Backbuild Mail: Email at Your Own Domain

Backbuild Mail is the email client and mailbox service built into the Backbuild workspace. You receive and send mail at your own domain, sort it with folders and labels, search the full text of every message, and read it live across every device you sign in from. This page teaches what Backbuild Mail does today, how your mail is stored and protected, and, so you can choose with clear eyes, what it does not do.

Email at Your Own Domain, on Every Plan

Email at your own domain is included on every Backbuild plan, including Free. You link a domain you own, and Backbuild Mail walks you through the DNS records that let you receive and send as you@your-domain. There is no separate mailbox subscription and no add-on: a mailbox at your domain is part of the workspace the same way Calendar, Docs, and Sheets are. The Free plan includes two linked domains, a primary domain and a separate one for marketing and newsletters, and paid plans lift the linked-domain limit. Mail you send through your Resend account carries no Backbuild allowance and no Backbuild charge; Resend bills it under your Resend plan. Current plan details are listed on the pricing page.

Receiving and Sending

Backbuild receives inbound mail for your domain directly; a domain that uses Cloudflare DNS can instead route it through Cloudflare, an option set when the domain is linked through the REST API. Either way, a message addressed to your linked domain is parsed, filed into the right mailbox, run through your filters, and appears in your inbox in real time, shown under the address in its From line (the address sender authentication checks), never under the bounce address a mailing service delivers it from. Outbound mail is sent through your organization's Resend account, chosen per sending domain, and signed with DKIM for the domain you verify in that account, so it authenticates cleanly at the receiving end (see Outbound Routing and Allowances). Messages sent from a mailbox you create in the app carry a short footer line naming the Backbuild free email service.

  • Real inbound mail: you receive messages sent to your domain, not just send from it.
  • Authenticated sending: outbound mail is DKIM-signed by Resend for the domain you verify in your Resend account, and the setup wizard sets up your domain's DMARC policy.
  • Unknown addresses are refused: mail to an address at your domain that has no mailbox is returned to the sender as undeliverable; a catch-all mailbox is not available yet.
  • Send protections: recipients who previously bounced or complained are removed before a send, which keeps the domain's reputation clean.

The Guided Domain Setup

Linking a domain is the step people dread with self-run email, so Backbuild Mail turns it into a wizard. You enter the domain, and the setup screen publishes the DNS records for you through your connected Cloudflare account, or with a GoDaddy access token or Amazon Route 53 key that it uses once and never stores, or, on Namecheap and any other DNS host, shows you the exact records to add with a copy button for each; it then checks every record for you and confirms each step with a checkmark. These are the MX records that route inbound mail and the DMARC record that sets your domain's policy. The SPF and DKIM records that sign your outbound mail come from your Resend account, where you verify the domain before it sends. You do not need to understand each record to get a working mailbox at your domain.

Sorting: Folders, Labels, and Filters

Backbuild Mail sorts mail the way a heavy email user expects. You get the standard system folders, Inbox, Sent, Drafts, Archive, Spam, and Trash, the Starred and Important views, and your own labels. A message can carry several labels at once, and you apply them to one message or a whole selection at once. Filters are rules you define once, a set of conditions and the actions to take, that run automatically on new mail as it arrives.

  • System folders and custom labels: file mail into folders, or tag it with as many labels as you like.
  • Server-evaluated filters: conditions map to actions such as label, move, star, or mark read, applied on arrival.
  • Sender authentication: every received message is checked with SPF, DKIM, and DMARC when it arrives, and DMARC ties the result to the domain in the From line you see.

Search That Reads the Whole Message

Backbuild Mail search covers the full text of your mail, the sender, the subject, and the message body. Because the mailbox index lives on the server, a search returns matches from inside the body of old messages, not just recent headers. A search can be narrowed to the subject with subject:, and single filters such as is:unread, is:starred, has:attachment, and label:"name" list matching mail. Sender, recipient, and date operators, and combining a filter with words, are not supported yet; the details are in Labels, Filters, and Search.

A Live, Multi-Device Client

An open mailbox is a single live object shared by every device you connect from. New mail, reads, stars, label changes, and deletes propagate in real time to every open client, so your devices never disagree about what you have read. The layout matches what people expect from a modern mail client: a left rail of folders and labels, a message list, and a reading pane you can place below the list or to its right, or turn off. Keyboard shortcuts are there for the people who live in their inbox.

Several Mailboxes, One Screen

Email always opens on your own inbox, the oldest mailbox you own yourself. When you can read more than one mailbox, such as a second address you own or the inbox of a virtual worker you run, a mailbox switcher at the start of the Email toolbar moves you between them, grouped as My inbox, Other inboxes, and Virtual workers. A virtual worker's inbox belongs to the worker, and whoever owns the worker holds the owner's rights on it; sharing the worker with a colleague does not share its mail. See Work From Several Mailboxes.

Composing Mail

The compose window is a rich HTML editor with attachments and a draft that saves itself as you write.

  • Rich or plain: format with bold, italic, lists, alignment, color, headings, and links, or write plain text.
  • Draft autosave: your draft is saved continuously as you write, so a closed tab does not lose it.
  • Attachments: attach files up to 25 MiB each, stored and de-duplicated per mailbox; a message must stay within 5 MiB in total to send, with attachments counted at their encoded size.
  • Open tracking: a message sent in Rich mode carries a small tracking image, and your Sent folder shows whether it was opened; a Plain message is not tracked.

How Your Mail Is Stored and Protected

Every message you receive is written as an immutable file to durable storage before it is accepted, the copy of each message you send is stored the same way once it has gone out, and the mailbox index is derived from those files, so your mail survives even if the live index is rebuilt. Mail is encrypted in transit over TLS and encrypted at rest in storage. Every read and write, opening a mailbox, fetching a message, fetching an attachment, sending, changing a label, editing a filter, is authorized against your identity and your organization's roles, and mailbox actions are recorded in an append-only audit trail. Inbound HTML is sanitized before it is shown, and remote images are proxied, so a message cannot run code or quietly phone home when you open it.

Being precise matters here, because email security is a field where overstating protection does real harm. Backbuild Mail is not end-to-end encrypted, and it is not zero-access: the service holds the keys, and the server can read message bodies, which is what makes server-side full-text search and HTML sanitization possible. If your requirement is that the provider be technically unable to read your mail, Backbuild Mail is not built for that model, and you should choose a zero-access provider. Backbuild does include a separate zero-knowledge, post-quantum password and secrets manager in the same workspace, documented under Security and Compliance, but that zero-knowledge property applies to the vault, not to mailbox contents.

Access Through the Backbuild Client

You read and send Backbuild Mail through the Backbuild web app and the Backbuild desktop app for Windows and macOS. Backbuild Mail does not expose IMAP, POP, or SMTP endpoints, so you do not connect a third-party mail program such as Apple Mail or Thunderbird to it. If connecting an external mail client over IMAP is a requirement for you, that is a real limitation to weigh.

Where Backbuild Mail Fits

Backbuild Mail is the right choice when you want professional email at your own domain, set up without wrestling DNS, that lives in the same workspace as your calendar, contacts, documents, sheets, and files, with real-time sync, strong full-text search, and role-based access and audit logging on every plan, including Free. It is not the right choice when your defining requirement is that the provider be cryptographically unable to read your mail, or when you must connect an external IMAP client. Choosing well means matching the tool to the requirement, and this page is written so you can.

Learn Backbuild Mail Task by Task

This page is the overview. The Backbuild Mail documentation teaches each job end to end: