Create a client mailbox in seconds — not in cPanel.
FlashMail Express turns the daily job of provisioning mailboxes — for OTPs, activation links and client onboarding — into a single screen. We install it on your server and configure it around your domains, your quotas and your staff.
The whole job, on one screen.
Verifying a client is the easy part. Getting their mailbox shouldn't be work.
Every activation email and every OTP needs somewhere to land. Done by hand, that means a trip through cPanel for each one — and then a second sign-in before you can even read the code you were waiting for.
By hand, in cPanel
- Sign in to cPanel and find Email Accounts
- Invent a name that isn't already taken
- Choose a domain from a dropdown
- Set a storage quota
- Invent a password and write it down
- Open webmail separately and sign in again
- Find the OTP, then go back for the next client
With FlashMail Express
- Paste the client's address — the name is cleaned for you
- Pick the domain, space and password policy
- Copy the credentials, or open the inbox already signed in
No second login. No note-taking. The next client is one paste away.
Five steps your team will learn in a morning.
Nothing to memorise, nothing to configure on the fly. The controls you change often are on the first screen; the rest is set once by us during installation.
Paste the client's address
Staff usually already have the client's email open in another tab. Paste it and
the local part is taken, cleaned and lowercased — rajesh.kumar@gmail.com
becomes rajesh.kumar. Anything illegal for a mailbox name is dropped,
so a paste can never fail validation.
It tells you if that mailbox already exists
Before you create a duplicate, the form checks what is already on the server and says so — red for an exact match, amber for a name one character away. Your team stops making twin mailboxes that nobody can tell apart six months later.
Pick the domain, space and password
If your cPanel account serves several domains or subdomains, they appear in a dropdown with the everyday one already selected. Set the storage, and choose whether this mailbox gets your team's standard password, a fresh random one, or one you type yourself.
Copy it, or walk straight into the inbox
The address and password are shown once, each with its own copy button. The webmail button signs the mailbox in and lands on the inbox itself — no chooser page, no "Open" button, no retyping a password.
- Shown once, after the mailbox actually exists
- Each credential has its own copy button
- The webmail link signs in as that mailbox
Find it again later
Search by name across the mailboxes you have already made, or across the live server — so when a client comes back in three months asking for their code again, the address is two seconds away instead of an archaeology project in cPanel.
The four things your team does all day.
Create
New client, new mailbox — under a couple of seconds, with nothing to look up.
- Paste and go. A client's address becomes a clean mailbox name.
- Any of your domains. Subdomains included, your everyday one pre-selected.
- Space on your terms. The default, a preset, or an exact figure up to your cap.
- Your password policy. One standard password, a fresh random one, or your own.
Open
Get into the inbox without a second sign-in — which is where the time actually goes.
- Straight to the inbox. Not the webmail chooser, not a login form.
- Copy buttons everywhere. The address and the password, each in one click.
- A fresh password on demand. Reset a mailbox you cannot get into.
Find
Yesterday's mailbox, or the one from eleven months ago, without leaving the page.
- Two scopes. What you created in this browser, or everything on the server.
- Duplicate warning. Told before you create a twin, not after.
- Near-miss warnings. A name one character off an existing one is flagged.
- Export and backup. Your browser list as CSV, restorable on another machine.
Maintain
The two things you eventually need on a mailbox you already made.
- Set a new password. For a client who has come back, or a mailbox nobody can open.
- Delete a finished mailbox. When the job is closed and the inbox is done.
- Off unless you turn them on. Both are opt-in, and both are one at a time.
Four things your team will actually do.
The tool is deliberately small. These are the journeys it exists to shorten, from the first paste to the mailbox nobody could get into.
From application form to verified
- Their email is already in front of you — on the form, or in your inbox.
- Paste it. The name is cleaned, and checked against every mailbox that already exists.
- Create it. The address and the password appear once, each with a copy button.
- Open the inbox. It signs in as that mailbox and lands on the mail itself.
- Read the code, paste it into their application, finish the job.
The point: the portal is still waiting when the code arrives, because nothing sat in between.
Months later, when they need the code again
- Type part of their name. The list filters as you type — no round trip, no waiting.
- If you still hold the password, open the inbox directly.
- If you do not — an older mailbox, or a different machine — one click sets it to your standard password and opens it.
- Retrieve the code. The mailbox stays where it is, ready for next year.
The point: a mailbox from eleven months ago is two seconds away, not lost somewhere in cPanel.
Working through a stack of applications
- Work down your list. Each mailbox is a paste and a click.
- The credentials collect in your own list as you go, searchable at any point.
- Search the whole account in memory when a name is only half-remembered.
- Close finished jobs with a delete — one at a time, confirmed, never on a timer.
The point: volume changes nothing about the process, which is why it is still accurate on the twentieth mailbox of the day.
Adding someone to the team
- We create them their own login during setup, or later when you ask.
- You decide which cPanel accounts they can reach — one, some, or all.
- They sign in with their own password. Nothing gets passed around.
- Everything they create or delete is recorded against their name.
The point: when someone leaves, you disable one login and it takes effect on their next click.
Built for a team that handles other people's business.
You are storing credentials for client mailboxes. That deserves more care than a shared login and a spreadsheet.
One login per staff member
No shared team password. Sessions end when the tab closes, and removing someone from the staff file cuts them off immediately — not whenever a token happens to expire.
Your cPanel token stays on your server
The browser never receives it. Staff sign in, and the server is the only thing that ever talks to cPanel — so an API key can never be lifted from a staff laptop.
An audit trail that never records passwords
Who created or deleted what, when, and from which address. Passwords are deliberately absent from that log — a record of what happened shouldn't become a second place to leak from.
Nothing destructive happens on its own
There is no expiry timer and no automatic cleanup. Mailboxes are deleted only when a person clicks delete, after confirming — because a timed delete of an inbox someone was still using is unrecoverable.
Limits so a mistake stays small
Creation is rate-limited per team and per person. A stuck button, a runaway script or an over-enthusiastic afternoon cannot turn into a thousand mailboxes.
Switches you control
Password resets and deletions ship switched off. Turn them on when your team is ready for them, and you decide which staff member can see which cPanel account.
Anyone who creates mailboxes for other people.
If your work involves waiting on an activation link or an OTP that has to land somewhere you control, this removes the slowest part of that loop.
DSC partners and CSCs
Applicant verifications in volume, each with its own address to receive the OTP and the acknowledgement.
Verification and KYC teams
Document checks, employer confirmations and one-time codes that need a mailbox per case.
Hosting resellers
Provision a working inbox the moment a client signs up, without opening cPanel for each one.
Agencies and onboarding teams
Give every new client a mailbox on day one, on the domain you already manage for them.
What it does not do.
A tool that only lists its strengths is a tool you cannot plan around. These are the boundaries, and each one is a deliberate choice rather than an oversight.
A mailbox is not unlimited
The everyday quota is small by design, because most of these mailboxes are throwaway. But a small mailbox fills with spam over a year — and a full mailbox silently rejects new mail, including the OTP you were waiting for. For long-lived mailboxes, set a bigger quota at creation.
No bulk password reset, on purpose
Resetting a mailbox signs out whoever was using it with the old password. Doing that across hundreds of mailboxes at once is a support incident and a pattern that gets servers blocked, so it is one mailbox at a time — deliberately.
Older mailboxes need one reset
cPanel never discloses a mailbox password through any API. A mailbox created before this tool existed therefore has to be reset once before you can open it. The tool does that in a single click, and leaves mailboxes it does not need to touch alone.
Passwords stay in the browser that made them
Saved credentials live in the staff member's own browser, not in a server-side vault — so they are not shared between machines, and clearing browser data clears them. If you would rather have a shared, encrypted vault, that is a change we can build into your deployment.
We install it, configure it and hand it over working.
This is not a download-and-figure-it-out product. Every deployment is configured against your cPanel account and your way of working, then handed to your team.
What a deployment covers
Priced per deployment, depending on how many cPanel accounts and staff logins you need.
-
Installed on your own server Runs on your existing cPanel hosting with PHP 8 or newer. No extra services to buy, no third-party cloud in the middle of your client data.
-
Connected to your cPanel account We set up a scoped API token, connect the account, and confirm a test mailbox is created and deleted cleanly before we hand over.
-
Your domains, quotas and password policy Every domain and subdomain you want to create on, your default storage, your ceiling, and whether staff may type their own passwords.
-
A login for each staff member Individual accounts, with access limited to the cPanel accounts each person actually needs. Add or remove people later without touching the code.
-
Training and documentation A walkthrough for your team, and clear documentation of how your deployment is configured — so you are never dependent on us to explain your own tool.
-
Yours to keep It runs on your hosting under your control. No subscription is required for it to keep working, and your client data never passes through us.
The things buyers ask before saying yes.
Including the ones where the honest answer is no.
Deployment and hosting
Can we host it on our own web server?
Yes — that is how it is meant to run. It is a PHP application, so it goes on the cPanel hosting you already have: upload two folders, point a domain at them, and it is live. Nothing gets installed into cPanel itself.
We use it on a laptop during development, which is convenient for testing but not the real thing — your staff need it somewhere they can reach.
Our staff work from different locations. Does that work?
Yes. Everyone signs in with their own account over HTTPS, from any network — different offices, home, a phone on mobile data. There is no office-IP restriction to maintain and no VPN involved. This mattered enough that it is the reason we replaced the original single shared key with per-person logins.
What does the server need?
Ordinary cPanel hosting with PHP 8.0 or newer — set per domain in cPanel's MultiPHP Manager — and HTTPS, because the console sends a session token and shows mailbox passwords. No database, no Node, no build step, no cron job.
Do we need a dedicated server, or a fixed IP address?
No. It runs comfortably on shared hosting, and neither your staff nor the server needs a static address.
Does anything need installing on the cPanel account it manages?
No. It talks to cPanel's API from the outside — it is a client of cPanel, not a plugin inside it. Your mail server, DNS, and every existing setting are left exactly as they are.
Where should we host it — on the same account it manages?
It works on the same account, and for a single account that is the simplest option.
If you manage several cPanel accounts from one console, hosting the console somewhere separate keeps its fate separate from theirs. We will recommend based on your setup.
What if our server cannot reach the cPanel API?
Rare, but it happens: some hosts block outbound connections to the cPanel ports, or a server calling its own public hostname.
The usual fix is to point the configuration at the server's hostname rather than the domain. If the host blocks it outright, the console can be deployed on a different server — it only needs to reach the API over HTTPS.
Day to day, and the honest noes
Do we have to hand over our cPanel password?
No. It uses a scoped API token that you create in cPanel and can revoke whenever you like. The token stays on your server and is never sent to a browser.
Does it read our clients' email?
No. It opens the mailbox in webmail, already signed in and pointed at the inbox. Reading the activation mail or the OTP is done there, by a person, exactly as it is today.
Can it copy the OTP automatically?
No — and we would not claim otherwise. It removes every step before and after the code. Reading the code is the part that stays human.
Do our existing mailboxes have to change?
No. They keep their passwords, their mail and their settings. This creates ordinary cPanel mailboxes, and it can open or reset the ones you already have.
What if the mailbox already exists?
The form tells you while you are still typing, and cPanel refuses a genuine duplicate outright — so you cannot end up with two mailboxes that nobody can tell apart six months later.
One standard password for everything — is that safe?
It is a policy you choose, per account: a standard password for throwaway mailboxes, a fresh random one each time, or one you type yourself. Many teams use the standard password for temporary inboxes and random ones for anything long-lived.
Worth knowing: cPanel never reveals a mailbox's password through any API, so a random password has to be copied at the moment the mailbox is created.
Where are the passwords kept?
In the browser that created the mailbox, not in a server-side vault. That is a deliberate trade: there is no central store of client credentials to steal, but a password does not follow a staff member to another machine.
A shared, encrypted vault is something we can build into your deployment if you need one.
Who can see which mailboxes?
Each staff member has their own login, and you decide which cPanel accounts each one can reach. Removing someone's access takes effect on their next click, not at the next restart.
Is there an audit trail?
Yes: who created or deleted what, when, and from which address. Passwords are deliberately left out of it — a record of what happened should not become a second place to leak from.
What happens when a mailbox fills up?
It starts rejecting mail silently, and that includes the OTP you were waiting for. The list shows how full each mailbox is and warns as it approaches the limit, so set a larger quota for the mailboxes you plan to keep.
Do mailboxes get deleted automatically?
Never. Deleting is manual, one mailbox at a time, behind a confirmation. A timer that deletes an inbox somebody was still using cannot be undone.
Can we use more than one cPanel account or server?
Yes. Each cPanel account is configured separately with its own token, and a staff member can be given access to one, some or all of them. One account having a problem does not affect the others.
Can staff use it from home, or a different office?
Yes. Everyone signs in with their own account, so there is no office-IP restriction to maintain — which is one of the reasons we moved away from a single shared key.
What do you need from us to set it up?
cPanel hosting on PHP 8 or newer; a scoped API token from your cPanel account; the domains or subdomains you want to create mailboxes on; and how many staff need logins.
How is it priced?
Per deployment — tell us how many cPanel accounts and staff logins you need, and we will quote. The form below reaches us directly.
Tell us about your setup and we'll come back with a plan and a price.
Send us your domain and roughly how many mailboxes you create in a month. If you already know how many staff need logins, and whether you want resets and deletions enabled, that is everything we need to quote.
Cloud84
- Phone and WhatsApp
- +91 83510 91922
- info@cloud84.in
- Address
- Galua Road, Una, Himachal Pradesh 174303, India
- Website
- cloud84.in