Apps
Mailboxes at your own domains, shared by the members you choose, sent and received through Amazon SES.
Mail at mail.gov.vin sends and receives email at your organization's own domains. A mailbox is an address, like support@example.com, with members: everyone in it reads and sends from it. A person can belong to several mailboxes.
Each mailbox also has its own calendars and contacts, in the same app.
Access
| Scope | Allows |
|---|---|
mail:read | Read and organize mail in mailboxes you're a member of. |
mail:send | Send and save drafts from those mailboxes. |
mail:admin | Domains, mailboxes, aliases, catch-all addresses and usage. Owners and admins have it. |
Being an admin doesn't open a mailbox: admins read only the mailboxes they're members of. Keys have no mailboxes. See Roles and scopes.
Set up a domain
Mail → Settings → Domains → Add a domain (needs mail:admin). A domain belongs to one organization, and only the platform organization can add domains under gov.vin.
Mail then lists the DNS records to add, named relative to your zone:
| Record | Type | For |
|---|---|---|
| DKIM | One CNAME at si1._domainkey → a name under dkim.mail.gov.vin | Signing what you send. Required for sending. The platform generates the domain's signing key and publishes the public key under its own zone; the private key is held only by Amazon SES. |
| MX | MX at the domain, priority 10 | Receiving mail. |
| MAIL FROM | MX and TXT at bounce | Bounce handling. |
| SPF | TXT at the domain with include:_spf.mail.gov.vin | Optional. If the domain already has an SPF record, Mail shows it with the include added before its all term; keep one SPF record. |
| DMARC | TXT at _dmarc | Optional. Your existing policy is kept; without one, Mail suggests p=quarantine. |
| Autodiscover | SRV at _autodiscover._tcp | Optional. Lets Apple devices find the server from an address alone. |
Copy all and Download zone file give the records as a zone file snippet for DNS hosts that import one. On Cloudflare, set the CNAME record to DNS only.
Mail runs in the region the location registry assigns to mail for the default location. Where mail isn't available yet, adding a domain says so.
The domain then moves through:
| Status | Shown as | Means |
|---|---|---|
pending | Waiting for DNS | Required records are missing. Mail lists which. |
verifying | Verifying | The DKIM record is in DNS; Amazon SES is confirming it, usually within minutes. |
active | Active | Verified for sending. Mail still lists any records that are missing. |
error | Needs attention | SES gave up after 72 hours without finding the DKIM record, or the domain's SES identity is missing. Remove the domain and add it again. |
Domains are checked in the background on the same schedule as custom domains: every 5 minutes on the first day, hourly for a week, every 6 hours up to 30 days. Check now checks right away. Checks ask your zone's own nameservers.
Remove domain stops accepting and sending mail for it. Delete its mailboxes first.
Mailboxes and aliases
Settings → Mailboxes → New mailbox (needs mail:admin):
- Address: the part before
@(letters, digits, dots, dashes and underscores) and one of your domains. - Sender name: shown to recipients.
- Members: people in the organization who read and send from it.
Each address belongs to one mailbox. Aliases are more addresses at your domains that deliver to the same mailbox. Delete mailbox deletes all of its mail, drafts and aliases; it can't be undone.
Receiving
Mail to one of your domains goes to:
- the mailbox or alias with that exact address, else
- the same address without a
+tag(sales+leads@example.comgoes tosales@), else - the domain's catch-all mailbox, if one is set (Settings → Domains → Catch-all).
Mail to any other address is dropped without a bounce, so forged senders never receive backscatter. Messages with a virus are discarded. Messages SES marks as spam, and messages that fail DMARC for a domain whose policy is reject, go to Spam.
Reading and organizing
Views: Inbox, Starred, Sent, Drafts, Archive, All mail, Spam, Trash and your labels. Conversations are grouped into threads.
- Archive, move to inbox, trash, mark as spam or not spam, mark read or unread, star, and label conversations, up to 100 at a time.
- Delete permanently works from Trash and Spam only.
- Labels belong to a mailbox; a mailbox can have up to 200.
- Search matches every word (2 characters or more, up to 5 words) against senders, recipients, subjects and the start of each message's text, outside Trash and Spam (or within them while you're in that view).
- Show the original of a received message (
.eml), and download attachments.
Sending
Compose has a rich text editor, attachments, and Cc and Bcc. Replies are threaded with the original. Mail warns about recipients that bounced or complained before. Drafts save as you write.
- The domain must be
activeto send. - Your signature, under Settings → Signatures, is added below new messages, replies and forwards.
- Your organization's plan sets how many messages it can send per day, how many recipients a message can have, and how large a message can be; Mail shows them in compose. Messages are at most 40 MB, the Amazon SES maximum.
The mail administration API reports messages sent, received, bounced and complained about per day.