← Back to blog

How to share a team mailbox without sharing the password

What a shared password actually costs, the four ways to give each person their own access, and what each one requires. With the documented limits of each.

Four ways to give several people access to one mailbox without handing out the password: Gmail delegation, a Microsoft 365 shared mailbox, a Google Group with Collaborative Inbox, or a shared inbox connected over OAuth. Each has documented limits worth knowing before you pick. What they all share is the property that matters: access is granted per person and revoked per person, so a departure costs one click instead of a new password for everybody.

Why the password gets shared in the first place

It is not carelessness. You create contact@ on a Friday because a client needs an address to write to, you choose a password, and you give it to the two people who will read it. It costs nothing, needs no admin console, and everyone understands it immediately.

It also fits how a small team sees itself. We trust each other, so why build barriers. The trouble is that consumer Gmail and Outlook.com accounts were built for one identity, and a shared password works against the grain of the product rather than with it. What looks like a shortcut on day one becomes structural the day the team changes shape.

What it actually costs

Four costs, in the order teams meet them.

The provider locks the account. This is usually the first symptom, and it arrives without warning. Sign-ins from several places at once look like an intrusion, and the verification code goes to whoever created the account. If that person is in a meeting or on holiday, the whole team is locked out of its own contact address. Google’s own documentation puts a practical ceiling here even in the supported setup: with typical use, about 40 delegates can access one Gmail account at the same time.

Nobody knows who did what. Every reply left under the same identity. When a client says “someone told me 450”, you cannot find out who, or what else they promised. There is no accountability to build on, and there is nothing to hand over when the person who knew leaves.

A departure becomes a chore for everyone. Someone leaves, so the password has to change, so the new one has to be given to everybody else. It gets postponed, which is why former colleagues routinely keep access to a company mailbox for months after leaving. Nobody decided that: it is what happens when the fix costs five people an interruption.

The exposure widens with every person. A password known by five people is a password that will end up in a chat thread, a note app, or reused on a site that gets breached. If your mailbox holds client, family or member data, that is a data protection question rather than an internal convenience one.

Worth knowing: Microsoft treats this as settled. A Microsoft 365 shared mailbox does have a matching account with a password, but Microsoft describes it as system-generated and not intended for use, and instructs you to block sign-in on it and keep it blocked.

Four ways to do it properly

Option Who it fits What it requires Documented limits
Gmail delegation One address, a few people, all on Google Delegation allowed by the admin on Workspace 10 delegates on a personal account, up to 1,000 on work or school, about 40 connected at once
Microsoft 365 shared mailbox A company already on Microsoft 365 An Exchange admin, and a licensed mailbox for each person 25 users maximum, 50 GB unlicensed, no external access
Google Group as Collaborative Inbox Teams comfortable inside Google Groups Conversation history on, plus moderation permissions Assigning requires “Who can moderate metadata”
Shared inbox over OAuth Mixed providers, or a team that also needs coordination Connecting the mailbox once Depends on the tool, not on the mailbox

Gmail delegation is the lightest. The owner grants access from their settings, the delegate opens the mailbox from their own Google account, and revocation is one click. One thing to check before you build a customer-facing address on it: when a delegate sends, their own email address appears. And a detail that has just changed, so older articles get it wrong: delegated accounts used to be web only, but Google announced mobile access for iOS and Android and resumed that rollout on 21 August 2026, so it is arriving rather than fully everywhere.

A Microsoft 365 shared mailbox is the sturdiest if you are already on Microsoft 365, and the most administrative. Permissions are assigned per user from the admin centre, each person needs their own licensed Exchange Online mailbox, and the shared mailbox itself needs no licence up to 50 GB. Two constraints to note: it maxes out at 25 users, and you cannot give access to anyone outside your organisation, a Gmail account included.

A Google Group with Collaborative Inbox adds ownership on top of a list: take a conversation, assign it, mark it complete. It needs conversation history enabled and the right moderation permission, and a volunteer who has neither can read and reply while being unable to claim anything.

A shared inbox connected over OAuth is the option that does not care which provider you are on. You grant a revocable token rather than a password, and each person signs in with their own account.

What to do when someone leaves

The whole point of the four options above shows up on this day. The procedure is the same for all of them, and it takes a minute.

Revoke that person’s access, individually. Nobody else is interrupted, and no password changes. Then check the sending address of anyone who remains, because a departure is when you discover that replies have been going out under an individual name. Finally, reassign whatever they had open before you lose track of it: an absence turns into customer silence when nobody knows what was in flight.

What you should not have to do is change a password and redistribute it. If that is still your procedure, it is the thing to fix first, before any tooling question.

What Trupeo does

You connect the mailbox once, over OAuth for Gmail, Google Workspace, Outlook and Microsoft 365, or with IMAP credentials for any other provider. Your team members are then invited by email and each creates their own account. Nobody else ever sees the mailbox credentials, and removing someone is one click that leaves everyone else untouched.

Because each person is identified, the work stays legible: each conversation has one owner, an open or done status, and internal notes attached to the message. When a colleague leaves, the history of what they sent and noted stays where it is, which is what makes a handover possible three months later.

See the features or our pricing. The security angle is covered in shared inbox security risks, the provider ceilings in shared mailbox limits, and the whole subject in the complete shared inbox guide. If you run a volunteer organisation, our advice for non-profits is more specific.

Frequently asked questions

How can several people access one mailbox without the password?

Four ways. Gmail delegation, where each delegate opens the mailbox from their own Google account. A Microsoft 365 shared mailbox, where permissions are granted per user from the admin centre. A Google Group with Collaborative Inbox. Or a shared inbox connected over OAuth, which works across providers. All four grant and revoke access per person.

Why is sharing a mailbox password a problem?

Because the provider can lock the account when it sees simultaneous sign-ins from several places, nobody can tell who replied what, and every departure forces a password change for the whole team, which is why it gets postponed. Microsoft’s own guidance for a shared mailbox is to block sign-in on its account and keep it blocked.

Does a delegate need the mailbox password?

No. That is the point of delegation: the delegate signs in with their own credentials and opens the shared mailbox next to their own. The owner grants access from their settings and can revoke it in one click without changing anything.

Will my colleagues’ replies come from the shared address?

Not automatically. With Gmail delegation, when a delegate sends, their own email address appears, which is fine internally and usually unwanted on a customer-facing address. Check it by sending yourself a test from each person’s account before you rely on it.

What happens to the emails when someone leaves?

With individual access, nothing: you revoke that one person and the mailbox is untouched for everyone else. What matters as much is reassigning whatever they had open, and checking that their replies were going out from the shared address rather than their own, since anything sent under their name will get its follow-up in a mailbox you can no longer open.


Sources:

  • Delegate and collaborate on email: the 10-delegate limit on a personal account and up to 1,000 on a work or school account, the note that about 40 delegates can access a mailbox at the same time with typical use, what a delegate can and cannot do, and the fact that a delegate’s own address appears when they send.
  • Work with delegated Gmail accounts from mobile devices: mobile access for delegated accounts on iOS and Android, previously web only, with the rollout resumed on 21 August 2026.
  • About shared mailboxes in Microsoft 365: the system-generated password not intended for use and the instruction to block sign-in, the 25-user maximum, the 50 GB of storage without a licence, the licensed Exchange Online mailbox required per user, and the impossibility of granting access to people outside the organisation.
  • Use a group as a Collaborative Inbox: taking, assigning and completing conversations, and the moderation permissions each action requires.

Ready to try a shared inbox?

Trupeo helps small teams manage email together. Free 30-day trial, no credit card.

Create an account

30-day free trial, no credit card required.