Getting Started with CodaMail
A step-by-step walkthrough for new accounts: how your addresses work, how to set up your mail, and how to put the privacy features to work for you.
Welcome to CodaMail
CodaMail is a privacy-focused email service built over 25+ years of operation. There is no tracking, no analytics, no telemetry, and no advertising. Every resource (fonts, icons, scripts) is hosted locally on our servers. Nothing phones home.
CodaMail works differently from other email providers, and that difference is what makes it powerful. This guide walks you through your account step by step, starting with the one concept that changes everything: you already have unlimited email addresses, and you never have to create them.
You don’t need to set everything up at once. Work through the steps in order, and skip anything you don’t need yet. Each section links to a detailed guide if you want to go deeper.
Before anything else: Set up password recovery now in Settings → Password Recovery. We keep no personal information about you, so without this, we cannot recover your account if you forget your password.
Step 1: Understand Your Addresses (The Big Idea)
At most email providers, if you want a second address you have to go somewhere in settings and create it. CodaMail does not work that way, and this is the single most misunderstood part of the service:
Every address at your account’s subdomains already works. There is nothing to create, register, or turn on. Make up a new address in your head while standing at a store counter, give it out, and mail sent to it will arrive in your inbox. This is called catch-all addressing, and it is automatic on every account.
Here’s how it works. Say your username is jsmith. From the moment your account exists, mail to anything@jsmith.codamail.com is delivered to you:
- newsletter@jsmith.codamail.com (works right now, no setup)
- amazon@jsmith.codamail.com (works right now, no setup)
- gym@jsmith.codamail.com (works right now, no setup)
You will not find a page anywhere in Settings to “add” these addresses, because no such page is needed. Any word you put in front of one of your catch-all subdomains is already a working address. There is no list to maintain and no quota to worry about. They are truly unlimited.
There are only two situations where you actually create something:
- Creating a new category (masked alias). A one-time step that gives you a whole new catch-all subdomain with no connection to your username. Covered in Step 2.
- Sending from an address. Receiving needs no setup, but to send from one of your addresses you add an identity for it. Covered in Step 3.
Why hand out a different address to every company? Because if one leaks or starts getting spam, you know exactly who sold you out, and you can shut off that one address without affecting anything else. That is the heart of the CodaMail approach to email privacy.
Step 2: The Four Kinds of Addresses
All of your addresses deliver to the same inbox. They differ in what they look like and how much they reveal about you.
1. Your main address and account aliases
Your main address is username@codamail.com. Account aliases are that same username at any of our 30+ other domains. Turn domains on or off with checkboxes in Settings → Account Aliases. Every enabled domain automatically includes its own catch-all subdomain (anything@username.thatdomain.com), so each one multiplies your unlimited address space. Account aliases are unlimited and don’t count against any quota.
Since these contain your username, they are best for everyday, non-sensitive use where being recognizable is fine.
2. Masked aliases (your category system)
Masked aliases are addresses with a name you choose and no visible connection to your username. Create one in Settings → Masked Aliases: pick a name, pick a domain, click Add. That single step gives you two things:
- The address itself (e.g., shopping@example.com)
- An entire catch-all subdomain: anything@shopping.example.com
The recommended way to use masked aliases is as categories. Create a handful of them, one per area of your life (shopping, social, finance, medical, or less descriptive names if you prefer). You are not creating them to hand out the root address. You are creating them to claim the catch-all subdomain. From then on, you invent specific addresses within each category on the fly, with no further setup:
- amazon@shopping.example.com → give to Amazon
- ebay@shopping.example.com → give to eBay
- reddit@social.example.com → give to Reddit
- mybank@finance.example.com → give to your bank
None of those addresses were ever “set up.” They work because they end in a catch-all subdomain you own. Each service gets its own unique address, none of them can be traced to your account name, and any one of them can be shut off individually if it’s ever abused.
Masked aliases are limited in number by plan (they are the only limited alias type), but since each one is a whole category holding unlimited addresses, a handful is all most people ever need.
3. Random aliases (throwaways)
Random aliases are machine-generated addresses like k9d8h1-x4z7@example.com for one-off signups, downloads, and trials. Nothing in the address means anything, and you can attach a private note so you remember what each one was for. Create them in Settings → Random Aliases. When you delete one it is retired forever. Use these when even a category address would reveal more than you want.
4. Auto-expiring addresses
Any catch-all address where the name is a date in YYYYMMDD format (e.g., 20260901@shopping.example.com) is automatically rejected after that date. Perfect for signups you know you’ll only need briefly. Again, nothing to set up: just use a date as the address.
Learn more: Account vs. Masked vs. Random Aliases · How to Categorize Mail with Unique Addresses
Step 3: Sending From Your Addresses (Identities)
Receiving mail at any of your addresses requires no setup. Sending from an address requires one small step: creating an identity for it. An identity tells the composer “this is one of my addresses, let me write mail as it.”
- Go to Settings → Identities.
- Click Add, and enter the address (any of your addresses works, including made-up catch-all addresses like amazon@shopping.example.com).
- Optionally set a display name and signature for that identity.
- Save. That address now appears in the From dropdown when composing.
When you reply to a message, CodaMail automatically selects the identity matching the address the message was sent to, so replies come from the right address without you thinking about it. If no identity matches, the reply uses your default identity instead. So it’s worth creating identities for the handful of addresses you actually correspond from.
Identities can also have their own custom SMTP server if you need to send through another provider for a particular address.
Learn more: What Are Identities and How to Use Them
Step 4: Organize Your Mail
With a category address system in place, organization becomes nearly automatic:
- Folders. Create a folder per category (Shopping, Social, Finance…) in Settings → Folders.
- Filters. Settings → Mail Delivery Filters creates server-side Sieve rules that run even when you’re not logged in. One filter per category (“To contains @shopping.example.com → move to Shopping”) and every address you ever invent in that category files itself automatically. Filters can also copy, redirect, flag, or PGP-encrypt mail.
- Labels. Create colored labels and apply them to messages in any folder. Labels sync to Thunderbird as native tags, and you can label mail automatically from filters. See Message Labels.
- Snooze. Temporarily clear a message out of your inbox and have it return at a time you choose.
- Threading. Group conversations together: click the options icon at the top of the message list and switch the mode from List to Threads.
- Archive. One-click archiving moves read mail out of the inbox into a dated archive structure.
Learn more: Understanding Sieve Filters · Message Labels & Thunderbird Tags
Step 5: Control Who Can Reach You
CodaMail rejects unwanted mail at the SMTP level, during the connection itself, with a “User Unknown” error. The mail never enters our system, and to the sender your address appears not to exist. There are two directions of control:
- Block List: control which senders can reach you. Block individual addresses, entire domains, or whole top-level domains (like .xyz), with wildcard support. Quick access from the block icon while reading a message, or in Settings → Block List.
- Manage Catch-alls: control which of your addresses accept mail. When an address you handed out starts drawing spam, add it here and all future mail to it is rejected. This is how you “delete” a catch-all address that was never created in the first place. Use the Kill Alias toolbar icon while reading a message for one-click access, or go to Settings → Manage Catch-alls. It can also run as a whitelist: only addresses you list accept mail, everything else is rejected.
Because every service got its own address, blocking one leaked address never disrupts anything else. Deleting an entire masked alias likewise shuts down its whole category at the server level.
SpamAssassin content filtering runs automatically on all mail that passes these checks. Nothing to configure, though you can tune it to your needs in Settings → Antispam Tools.
Learn more: Understanding Mail Blocking Options · Overview of Anti-Spam Solutions
Step 6: Security & Encryption
Several protections are active on every account by default, with no setup required:
- At-rest encryption. Every email is individually encrypted with AES-256-GCM on our servers.
- Header stripping. 35+ tracking and identifying headers are removed from outgoing mail.
- Tracking pixel blocking. Remote images are blocked by default to prevent read tracking.
- Read receipt blocking. Read receipt and delivery notification headers are automatically removed.
- Encrypted connections only. All connections use TLS with Perfect Forward Secrecy.
Protections you can add:
- Two-Factor Authentication. Add TOTP-based 2FA in Settings → 2-Factor Authentication. Recommended for everyone.
- PGP Auto-Encryption. Automatically PGP-encrypt incoming mail as it arrives so only you can read it, for all mail or per-address. Combined with categories, you can encrypt just your sensitive categories (e.g., everything to @medical.example.com).
- Secure Link. Password-encrypt attachments client-side with AES-256-GCM before sending. The password is never stored on our servers.
Learn more: Set Up Two-Factor Authentication · Automatic PGP Encryption Setup · How to Use CodaMail Most Securely
Using Your Own Domain
If you own a registered domain, you can host it on CodaMail at no extra charge (how many domains you can host depends on your plan; most plans allow unlimited). Add and verify it in Settings → Private Domains (a DNS verification record plus MX records; the custom domains guide walks through it).
Once verified, your domain works exactly like your other catch-all subdomains, only better: every address at the domain is yours automatically. Mail to anything@yourdomain.com arrives in your inbox. Just like the rest of the service, you do not create aliases for yourself anywhere. Invent addresses on the fly, block the ones that go bad in Manage Catch-alls, and create identities for the ones you send from. Filters, blocking, and auto-encryption all work across your domain.
A common point of confusion: the “assign” (delegation) options on the Private Domains page are not where you set up your own addresses. Your own addresses need no setup. Delegation is for routing parts of your domain to other CodaMail accounts: give bob@yourdomain.com to Bob’s account, give all of @support.yourdomain.com to a separate support account, and so on. It’s how a family or group shares one domain across separate accounts while you keep ownership and control. If you’re the only user of your domain, you can ignore delegation entirely.
Learn more: Setting Up Custom Domains
Calendar, Tasks, Contacts & Notes
Your account includes a full set of personal information tools, all accessible from the webmail interface:
- Calendar. Multiple calendars with events, invitations, reminders, and iCalendar import/export. Optionally show your due-dated tasks directly on the calendar.
- Tasks. Task lists with due dates, priorities, and iCalendar support.
- Contacts. Address book with vCard and CSV import/export.
- Notes. Notes in plain text, HTML, or Markdown, organized in nested folders, with image and PDF storage.
You can also convert any email directly into a calendar event or task.
All of it syncs privately to your phone, tablet, and desktop apps through our own CalDAV/CardDAV server, which uses a unique dual-random authentication system that reveals nothing about your account. Notes sync over WebDAV to apps like Obsidian, 1Writer, and QOwnNotes.
Learn more: Syncing Calendars, Tasks & Contacts · Syncing Notes (Obsidian & More)
Make It Yours
Customize the look and feel of your webmail:
- Layout. Choose between widescreen (three-column), desktop (two-pane), or list (minimalist) layouts to match how you prefer to read mail.
- Color themes. Pick from 40+ professionally designed color schemes.
- Density. Adjust list spacing and icon sizing for a compact or relaxed interface.
- Language. The interface is available in 80+ languages.
Learn more: Changing Desktop Layout · Changing Your Color Scheme · Interface Density & Icon Sizing · Changing Languages
Using CodaMail on Your Devices
The CodaMail webmail interface is fully responsive and works on any screen size. Visit https://codamail.com/mail/ in any browser and create a home screen shortcut for app-like access.
You can also use external email clients (Thunderbird, Outlook, Apple Mail, K-9 Mail, etc.) via IMAP or POP. For security, external client access requires an app password: create one in Settings → App Passwords and use it in place of your account password in the client. App passwords can be restricted per-service and per-network, and revoked individually without changing your real password.
Server Settings
- IMAP: mail.pnsh.com, ports 143 and 993
- POP3: mail.pnsh.com, ports 110 and 995
- SMTP: smtp.pnsh.com, ports 25, 465, 587, or 2525
- Login: Use only your username (not your email address), with your app password
- Security: TLS/SSL required, plaintext connections denied
Platform Setup Guides
More Powerful Features
Beyond the essentials above, your account includes:
- Delayed Send. A configurable 5-30 second window after hitting Send, giving you a chance to undo mistakes.
- Scheduled Send. Compose a message now and schedule it to send at a future date and time.
- Deadman Switch. Set messages to be sent automatically if you haven’t logged in for a specified number of days.
- Fetch Mail. Automatically pull mail from your other email accounts via POP or IMAP, so everything lands in one inbox.
- Built-in PDF Viewer. View PDF attachments directly in the browser with annotation tools.
- Full Data Portability. Import and export mail (eml, mbox, maildir), contacts (vCard, CSV), and calendars/tasks (iCalendar) in standard formats. Your data is yours.
Learn more: Complete Features List · Importing & Exporting Your Mail · Hidden Features and Easter Eggs
Getting Help
If you have questions or need assistance:
- Frequently Asked Questions: Answers to the most common questions.
- Support Documentation: Complete documentation for all features.
- helpdesk@codamail.com: Reach our team directly. You’ll get a response from an actual member of our core team, not a bot.
