.

ANTISPAM filters: The second scan is aimed at understanding if the message can be considered unwanted (Spam or Bulk email) or containing a potential threat not detected by the previous Antivirus filter. Penalties related to the content of emails and the presence of the sender IP are applied in various less relevant DNSBLs. If the penalties are lower than a certain score, the email is quarantined in the “Spam” folder of the user’s mailbox (available from Webmail or IMAP), if the penalties are above the threshold, the email is rejected with an error 500 at the SMTP dialog level. The sender of the email can thus receive a notification of non-delivery and take the necessary measures.

The Log Analyzer tool in real time, ETLive, allows you to check if the Antispam or Antivirus filter has blocked a message due to a false positive:

The Whitelists, which can be activated from the webmail, act only at the “Antispam” level. If the email comes from a blacklisted IP, from an incorrectly configured server or contains a virus, it will be rejected in any case.

Blacklists are also manageable by the user via webmail and cause the message to be sent back to the sender with a 500 SMTP type error.

Whitelists and blacklists entered by users are intended to “heal” a problematic situation temporarily. Our system is able to learn, on the basis of user reports, any problems of false positives / negatives and to adapt its filters in this sense.

The email addresses of the senders of the message must be valid internet addresses, it is not possible to accept emails from the sender to which it is not possible to send a reply to (for example domains without a correct DNS configuration or invalid or non-existent domains). If the sender domain uses SPF or DKIM the settings must be correct.

The DNSBL lists used may vary over time depending on technical factors. When they receive a connection from a blacklisted IP, return a “permanent” error 5.xx, in this case the remote server will not retry the connection and will immediately generate a bounce (error message) addressed to the sender.

Except for the Antispam analysis, the filters cannot be customized by the user. Furthermore, since the block is at the IP / DNS level on the first phases of the SMTP dialogue, the email addresses of the blocked senders are not present in the logs of our systems but only the IP addresses of the sending servers. In any case, following a block for one of the reasons given above, the sender server or the sender itself (ie the e-mail address specified in the “Return-Path” header) always returns an error message, so no email can be lost.

In any case, our technical support is always available to customers / senders to analyze cases of false positives.

There is also an Antispam and Antivirus system on our SMTP servers, this to avoid that the compromise of an email account (for example following a password theft) can lead to sending spam from our servers and penalise the reputation of our IPs. Through ETLive you can check if an account or a message has been blocked for these reasons.

Here is how the error appears in ETLive when trying to send a spam email via our SMTP:

If the attempts to send Spam are repeated over time, the email account will be inhibited by sending other messages by SMTP block. It will be the customer’s responsibility to verify the problem, generally with an Antivirus scan of his PC and subsequently a password change, and then re-enable the email account at the authenticated sending.

Working with mailboxes

You can see the list of mailboxes for each domains, simply clicking on the number of them in the domains table.

Now, you can see the list of your mailboxes with some useful data:

in order

  • status of the mailbox: if the status is not a “green check”, you can click on iit to see the details of the errors(“domains status buttons”)
  • name: if you click on it, you can edit some info
  • usage: the percetange of space remained
  • last access date
  • delete button

You can use the search field at the top of the table to filter the results, or the filter tabs

To add a new domain, use the plus button in the top part of the page.

Work with domains

Domains are the primary resource when talking about emails. You need a domain to create new email addresses, and you need to be the administrator of the domain to add it to our service.

When you are in the panel, you can access to the domain section, using the tnavbar at the the top.

Now, you can see the list of your domains, every row gives the info about the domain:

in order

  • status of the domain: if the status is not a “green check”, you can click on iit to see the details of the errors (domain_status_1, domain_status_2)
  • name: if you click on it, you can edit some info
  • number of domain alias
  • number of mailboxes
  • number of email alias
  • action button : here you can disable it, change its postmaster password or delete it

You can use the search field at the top of the table to filter the results, or the filter tabs

To add a new domain, use the plus button in the top part of the page.

Type of User and roles available on Control Panel

The Qboxmail control panel has been designed to work in a multi-level mode to provide maximum flexibility for every kind of customer, such as resellers or companies with multiple departments.

Here are the types of users, each with its own role, who can access the email management panel with different privileges:

  • Customer
  • Manager
  • Postmaster
  • Final user

The “Customer” user is the owner of the Qboxmail account and has full access to all the features by the plan purchased. Access is made with the email entered at the registration stage.

Manager” user can be activated by Customer with a Reseller Plan and now allow 2 types of configuration. In the first configuration, Managers have the same customer level management on a limited group of domains. A useful solution for customers who need limited access for their resellers. The second configuration provide to managers the same level and autonomy of the customer. This is the best way for companies with distinct IT departments to allow multiple access. You can assign a “Manager” to domains already from the first time of the creation. Email notifications sent to Managers are whitelabel and with no logos or references to Qboxmail. Managers can access to the Control Panel with an email address chosen by the Customer in the assignment, the email address may also be outside Qboxmail.

The “Postmaster” user is created automatically whenever a new domain is added to Qboxmail. He can access to the single domain within the limits (number and size of email boxes) set by the Customer. The Postmaster user can see only the emails, alias, and forward associated with his domain and can enable a number of email boxes limited to the value specified by the Customer user or Manager when creating the new domain. Access to the control panel by this user is allowes with the email address postmaster@DOMINIO and the password entered during the creation of domain.

Final User” is the last one who manage the email account of the domain hosted by Qboxmail. He can access to Control Panel to set forward, autoresponder, verify the quota and use of mailbox, the status of email services and the last access to mailbox.

If you need to manage a single domain for others, don’t create a manager, the Postmaster user is already available and enabled for that purpose.

All users access the same control panel https://panel.qboxmail.com.

Each user can change their password, create or remove a new token API needed to use the Qboxmail API.

 

Policy for authenticated SMTP service

Qboxmail guarantees a high level of deliverability of emails sent from our SMTP servers. In order to maintain a high service warranty we have set up policy about usa and sending limits on our SMTP.

Qboxmail smtp sending limits

The Authenticated SMTP of Qboxmail service is to be used in compliance with the following limits:

  • use is allowed to send personal emails by user’s email clients (Outlook, Thunderbird, iPhone, Webmail or other email clients)
  • use is allowed for sending transactional emails from your billing / ecommerce systems
  • use is not allowed for Newsletter / Email Marketing
  • the maximum attachment size you can send is 50MB (remind that many mailboxes do not accept large attachments)
  • the maximum number of recipients for each single send is 150
  • the maximum number of authentication executable within 30 minutes is 100-150 (it varies for different factors)
  • the maximum number of different IP addresses from which a user can authenticate within 30 minutes is 5
  • any other type of abuse (to affect other users’ operation) causes the temporary blocking of the SMTP service
  • messages must have a sender (From) with an active domain on Qboxmail

Starting from the above limits, a maximum of 1000 emails per day can be sent per single email account. When this threshold is exceeded, SMTP returns a “Quota exceeded (number of mails in total)” error.

Additional SMTP Sending Packages:

In case you want to use our SMTPs for sending transactional emails from billing systems, order management, ecommerce (our SMTPs are compatible with WordPress, Magento, Prestashop and almost all CMSs) you can purchase delivery packages additional to the following costs:

  • 2000 daily messages per mailbox: 3€ +VAT / month
  • 5000 daily messages per mailbox: 6€ +VAT / month
  • 10000 daily messages per mailbox: 12€ +VAT / month

You can purchase this additional message packets directly in the control panel, by selecting Domains -> Email Account -> your email -> advanced -> OUTBOUND LIMIT and choosing the desired package. The amount will automatically be included in the next invoice.

We remind you that all the emails sent by our SMTPs are automatically signed with DKIM, and you can also enable a custom DKIM signature for your domain from the control panel.

Antiabuse e antispam policy

Policies and limits on our SMTPs are necessary to prevent any blacklist entries or penalties, to prevent any “botnet” emails that could fraudulently misled a user’s password or to avoid any abuse by the same users of the service.

Policy violations include blocking an SMTP account (all other features, including email retention, will be still active) when an irregular connection to the server or e-mail is detected. Irregular activity means: a large number of SMTP authentication in a few minutes, simultaneous authentication from multiple IP addresses or sending messages containing Spam / Phishing.

In any case, the block has been designed to not get into operation during the normal email sending activity by the user through the classic email and browsing tools (MS Outlook, Thunderbird, iPhone, Webmail, or other email clients). Instead, it may trigger the block if the account is connected in automated email delivery systems (such as Sendblaster or other newsletter software) or if you send massive emails from your email client or webmail.

The account in “SMTP Block” can be unlocked (or verified if it is locked), independently, from the control panel by the Qboxmail Domain Owner selecting: Domains -> yourdomain.it -> Email Account -> select the account locked -> Limits and click on the SMTP button that will go from red to green.

If after unlocking the same user will present new abuses, the account will be blocked by our operators and will remain locked until we receive a response by customer, confirming the resolution of the problem that it has caused spam / phishing emails (typically PCs infected by virus stealing mailbox passwords). The proper PC cleaning procedure require to remove the virus / malware responsible for data theft and after, the change of password.

Supervise and tracking emails with Etlive

Selecting ETLive -> Mail Sent available in the control panel, you can get a detail of messages sent from a specific domain account. This option can help diagnose the causes of the block.

Spam from SMTP account compromised and analyzed by Etlive

The SMTP service analyses outbound emails to detect the presence of Virus or Spam if these messages contain malicious material, for the recipient or the reputation of the Qboxmail server, sending is not permitted.

Send email rate limit for free trial period

During the free trial period, the max number of messages that can be sent is 25 per day, for email accounts, in order to avoid abuse. When this limit is exceeded, the sending SMTP server returns the follow error: “Quota exceeded (number of mails in total)“. The counter is automatically reset 24 hours after the first transmission. The limit is removed once the customer is purchasing the service.

Dedicated SMTP server

Users who need to send large amounts of email without incurring these limits can choose the dedicated SMTP Service to allow unlimited emails. The cost of this service is 30€ +VAT / month. To activate it, you can contact our support technician.

Mail Time Machine

With Mail Time Machine all users can view the status of their email backups for the last 15 days.

In order to use Mail Time Machine you need to enter your email address, your password and select the day of backup. Once logged inthe interface is very similar to a webmail but with limited functionalities (we provide a read only access). By default, only main folders are displayed like INBOX, SEND, Draft, Trash and Junk. If you have created other folders you can show them by clicking the Manage Folder button at the bottom left corner (Gear icon).

Backups are performed by NetApp’s Snapshot Technology at midnight every day and contain all messages in all folders present at the backup time in the User Mailbox.

Through MTM you can:

  • see all emails in the backup
  • download single email in EML format
  • download groups of email messages in MBOX or Maildir format

To download one or more messages, select the message and click on More > Download.

Backups are read-only, so messages can not be deleted or modified. Backups are related to messages on the server, messages via POP3 are not available. Instead users who use IMAP will find an exact “picture” of their mailbox.

If the users need to perform a full recovery of their Mailbox or just some folders, for example due to an accidental deletion, they can request to Qboxmail support staff to perform the operation under the conditions described in Backup and restore of mailbox accounts and emails.

Availability of backups is guaranteed through access to Snapshots present on replication storage which assures to the user the best availability of the service and the assurance that replication and security systems of data implemented in Qboxmail are working properly.

ETLive

With ET live, you can easily track the activities of all your domains. You will have access to differents kind of info:

  • log in, and log out info of your domains’ acounts
  • errors and failed attempts
  • complete logs about your sent, received and enqueued emails

To use ETLive, click on its button in the top navbar, and choose the kind of info you need to see.

Once you’ve made the choice, use the Domain field to see the logs for the choosen domain.

Backup and restore of mailbox accounts and emails

Qboxmail provides a free email Backup service included in the monthly fee.

In case of missing emails without a personal backup available, the customer can request a recovery from our backups.

Our infrastructure provides regular process and system backups about user data and settings. These backups are executed several times a day, daily or weekly, (it depends on the type of data) and they are available to the technical staff in order to keep user data and infrastructure functionality safe from technical issues or human errors.

The recovery is not guaranteed in the case of email deleted immediately before the backup process or emails managed via POP3.

In order to check the status of backups or restore deleted emails, the users can use Mail Time Machine, a tool that provides backups for the last 15 days.

If the missing data is available to restore, it is possible to open a ticket to our technical staff, the backup restore costs 50€ + taxes that will be billed to the customer.

For all customers and users it is raccomended to schedule personal email and data backups on their devices and computers.

Alias Email

An alias email it is a simple “fake” account, that fowards all the messages that receive to other destinations.
You can create a new alias domain simply clicking on the number of them in the domains table, and then on the plus button at the top:

 

 

Then you’ll be asked to insert the email account destinations that will received the messages sent to this alias.

Alias Domain

With an alias domain you can have a second email address where you can receive messages. When you create one, all the Mailboxes and Email aliases of the original domain are present in the alias domain.

You can create a new alias domain simply clicking on the number of them in the domains table.

And click on the plus button at the top of the Alias Domain page

You will be asked to enter the alias for the domain, and after that, you need to verify the ownership of it before it can be active..

Login Free trial