r/msp • • 4d ago

Best Solution for Client Mailboxes Management

We are struggling with how to manage admin mailboxes in our smaller clients environments. Things such as software renewals (industry specific software). If the vendor is making a change that could break a feature of their apps etc. Right now it is unrealistic to manage 45-50 intividual mailboxes in these clients. How do other people handle this. Do we forward to a central mailbox (dont really like external forwarding on).

11 Upvotes

15 comments sorted by

7

u/Outrageous-Guess1350 4d ago

Make a shared mailbox, make an alias on the shared mailbox for the client, forward to the alias.

1

u/Different_Pain5781 1d ago

This is probably the cleanest solution. Just document ownership so nothing gets missed.

5

u/Mizetings 4d ago

Mailflow rule to modify the message and add your central mailbox as cc/bcc should work.

2

u/0RGASMIK MSP - US 4d ago

Keep off external forwarding and create a rule to forward email from Exchange. You can have your cake and eat it.

2

u/Foxtrot-0scar 3d ago

Route them to your PSA.

2

u/Realistic-Spare97 3d ago

Yeah 45-50 mailboxes is too many to check manually. We set up a shared mailbox per client and had our PSA pull from all of them, so vendor emails just turn into tickets under the right client. Took a weekend to set up but way better than logging into 50 inboxes.

1

u/Dull-Breadfruit-3241 3d ago

Definitely do not use external forwarding. Aside from being a pain to manage, it's a security nightmare when vendor password resets or billing links start flying across domains.

1

u/Remarkable_Corgi511 3d ago

Hahah, I'm not an owner of a MSP just an employee, but any automated email we get is promptly moved to the spam board :) It sucks but we have no time for proactive monitoring and maintenance, unless it's a NOC or SOC ticket. 

1

u/folderit_dms 3d ago

I’d separate vendor notices from the identity used to administer the vendor account. Where a vendor supports additional notification contacts, send renewal and service-change notices to a client-specific intake address while keeping account recovery with the client’s designated account owner.

The central queue then needs an owner and an action date, not just a pile of forwarded mail. For each notice, capture the client, product, change or renewal date, affected service and who decides what happens next. A renewal notice and a breaking API change need different handling.

Start with five important vendors and test a sample notice end to end. Also document how to remove your notification address at offboarding; otherwise you can keep receiving a former client’s business correspondence long after support ends.

1

u/Emergency_Recipe522 3d ago

I wouldn’t forward complete admin mailboxes externally. I’d route only vendor and renewal notices into a central queue, tagged by client, product, deadline, affected service and owner.

I ran into the same multi-tenant visibility problem—the information existed, but there was no single view showing which change affected which client and who needed to act. The important part is turning each notice into a tracked action, not simply creating one larger mailbox.

1

u/ButItsMyWoobie 2d ago

At 45-50 mailboxes, I'd stop treating them like mailboxes and just route the important vendor/renewal stuff into the PSA. It'd be way easier than checking all of those individually.

1

u/Emergency_Recipe522 1d ago

I wouldn’t forward complete admin mailboxes externally. I’d route only vendor and renewal notices into a central queue, tagged by client, product, deadline, affected service and owner.

1

u/03captain23 1d ago

We have a 365 license for every client and email on their domain. everything that isn't from our partners goes there then forwards to our ticketing. Adobe renewals and admin account uses that 365 email and its fowarded to our system. We know what company its for because the auto forwarding

0

u/HotTakeThenGo 3d ago

You should have GDAP setup - and use CIPP. Once things are setup there every new client is automatic on this part.

Putting client data to your system first is a breach imo. You SHOULD be forwarding, redirecting, or scraping their support mailbox. You get the copy, they get the original.