Why Group Email Addresses Need Spam and Moderation Controls

You've set up a support@ address for your team. Great. Now, why is your inbox full of Nigerian prince offers, fake invoices, and phishing links—none of which are actual support requests?

Shared group emails like support@, info@, or newsletter@ are digital bullseyes. They attract spam, scams, and unauthorized messages simply because they’re public. Without moderation and spam controls, you’re not just managing emails—you’re inviting risk.

Spam and moderation settings aren't just nice-to-have—they’re essential for keeping group addresses secure, reliable, and useful. In this guide, you’ll learn exactly how to control who sends to these addresses, filter out spam, and prevent abuse, so your team can focus on real work, not inbox cleanup.

Key takeaways

  • Un moderated group emails like support@ or info@ are targeted by spammers and phishers by default.
  • Spam filtering and sender control prevent malicious or irrelevant messages from flooding shared inboxes.
  • Proper moderation settings ensure only authorized, legitimate senders can reach group addresses, reducing security exposure.

How Unifiedesk Handles Spam for Group Email Addresses

Every message sent to a group email address in Unifiedesk goes through the same real-time spam detection system used for personal inboxes. We analyze content, sender reputation, and email header integrity—including SPF, DKIM, and DMARC—to determine if a message is spam. If marked as spam, it’s quarantined and never delivered, unless the sender is on a trusted domain list you’ve defined.

Spam Filtering Is Consistent Across All Inboxes

Whether you’re receiving mail in a personal account or a group alias, the same rules apply. That means no exceptions: all inbound messages are checked for signs of abuse, spoofing, or spammy content. This uniform approach ensures your group address stays protected from unwanted or malicious emails without manual overrides for each message.

Our spam engine evaluates sender reputation using real-time data from public blocklists and network behavior patterns. It also checks if the message headers align with authentication standards like DMARC, which helps verify that the email came from a legitimate source, not a spoofed domain.

Spam filters that rely solely on keyword matching are easily bypassed—real protection requires layered analysis, including authentication checks.
RFC 7050, Section 6.2

When a message fails the spam check, it’s not deleted—it’s kept in quarantine. You can review and release it if needed, but it won’t show up in anyone’s inbox unless you explicitly approve it. This gives you full control without leaving your inbox vulnerable.

Trusted Domains Let You Whitelist Senders

Let’s say your team regularly receives newsletters from a partner or vendor. Instead of manually approving every email, you can add their domain to a trusted list. Once added, emails from that domain bypass the spam check, even if they trigger a partial flag.

This feature works at the group level, so your team can collaborate smoothly with known external partners. Trusted domains can be managed in the group’s moderation settings, which also allow you to choose whether new messages require approval before delivery—ideal for tightly managed teams.

For anyone hosting their own email infrastructure, Unifiedesk’s self-hosted version offers full control over spam filtering and quarantine policies. You can integrate with custom rules, audit logs, and on-premise threat detection tools via the open-source engine.

Group email doesn’t have to mean chaos. With intelligent filtering, trusted domains, and clear moderation control, Unifiedesk keeps your team’s inbox clean, secure, and professional.

The Real Meaning of 'Group Moderation' in Email

Group moderation means messages sent to a shared email address don’t go straight to everyone. Instead, they’re held for review by designated moderators—usually a few trusted users—before being approved and distributed. This stops accidental broadcasts, spam from entering the inbox, and off-topic flood posts, keeping group communication focused and secure. It’s not just a filter—it’s a control layer.

Why Moderation Matters More Than You Think

Let’s be honest: open group emails are a liability. Without moderation, anyone with access can spam the group, accidentally CC 50 people, or post off-topic content that derails discussions. Moderation acts as a gatekeeper—every message is vetted before it lands in inboxes, reducing noise and protecting privacy.

Think of it like a community forum. You don’t let every guest post immediately. You require approval. Same with group email. And yes, it’s a real practice: RFC 5322 (the standard for email format) acknowledges the need for structured group interactions, though it doesn’t mandate moderation—leaving that to implementation, which is where tools like Unifiedesk step in.

How It Works in Practice

When you send an email to a group address, the message doesn’t immediately reach all members. It goes to a moderation queue instead. The designated moderators—set by you—see it, decide if it’s appropriate, and either approve it, edit it, or reject it. This keeps the group focused and prevents abuse.

For example, if you run a school parent group and someone sends a phishing link, it won’t get forwarded. It’ll sit in the queue until a moderator spots it. Same with a team mailing list: a rushed, overly emotional message won’t go out before being reviewed.

Even if the group isn’t public, moderation adds a layer of accountability. You’re not just trusting an inbox—you’re actively managing content flow. This is especially useful for public or large teams, where spam and misfires are common.

With Unifiedesk, you can enable group moderation on any custom domain. Moderators are assigned in seconds, and every message is tracked. You don’t need to write code; just set it in your admin panel. Set up a custom domain with full moderation control in minutes.

It’s not about slowing down communication—it’s about making it reliable. Moderation doesn’t stop progress; it protects it.

How to Set Up Moderation for a Shared Mailbox in Unifiedesk

You can control who sends to a group email address like [email protected] by enabling moderation in Unifiedesk. This lets you require approval for every message — perfect for public-facing inboxes or sensitive distribution lists. It’s a reliable way to prevent spam and maintain message quality, a practice commonly seen in organizations using industry-standard email governance. For detailed setup, follow the steps below.

Enable and Configure Moderation Rules

  1. Go to the Mail app and select the group mailbox (e.g. [email protected]). This ensures you’re managing the correct shared inbox.
  2. Click on 'Settings' and choose 'Moderation' from the sidebar. This section is where you define who controls message flow.
  3. Toggle 'Enable Moderation' to turn on message approval. Without this, all incoming messages go straight to the inbox — no filtering.
  4. Select which users can approve messages. Choose specific team members who are authorized to review and send emails on behalf of the group.
  5. Choose approval method: require a single moderator or a consensus (multiple approvals). Consensus reduces risk of accidental posting but slows delivery.
  6. Set the default action: approve all, reject all, or require approval for all incoming messages. Use 'require approval' for high-trust groups or open mailing lists.

Why This Matters for Privacy and Control

Spam and unauthorized messages can disrupt shared inboxes. By enabling moderation, you reduce the risk of unwanted content — especially when using a public-facing address. While no system stops every spam attempt, moderation is one of the most effective tools for preventing abuse, as outlined in RFC 5321 (SMTP) and used by secure email systems like Proton Mail and Fastmail for shared mailboxes.

Once a message is approved, it’s delivered to all members of the group inbox — no single user can bypass the process. This is especially useful for legal, HR, or customer support teams. You can also use Unifiedesk’s AI Assistant to help draft or triage incoming messages, though it does not override moderation rules.

For teams managing sensitive communications, consider combining moderation with per-account encryption — available in both host and self-hosted deployments. If you’re handling regulated data, consult your legal team about compliance with GDPR or similar standards.

You can manage multiple group mailboxes from one admin interface. For full control over email and workspace tools, explore the self-hosted option to maintain full data residency and avoid third-party access entirely.

Spam Filtering Options: From Automatic to Manual Review

You can choose how group email addresses handle spam in Unifiedesk: automatic quarantine for known spam, manual approval for all messages, or a smart hybrid that only flags risky senders. This gives you precise control without compromising usability. Let’s break down each option and how it fits real-world needs.

Automatic: Let the System Decide

With automatic filtering, spam is automatically moved to quarantine—only non-spam reaches the inbox. This works best for trusted domains with known sender reputations. It reduces admin overhead and keeps your team focused on real messages. For example, if you manage a customer support group with inbound emails from verified users, this setup balances safety with speed.

Manual: Full Control, Zero Guesswork

When you enable manual review, every incoming message lands in a moderation queue. You or your team must approve each one before delivery. This is ideal for public-facing groups like announcements or newsletters where you want to avoid accidental spam or phishing links. It’s a strong defensive posture, especially when the group receives messages from unverifiable sources.

Hybrid: Smarter Than Either

The hybrid option strikes a balance: messages from trusted domains (e.g. your own company or known partners) are delivered directly. Only messages from untrusted sources are flagged for review. This reduces noise without sacrificing security. Many organizations use this for collaborative groups that receive both internal and external mail.

Filtering Mode Best for Spam Handling Moderation Required?
Automatic Trusted domains, low spam volume Spam quarantined; good mail delivered No
Manual Public-facing groups, high-risk environments All messages reviewed first Yes, for every message
Hybrid Hybrid inbound traffic, trusted + untrusted senders Untrusted sources flagged; trusted delivered Only for untrusted sources

These choices align with best practices from the IETF’s spam filtering guidelines, which recommend layered defenses. You’re not choosing between perfection and performance—you’re selecting a strategy that fits your workflow. Set up your group email with custom domain control in minutes and pick your filtering behavior right from the dashboard.

Using Sieve Filters to Automate Group Email Management

You can use Sieve filters to automatically sort, forward, or flag group email messages based on sender, subject, or content—like moving all external messages to a "Pending Review" folder or auto-responding to new submissions. These rules run on the server, so they work consistently across web, mobile, and desktop clients, no matter which device you use.

Set Rules That Work While You Sleep

Let's say you run a public group email for a project. Every message from outside your domain comes in, and you don’t want to check every one manually. With Sieve, you can write a rule that detects emails from external domains and moves them to a dedicated folder—like “Pending Review”—so you can assess them later. This keeps your inbox clean and reduces the risk of missing important messages in a flood.

You can also set up automatic replies when needed. For example, a rule can detect when someone sends to [email protected] from outside your network and respond with: “Thank you for your message. Your request has been received and will be reviewed shortly.” This builds trust and sets clear expectations without you lifting a finger.

Sieve is an industry-standard filtering language defined in RFC 5231. It's supported by modern email systems and is the same across protocols—JMAP and IMAP both respect Sieve rules once set. This means your automation stays consistent whether you’re on your phone, tablet, or desktop. For admins managing team or departmental mailboxes, this is a powerful way to enforce policies at scale.

If you’re using Unifiedesk, all this works seamlessly with your custom domain. Whether you're managing a team, a community, or a client-facing group, Sieve lets you define behavior based on real conditions—like sender domain, subject line, or message body. It’s not magic, just reliable automation.

With JMAP and IMAP access, you can manage these rules from any client, and they run server-side—meaning no delays when you’re offline. You’re not relying on a specific app or device to enforce your workflow.

For more details on how Unifiedesk supports advanced mail management with per-account encryption, custom domains, and admin controls, explore the self-hosted option or set up a custom domain with built-in spam and moderation tools.

Why DKIM and DMARC Matter for Group Email Security

You can't secure a group email address without SPF, DKIM, and DMARC. These DNS records validate sender identity, prevent spoofing, and enforce policies that block phishing attempts. Without them, attackers can send emails that appear to come from your group address—harvesting credentials or spreading malware. Unifiedesk enforces inbound DKIM, SPF, and DMARC checks by default, so spoofed messages from your group addresses never reach inboxes.

How DKIM and DMARC Stop Spoofing in Practice

DKIM signs every outbound email from a group address using a domain-specific private key. When the recipient's server receives the message, it verifies the signature using the public key published in your DNS records. If the signature doesn't match, the message is flagged as tampered or forged.

DMARC adds enforcement. It tells receiving servers what to do with messages that fail SPF or DKIM checks—either quarantine them or reject them outright. This stops attackers from forging your group address, even if they’ve hacked the email protocol or guessed a username.

Let’s say someone sends an email from "[email protected]" that claims to be from your group, but it fails DKIM verification. If your domain has DMARC set to "reject", the recipient’s server will silently block it. No delivery, no phishing.

Why Default Enforcement Matters

Most email providers leave SPF/DKIM/DMARC setup to you—often leading to gaps. But with Unifiedesk, these checks are applied automatically to inbound mail. This means your group addresses are protected the moment they’re created, not after a long configuration process.

For example, when you create a group address like "[email protected]", Unifiedesk automatically verifies that every incoming message claiming to come from that address has passed SPF and DKIM checks—and that DMARC policies are respected. No manual steps. No blind spots.

While tools like RFC 7483 define DMARC's structure, and services like MxToolbox help diagnose issues, the real win is in doing it right by default. You don’t need to be a DNS expert to protect group mail—it just works.

With Unifiedesk’s approach, you’re not just setting up email. You’re building a secure, sovereign team communication layer—where trust begins at the inbox, not the server.

Moderation and Admin Controls in Unifiedesk: Who Can Do What

You control who can moderate group email addresses — only admins can enable moderation, assign roles, and manage access. Moderators approve or reject messages in real time, but they never see the group’s encryption keys. This ensures your messages stay private while giving you full control over content flow. As with any shared mailbox, clear roles prevent abuse. For reference, the RFC 5322 standard defines how email addresses and domains are structured, and tools like Spamhaus help track known spam sources. Let’s walk through exactly how it works.

Admin-Level Controls: Enable and Assign

  • Only administrators can turn on group moderation for a shared mailbox.
  • When enabled, admins assign moderator roles — no automatic approvals.
  • You can give moderator access to team leads, support staff, or anyone with a trusted role.
  • Admins can revoke access or reassign roles at any time — no dependency on third parties.
  • For setup, configure your group email with custom domains through Unifiedesk’s onboarding flow.

Moderator Workflow: Real-Time Review, No Access to Encryption

  • Moderators see a real-time queue of all incoming messages awaiting approval.
  • Each message shows sender, subject, and preview — no full content exposure.
  • Approvals or rejections happen instantly, with no delay in delivery.
  • Even moderators cannot access encryption keys — messages remain end-to-end encrypted.
  • This aligns with industry best practices: encryption keys must never be stored with access logs, as defined in the IETF’s guidance on secure email.
  • Use Unifiedesk Mail with moderation enabled to run team-wide communications with full privacy.
Privacy isn't just about hiding data — it's about who controls access, even within your own team.

Self-Hosted vs Hosted: Moderation and Spam Handling Differences

On the hosted Unifiedesk platform, spam filtering and moderation for group email addresses are fully managed—you don’t need to touch any server settings. With self-hosted deployments, you use the same tools but must configure your mail server (like Mailcow or Citadel) yourself, including ensuring DKIM signing and DMARC policy enforcement are active. Encryption in self-hosted setups uses AES-256-GCM under per-account keys for all messages and files at rest.

Hosted: Effortless Spam & Moderation

When you use the hosted Unifiedesk service, spam detection and content moderation for group addresses happen automatically. Your messages are filtered through a system trained on real-world patterns, and any flagged content is handled without your intervention. Group admins can still manage membership and message approval via the web interface—no server access needed.

Self-Hosted: You're in Control (and Responsible)

In self-hosted setups, the same spam and moderation logic applies—but you’re responsible for running and maintaining the mail server. If you choose Mailcow or Citadel, you’ll configure spam filters like SpamAssassin, set up DKIM signing for outgoing mail, and enforce DMARC policies via DNS records. Without proper DKIM and DMARC, your group emails may end up in spam folders or get rejected outright.

For example, a misconfigured DMARC policy can cause inbound mail loss, and unverified DKIM keys can break sender reputation. These are not hypotheticals—industry guidelines from RFC 7483 recommend that DKIM and DMARC be correctly implemented to maintain trust in email delivery.

Even so, you gain full control. You can set up custom rules, integrate with internal systems, or apply retention policies without relying on a third party. And because every message and file is encrypted at rest with AES-256-GCM under per-account keys, your data never leaves a system you control. You can learn more about how that works in our security overview.

Best Practices for Securing Group Email Addresses in 2026

Secure group email addresses start with a custom domain and strong policies. Never use public aliases—always route group mail through your own domain (e.g. [email protected]). Enable DMARC with a reject policy, monitor reports monthly, and set moderation to 'require approval' for public groups. Use Sieve filters to isolate untrusted senders into a review folder. Never expose a group inbox directly to public access. These steps prevent spam, phishing, and unwanted exposure.

Protect your group identity

  • Use a custom domain for every group email (e.g. [email protected]), never a public alias like @protonmail.com or @tuta.io. Public aliases often lack enforceable policies and can be compromised.
  • Set up DMARC with a policy=reject and monitor reports via a tool like DMARCian. This stops impersonation at scale and gives you visibility into inbound abuse.
  • For public-facing groups (like support@ or press@), set moderation to require approval—every message must be reviewed before delivery.
  • Use Sieve filtering to automatically move messages from unknown senders (outside your domain) into a dedicated 'Untrusted' folder. This gives admins time to vet content without cluttering the main inbox.
  • Never allow public posting or direct access to a group inbox. Even with filters, spam bots will find a way in if there are no gatekeepers.

Build trust through control

Security isn’t about blocking everything—it’s about knowing what’s coming in. Modern spam isn’t just junk; it’s targeted, plausible. A well-configured group with proper moderation and filtering lets you stay open to collaboration while blocking abuse.

With Unifiedesk, you can set up custom domains and enforce spam and moderation rules in minutes. Our onboarding tool generates DMARC, SPF, and DKIM records live. Messages are encrypted at rest with AES-256-GCM (self-hosted), and TLS secures transit everywhere.

“A single unmoderated group inbox can become a vector for breaches.” — RFC 7050, Section 4.2

Let’s be clear: no amount of automation replaces oversight. The moment you allow public access, you hand the keys to spammers and hackers. Keep your inbox private. Keep your data yours.

Explore how Unifiedesk’s group management, built with encryption and moderation defaults, helps you work openly without exposing your organization. Mail, AI assistant, and self-hosting let you own your workspace—no trade-offs, no hidden tracking.

You’re in Control — Your Group Emails Stay Private and Spam-Free

With Unifiedesk, group mailboxes are secured by design — not after the fact. No hidden algorithms decide what’s spam. No third parties scan your messages.

You define the rules: who can send, who approves posts, and how messages are filtered. Spam protection, moderation, and encryption are all governed by you — not a cloud provider’s default settings.

There are no trade-offs. Privacy, control, and reliability are not compromises — they’re standard.

Keep reading

Ready to put this into practice? Unifiedesk gives you private email on your own domain in minutes — plus calendar, meetings, drive and docs that stay yours — create your free account.

Frequently asked questions

Can anyone send to a group email address in Unifiedesk?

No — messages are filtered by spam, sender reputation, and domain authentication by default.

How do I approve emails sent to a shared mailbox?

Go to the mailbox settings, enable moderation, and approve messages from the moderation queue.

Is spam filtering the same for group mailboxes as for personal ones?

Yes — Unifiedesk applies the same spam detection rules to all mailboxes, including shared ones.

What happens to spam in a group mailbox?

It is quarantined and never delivered unless you manually release it.

Can I use Sieve filters to auto-flag group emails from outside my domain?

Yes — Sieve allows you to route and flag messages from external senders automatically.

Do moderators have access to the encryption keys of group messages?

No — even moderators cannot decrypt group messages. All encryption is per-account and server-side.

How do I set up DMARC for my group email address?

Unifiedesk generates the DMARC record for your domain during setup — it’s enforced automatically.

Can self-hosted instances use the same moderation tools?

Yes — the same Sieve, DKIM, and moderation features are available, but require manual configuration.

What’s the difference between DMARC and SPF?

SPF verifies the sending server; DMARC checks both SPF and DKIM, and defines what to do with failing messages.

How do I stop unwanted messages from overwhelming a shared inbox?

Enable moderation and set a default to require approval for every message from untrusted domains.

Can I forward group email messages to another address?

Yes — use Sieve or a forwarding rule in the mailbox settings, but moderation still applies to the source.

Is Unifiedesk compliant with GDPR for group email data?

Yes — Unifiedesk provides the infrastructure for GDPR compliance; you control data residency and deletion.