Skip to the topics

Help & how-to

FlashMail Express — everything your team needs, on one page

The everyday job

Nine times out of ten this is the whole thing. The console answers one question — what email do you need? — and then gets out of the way.

Paste the client's address, or type their name

  1. 1Paste anything you have: a full address, Name <address>, or a bare name. The address's own domain is discarded — which domain the mailbox lands on is decided by the selector, not by what you pasted.
  2. 2The console checks the mailbox list it already has in memory and shows you the options. Create appears only if the name is genuinely free; if it already exists you get Open instead, and near-misses are listed in amber.
  3. 3Press Enter to run the first option, or click the one you want.
  4. 4The inbox opens in a new tab, already signed in and pointed at the inbox itself. Read the OTP, paste it into the application.

If the inbox tab does not open

The console claims the new tab at the moment you click, before it talks to cPanel, so a slow create cannot lose it. If you still get “Your browser blocked the webmail tab”, your browser is blocking pop-ups for this site:

  • Chrome/Edge: the blocked-pop-up icon at the right of the address bar → Always allow.
  • Safari: Settings → Websites → Pop-up Windows → Allow for this site.
  • The mailbox was still created. Nothing is lost — open it later from the Mailboxes view, or with /open.

Commands

Faster than the form once you know them. They run inside your browser — no AI key, no network call, no cost — so they work even when nothing else is configured. The slash is optional (new anjali verma works), and /help prints this list in the conversation.

Command What it does
/new anjali verma Creates anjali.verma and opens the inbox. Add a size (500mb) or a domain (on the second domain) anywhere in the line.
/open anjali.verma Opens a mailbox you already have a password for. If the name is ambiguous it asks — it never guesses, because opening the wrong client's inbox is a real incident.
/find anjali Searches every mailbox on the account and puts the matches in the list.
/pass anjali.verma Sets the mailbox to your team's standard password and opens it. This is the path for an older mailbox nobody has the password for.
/del anjali.verma Deletes one mailbox, permanently, after its own confirmation dialog. Never inferred from anything else you type.
/help Prints the command list into the conversation. /clear empties it.
/ai make a mailbox for… Forces a message to the AI provider. Only available if your administrator configured one; the header says where free-form text goes. Off by default.

A typo is answered, not guessed: /nwe comes back with “Did you mean /new?”. A bare name or an address is offered rather than acted on, because it is ambiguous — but /new is an instruction and runs straight away.

The three views

The tabs at the top of the page. Nothing is thrown away when you switch — a half-typed name or a result you have not copied yet is still there when you come back.

Inbox

The front door, and where most people stay. The box, plus the inboxes you opened recently — which is what makes the second and the twentieth OTP of the morning a single click.

Mailboxes

The list and the search: two scopes, copy buttons, the size and fill level of each mailbox, and the export/backup buttons.

Advanced

The full create form — single or a whole list — with the account, domain, space and password controls. Everything the chat can do, with every decision visible.

Domain, space and password

The three decisions the form asks for, and the ones people get wrong.

Which domain the mailbox lands on

The account may serve several domains and subdomains; they are all in the Email domain selector, with the everyday one already chosen. If the account has only one, the selector hides itself. A domain your administrator has not listed cannot be used — the server refuses it, deliberately, so a typo cannot put a mailbox somewhere unexpected.

Size — and why a small mailbox can bite

Most of these mailboxes are throwaway, so the everyday size is deliberately small. But a small mailbox fills with spam over a year, and a full mailbox silently rejects new mail — including the OTP you were waiting for. The list shows a fill percentage and colours it as it approaches the limit. For a mailbox you plan to keep, choose a bigger size now.

One rule worth knowing: only a size you actually type changes the size. Typing /new anjali with no size leaves the form's setting alone, so a mailbox can never be created at 22 MB while the screen says 250 MB.

The three password choices

Standard — your team's fixed password for the domain, applied on the server. It never travels through the browser before the mailbox exists, and it means one password your staff already know opens every mailbox made this way. Fine for a 22 MB activation inbox; think twice for a client's long-term mailbox.

Random — generated on the server, shown to you once. Use it for anything long-lived. cPanel never reveals a mailbox password through any API, so if it is not copied at the moment of creation it is gone — though you can always set a new one.

Custom — you type it, within the length the administrator allows. This option can be switched off for a domain, in which case it is greyed out.

Whichever you pick, the password is stored only in this browser against the mailbox you made. Which is why the list has Backup and Restore — and why clearing your browser data loses the passwords, though never the mailboxes.

Creating a list at once

On Advanced, switch from One to List. Paste the names or drop in a file; the account, domain, space and password controls stay on screen, because a batch needs exactly the same decisions as a single create.

What you can paste or upload

  • One name per line — and a full address works too; a foreign domain keeps the name and uses the selected domain, exactly like the single field.
  • Name <address> straight out of an inbox.
  • Comments starting # or // are ignored.
  • A .csv, .json or .txt file. CSV may carry a per-row size column. Files are read in the browser — nothing is uploaded anywhere.
# a comment, ignored
anjali verma
[email protected], 500
Kavita Rao <[email protected]>

Read the plan before you run it

Nothing is created until you confirm; first you get a line saying what would happen, and every row is colour-coded:

  • Will be created — free on the server and unique within your list.
  • Already exists — it is on the account, so it is skipped rather than duplicated.
  • Duplicate in this list — two lines reduce to the same mailbox. Caught on purpose: two applicants sharing one inbox would each receive the other's OTP.
  • Needs fixing — unusable, with the reason beside it.

The plan also warns if the list is longer than your hourly allowance, so a long run cannot stop halfway without warning first.

Finding a mailbox again

The promise that matters: a mailbox from eleven months ago is two seconds away, not an archaeology project in cPanel.

Two scopes

This browser searches the mailboxes you made here, with their passwords. Server searches everything on the account, including mailboxes that existed before this tool did. The server list is loaded once after sign-in and filtered in memory, so typing is instant and costs no requests.

If you search in the first second after signing in, before the list has finished loading, you may see “No mailboxes matched” when there are matches. Wait a moment and search again — the status line says how many mailboxes are loaded.

Opening a mailbox nobody has the password for

A row that predates this tool, or was made by hand in cPanel, has no password here — so instead of Webmail it offers Set password & open. That sets it to your standard password and opens the inbox. Do it again later and nothing changes: it is idempotent, and it never touches the mail inside.

Worth telling a client when you do it: if they were using that mailbox with their own password, the old one stops working and they will need the new one. There is deliberately no bulk version of this.

The New badge

cPanel has no mailbox creation date — the one timestamp it exposes is written on first use, not at creation. So the console records the first time it sees each address, and flags anything that appeared within the last week. It means “this console had not seen it before”, not “created on this date”.

When something goes wrong

The messages you are most likely to meet, and what each one actually means.

“Incorrect username or password.”

Check the login, not just the password. A username typed in capitals is fine — the server lowercases it — but a dot is not interchangeable with an underscore.

If it keeps failing, remember that only failed attempts count towards the lockout, and there is a 15-minute cooldown after too many. Ask your administrator rather than guessing repeatedly.

“Too many failed sign-in attempts” / a 429 while creating

Two different limits. Sign-in failures are counted per person and per network, with a 15-minute cooldown. Creations are counted per person per hour, so a colleague working at the same time does not spend your allowance — but a busy hour can still run out, and the plan tells you before you start a list.

Wait, or ask your administrator to raise the limit in api/.env.

It asked me to sign in again

Sessions last a fixed number of hours and then expire, whichever tab is open. Closing a tab does not sign you out — that is deliberate, so you can open an inbox in a new tab without losing the console.

Your saved mailboxes and passwords are untouched by a sign-out. They live in the browser, not in the session.

The search says “No mailboxes matched” but the mailbox exists

Two causes, in order of likelihood. First, the list may still be loading — it arrives once after sign-in and the status line says how many are loaded; wait a moment and search again.

Second, the mailbox may be on a domain that is not in your administrator's list. The console only shows and creates mailboxes on the domains it is configured for, even though the cPanel account may serve more. Ask them to add it.

“This origin is not allowed to use the proxy.”

The console is being opened at a different address from the one the server was configured for — a different hostname, or http instead of https.

Use the address your administrator gave you. If your team has a short link that redirects, the final address must still be the configured one — the check is exact.

“Could not reach the proxy” or a failure on every create

Nothing that talks to cPanel will work until the server can reach its own API. The header's status pill is the first thing to look at: it turns amber or red when the console cannot reach the proxy, which is a different fault from the proxy failing to reach cPanel.

Either way this one is for your administrator — from your side there is nothing to retry.

The result said “Mock profile — this mailbox was simulated”

You are on a demo account. It fakes every response so the interface can be practised and shown without touching a real server, and the password it shows is a dummy. Nothing was created anywhere — switch to a real account to make a real mailbox.

I lost the saved passwords

Passwords are kept in the browser that created the mailbox, so clearing site data, using a different machine, or a private window loses them — the mailboxes are unaffected and still exist on the server.

Recovery is one click per mailbox: find it in the Server scope and use Set password & open. For the future, the list has Backup — take one occasionally, and after a busy week.

What it will not do

Stated plainly, so nobody plans around something that is not there.

  • It does not read mail for you. The inbox opens already signed in, and a person reads the code. That step stays human.
  • It does not send mail. It creates and opens mailboxes; what arrives in them comes from whatever you signed the client up to.
  • It never deletes on a timer. There is no expiry and no cleanup. Deletion is one mailbox, by a person, after confirming.
  • It cannot set passwords in bulk, because each reset locks out whoever was using the old one.
  • It only shows mailboxes on its configured domains. Others on the same cPanel account stay invisible by design.
  • It cannot tell you who a mailbox is for. The address is all it stores — if you need an applicant reference, put it in the name.

For administrators

The parts staff never need, kept in one place.

Settings is read-only on purpose

It shows what is active, the configuration health check, the profiles and the feature flags — and lets you set your own browser preferences. It deliberately cannot change server configuration: the file it would write holds a cPanel API token and your standard mailbox password, and a web form that can write that file is the one thing this tool will not ship. Change those on the server, in api/.env.

Who created which mailbox

Every creation, password reset and deletion is written to a server-side log with the signed-in staff name, the address, the size and the time — and never a password. It is the answer to “who made this?” months later, and it is not in this interface; read it with php tools/audit-report.php.

Adding a domain

Create it in cPanel → Domains, give it MX records, then add it to CPANEL_<ID>_DOMAINS. No restart is needed. The Settings drawer compares your list against cPanel's and reports anything cPanel serves that you have not offered — which is how you notice a domain you forgot to add.

Full documentation

docs/README.md explains how the tool works, docs/DEPLOY.md how to put it on a server, and docs/EXTENDING.md how to change it. None of them ship with the console, which is why they can be blunt about its limitations.