Email Alias vs Mailbox vs Shared Address
Mailboxes, aliases and shared addresses can all appear on the left side of an email address, yet they solve different administrative problems. A clean domain setup uses each type deliberately: mailboxes belong to people, aliases label purposes, and shared addresses serve responsibilities handled by a group.
The distinction affects access, storage, recovery, privacy and plan capacity. It also determines how easily an administrator can reassign an address when a household member or teammate changes roles.
Thelemail supports separate mailboxes, group routing and unlimited email aliases on @thelemail.com and connected domains. Custom domains are the primary structure for households and founder-run teams because the administrator controls the identity and can move it later.
The short definition of each address type
| Type | Main purpose | Sign-in | Where incoming mail goes |
|---|---|---|---|
| Mailbox | A private account for one person | Its own credentials | Its own inbox and storage |
| Alias | Another address for one destination | Uses the destination account | One existing mailbox |
| Shared address | A durable role handled by several people | Members keep individual credentials | A copy reaches each selected member |
These definitions describe the routing model. Sending permissions can vary by provider, so an administrator should verify who can send from an alias or shared address and how that identity appears to recipients.
A mailbox belongs to a person
A mailbox is the right choice when someone needs a private inbox, an independent sign-in and their own account recovery. Each family member, founder or teammate should normally have a mailbox.
Separate credentials reduce the need for shared passwords. They also make device management and offboarding clearer. When a teammate leaves, an administrator can remove that member and reassign company role addresses while other accounts stay unchanged. In a household, each person can use multifactor authentication and recovery settings suited to them.
Mailbox capacity is a plan resource because every mailbox has storage, account state and security material. The pricing page lists current mailbox, storage and custom-domain capacities for Personal, Family and Business plans.
With Thelemail, OPAQUE unlocks wrapped account keys on the user’s device, and stored mailbox content remains ciphertext to the service. Each member has their own encryption key. Messages between Thelemail accounts are end-to-end encrypted. For outside mail, WKD/OpenPGP protects message content when a compatible key is available; standard SMTP with TLS where supported handles the other cases. External subject headers and envelope metadata remain visible for routing. The security page documents each boundary.
An alias gives one mailbox another address
An alias is an additional address that routes to an existing mailbox. It has no independent inbox or sign-in. Mail delivered to the alias uses the destination mailbox’s storage and access controls.
Aliases work well for purpose-specific identities:
[email protected]can route to the household member who manages online orders.[email protected]can collect booking confirmations in one person’s mailbox.[email protected]can reach the founder responsible for media requests.- A unique address for each online service can make its source clear if the address receives unexpected mail.
Paid Thelemail plans have unlimited aliases. A workspace anti-abuse guardrail may restrict excessive, automated or abusive alias creation. The personal Free plan has no aliases. Free Family includes one shared @thelemail.com alias. Mailbox, storage and connected-domain capacity still follow the paid plan. This model lets the address structure grow without creating a separate account for every service or public label.
An administrator can keep an alias stable while changing its destination. If responsibility for press@ moves from one founder to another, the public address can continue receiving mail throughout the reassignment.
An individual on a paid Personal plan can create aliases on an @thelemail.com account before owning a domain. Aliases on a custom domain carry the identity that the administrator controls and can move between hosts.
A shared address belongs to a responsibility
A shared address serves a role that several people handle. Incoming mail is delivered to selected members, with each person receiving a copy through their own account. Members keep individual credentials and encryption keys.
Useful household examples include bills@, school@ and bookings@. Founder-run teams may use hello@, invoices@ or support@. The address should describe a durable responsibility so it remains useful as membership changes.
Shared routing avoids a single password known by several people. It also lets the administrator see which accounts hold access and update that list when responsibilities change. Establish a reply convention to prevent two members answering the same message independently. For a high-volume support workflow, a dedicated help desk may provide assignment and collision controls beyond ordinary email routing.
The family email guide shows how to combine private member mailboxes with shared household addresses. Small teams can review the commercial founder-run business email model.
Choose by person, purpose or group
Use three questions for every address on the domain.
Does one person need private access?
Create a mailbox. This gives the person their own credentials, inbox, storage, sessions and recovery path. Avoid using a public role name as the person’s only identity because roles often outlast the current owner.
Does one existing mailbox need another label?
Create an alias. The address can identify a service, project, public contact point or temporary responsibility while all mail lands in the chosen mailbox.
Do several people need the same incoming message?
Create a shared address and select the members. Each recipient uses a personal account, and the administrator can update membership without distributing a new shared password.
This model scales from a household to a small company. It also makes migrations safer because every recipient has an explicit type and destination.
Build an address register
A simple address register prevents abandoned routes and unexpected privacy exposure. Record:
- The complete address.
- Its type: mailbox, alias or shared address.
- The owner or selected recipients.
- Whether members may send from it.
- Its business or household purpose.
- Important external accounts that use it for recovery.
- The date of the last review.
Review the register during onboarding, offboarding and provider migration. A domain can accumulate addresses that receive only annual renewals or rare recovery messages, so recent inbox activity alone gives an incomplete inventory.
When moving hosts, recreate every active mailbox, alias and shared address before changing MX. The staged MX cutover guide explains why recipient completeness matters. Thelemail’s domain setup flow keeps current inbound delivery active during preparation.
Consider privacy at the routing layer
Routing decisions determine who receives a message. An alias directed to one mailbox gives that mailbox holder access. A shared address gives each selected member a copy, so its membership should match the real responsibility.
Review shared addresses when a family relationship or team role changes. Remove former recipients promptly and rotate any related account credentials they may know. Give sensitive mail a narrower address and recipient list than a broad household or company route.
The address itself is metadata and remains visible to systems that route mail. Aliases can reduce exposure of a person’s primary address to individual services, while the domain stays visible. Security still depends on account credentials, recovery, device sessions and the protection offered along the message path.
A durable pattern for a custom domain
A practical structure usually looks like this:
- One mailbox for each person.
- Shared addresses for responsibilities handled by several members.
- Aliases for services, projects and public labels routed to one mailbox.
- One administrator who owns DNS and reviews routing.
- A written recipient inventory used before every provider move.
Connect the domain through the custom-domain setup process, then test one recipient of each type from an external provider. Confirm that replies use the intended address and that every selected member receives shared mail. A deliberate routing model keeps addresses stable while people and responsibilities change.