Installed on your own cPanel server

Create a client mailbox in seconds — not in cPanel.

FlashMail Express turns the daily job of provisioning mailboxes — for OTPs, activation links and client onboarding — into a single screen. Type a name, or paste the address the applicant already sent you, and it does the rest — one mailbox at a time, or a whole list in one run. We install it on your server and configure it around your domains, your quotas and your staff.

Runs on your server Your cPanel tokens never leave it A login per staff member Every action recorded

The whole job, on one screen.

The daily grind

Verifying a client is the easy part. Getting their mailbox shouldn't be work.

Every activation email and every OTP needs somewhere to land. Done by hand, that means a trip through cPanel for each one — and then a second sign-in before you can even read the code you were waiting for.

By hand, in cPanel

  1. Sign in to cPanel and find Email Accounts
  2. Invent a name that isn't already taken
  3. Choose a domain from a dropdown
  4. Set a storage quota
  5. Invent a password and write it down
  6. Open webmail separately and sign in again
  7. Find the OTP, then go back for the next client

With FlashMail Express

  1. Paste the client's address — the name is cleaned for you
  2. Pick the domain, space and password policy
  3. Copy the credentials, or open the inbox already signed in

No second login. No note-taking. The next client is one paste away.

How it works

Five steps your team will learn in a morning.

Nothing to memorise, nothing to configure on the fly. The controls you change often are on the first screen; the rest is set once by us during installation.

Paste the client's address

Staff usually already have the client's email open in another tab. Paste it and the local part is taken, cleaned and lowercased — [email protected] becomes rajesh.kumar. Anything illegal for a mailbox name is dropped, so a paste can never fail validation.

It tells you if that mailbox already exists

Before you create a duplicate, the form checks what is already on the server and says so — red for an exact match, amber for a name one character away. Your team stops making twin mailboxes that nobody can tell apart six months later.

Pick the domain, space and password

If your cPanel account serves several domains or subdomains, they appear in a dropdown with the everyday one already selected. Set the storage, and choose whether this mailbox gets your team's standard password, a fresh random one, or one you type yourself.

Copy it, or walk straight into the inbox

The address and password are shown once, each with its own copy button. The webmail button signs the mailbox in and lands on the inbox itself — no chooser page, no "Open" button, no retyping a password.

  • Shown once, after the mailbox actually exists
  • Each credential has its own copy button
  • The webmail link signs in as that mailbox

Find it again later

Search by name across the mailboxes you have already made, or across the live server — so when a client comes back in three months asking for their code again, the address is two seconds away instead of an archaeology project in cPanel.

The box at the top

Or just type it.

The form is still there, but most days you can skip it. Type a name, or paste an address the applicant already sent you, and the box offers what you probably wanted — with the answer already on screen.

Paste an address, get an offer

Pasting a client's address is ambiguous — it means "make one of these" about as often as it means "open the one we already made". So the box asks instead of guessing, and it only ever offers actions that can actually succeed.

  • Not there yet? It says the name is free, and offers to create it.
  • Already exists? It offers to open it instead — never a create that would fail.
  • Close names exist? It names them, so you spot the near-duplicate before two clients share an OTP.
  • Enter runs the first option, so "type a name, hit Enter" still works.

A few commands, if you prefer them

A name or a pasted address is offered as options. A command states what you want, so it runs straight away. The slash is optional, and /help lists the lot.

  • /new — create the mailbox, then open its inbox
  • /open — open a mailbox, no second sign-in
  • /find — search every mailbox on the account
  • /pass — set the standard password and open
  • /del — delete one, after confirming
  • /help — the list, in the conversation

It keeps working when other things don't

  • Handled in the browser. The commands need no API key, make no network call and cost nothing — so they keep working even if you never enable anything else.
  • A typo is answered, not guessed. /nwe comes back with "Did you mean /new?" instead of quietly doing something else.
  • Nothing destructive is ever inferred. Deletion happens when a person asks for it and confirms it, never because a sentence sounded like it.

There is also an optional AI mode that understands a full sentence. It is off by default, it needs your own provider key, and it sends the text you type to that provider — a deliberate choice rather than something that happens quietly. The commands above never leave your browser.

Features

The four things your team does all day.

Create

New client, new mailbox — under a couple of seconds, with nothing to look up.

  • A whole list at once. Paste names, or bring a CSV, and it reads the batch first — what will be created, what already exists, what needs fixing — before a single mailbox is made.
  • Paste and go. A client's address becomes a clean mailbox name.
  • Any of your domains. Subdomains included, your everyday one pre-selected.
  • Space on your terms. The default, a preset, or an exact figure up to your cap.
  • Your password policy. One standard password, a fresh random one, or your own.

Open

Get into the inbox without a second sign-in — which is where the time actually goes.

  • Straight to the inbox. Not the webmail chooser, not a login form.
  • Copy buttons everywhere. The address and the password, each in one click.
  • A fresh password on demand. Reset a mailbox you cannot get into.

Find

Yesterday's mailbox, or the one from eleven months ago, without leaving the page.

  • Two scopes. What you created in this browser, or everything on the server.
  • Duplicate warning. Told before you create a twin, not after.
  • Near-miss warnings. A name one character off an existing one is flagged.
  • What's new since you last looked. Mailboxes this console had not seen before are marked, so arrivals stand out from the ones you have always had.
  • Export and backup. Your browser list as CSV, restorable on another machine.

Maintain

The two things you eventually need on a mailbox you already made.

  • Set a new password. For a client who has come back, or a mailbox nobody can open.
  • Delete a finished mailbox. When the job is closed and the inbox is done.
  • Off unless you turn them on. Both are opt-in, and both are one at a time.

Also in the box

  • Nothing to install. It runs in the browser your staff already use — desktop, tablet or phone. No app, no extension, no per-seat licence.
  • Light and dark. Follows the operating system by default, or each person can pin the one they prefer.
  • A help page inside the tool. Searchable, written for the people doing the work rather than for administrators, and one click from the header — so “how do I…?” is answered in the console instead of by interrupting you.
  • Several cPanel accounts. One profile each, with its own token — and each staff member sees only the accounts you grant them.
  • More than one domain. Every domain and subdomain on the account, with your everyday one pre-selected.

…and the smaller things

  • Quota presets, per account. Your everyday sizes as one-click chips, set during installation.
  • A CSV log of everything created. Plus a JSON backup you can restore on another machine.
  • Fill level on every row. Space used, in colour, so a mailbox about to fill up is visible before it starts rejecting mail.
  • Copy buttons where they matter. The address and the password, each one click from the list.
Workflows

Four things your team will actually do.

The tool is deliberately small. These are the journeys it exists to shorten, from the first paste to the mailbox nobody could get into.

New applicant

From application form to verified

  1. Their email is already in front of you — on the form, or in your inbox.
  2. Paste it. The name is cleaned, and checked against every mailbox that already exists.
  3. Create it. The address and the password appear once, each with a copy button.
  4. Open the inbox. It signs in as that mailbox and lands on the mail itself.
  5. Read the code, paste it into their application, finish the job.

The point: the portal is still waiting when the code arrives, because nothing sat in between.

A client returns

Months later, when they need the code again

  1. Type part of their name. The list filters as you type — no round trip, no waiting.
  2. If you still hold the password, open the inbox directly.
  3. If you do not — an older mailbox, or a different machine — one click sets it to your standard password and opens it.
  4. Retrieve the code. The mailbox stays where it is, ready for next year.

The point: a mailbox from eleven months ago is two seconds away, not lost somewhere in cPanel.

A busy day

Working through a stack of applications

  1. Work down your list. Each mailbox is a paste and a click.
  2. Or hand the whole list over at once: paste the names, or drop in a CSV. It reads the batch first and shows you the plan — what will be created, what already exists on the server, and anything duplicated inside your own list.
  3. A batch longer than your hourly allowance is flagged before it starts, not discovered halfway through.
  4. The credentials collect in your own list as you go, searchable at any point.
  5. Search the whole account in memory when a name is only half-remembered.
  6. Close finished jobs with a delete — one at a time, confirmed, never on a timer.

The point: volume changes nothing about the process, which is why it is still accurate on the twentieth mailbox of the day. Creating in bulk is still not reading in bulk — the codes stay one inbox at a time.

A new colleague

Adding someone to the team

  1. We create them their own login during setup, or later when you ask.
  2. You decide which cPanel accounts they can reach — one, some, or all.
  3. They sign in with their own password. Nothing gets passed around.
  4. A searchable help page sits one click from the header: the everyday tasks, the shortcuts, and what to do when something looks wrong.
  5. Everything they create or delete is recorded against their name.

The point: when someone leaves, you disable one login and it takes effect on their next click.

Control and security

Built for a team that handles other people's business.

You are storing credentials for client mailboxes. That deserves more care than a shared login and a spreadsheet.

One login per staff member

No shared team password. Each session is individually signed and expires after a set number of hours, and removing someone from the staff file cuts them off on their very next click — not whenever a token happens to lapse.

Your cPanel token stays on your server

The browser never receives it. Staff sign in, and the server is the only thing that ever talks to cPanel — so an API key can never be lifted from a staff laptop.

An audit trail that never records passwords

Who created or deleted what, when, and from which address. Passwords are deliberately absent from that log — a record of what happened shouldn't become a second place to leak from.

Nothing destructive happens on its own

There is no expiry timer and no automatic cleanup. Mailboxes are deleted only when a person clicks delete, after confirming — because a timed delete of an inbox someone was still using is unrecoverable.

Limits so a mistake stays small

Creation is rate-limited per person — your hourly allowance is yours, not a pool shared with the rest of the office, so a colleague working through a stack never spends it. A rejected attempt is not charged against the limit either, so a typo or a duplicate name costs you nothing. And a stuck button or a runaway script still cannot turn into a thousand mailboxes.

Switches you control

Password resets and deletions ship switched off. Turn them on when your team is ready for them, and you decide which staff member can see which cPanel account.

Who it's for

Anyone who creates mailboxes for other people.

If your work involves waiting on an activation link or an OTP that has to land somewhere you control, this removes the slowest part of that loop.

DSC partners and CSCs

Applicant verifications in volume, each with its own address to receive the OTP and the acknowledgement.

Verification and KYC teams

Document checks, employer confirmations and one-time codes that need a mailbox per case.

Hosting resellers

Provision a working inbox the moment a client signs up, without opening cPanel for each one.

Agencies and onboarding teams

Give every new client a mailbox on day one, on the domain you already manage for them.

Straight answers

What it does not do.

A tool that only lists its strengths is a tool you cannot plan around. These are the boundaries, and each one is a deliberate choice rather than an oversight.

A mailbox is not unlimited

The everyday quota is small by design, because most of these mailboxes are throwaway. But a small mailbox fills with spam over a year — and a full mailbox silently rejects new mail, including the OTP you were waiting for. For long-lived mailboxes, set a bigger quota at creation.

No bulk password reset, on purpose

Creating a batch is fine; resetting one is different. A reset signs out whoever was using the old password, so doing that across hundreds of mailboxes at once is a support incident and a pattern that gets servers blocked. It is one mailbox at a time — deliberately.

Older mailboxes need one reset

cPanel never discloses a mailbox password through any API. A mailbox created before this tool existed therefore has to be reset once before you can open it. The tool does that in a single click, and leaves mailboxes it does not need to touch alone.

Passwords stay in the browser that made them

Saved credentials live in the staff member's own browser, not in a server-side vault — so they are not shared between machines, and clearing browser data clears them. If you would rather have a shared, encrypted vault, that is a change we can build into your deployment.

cPanel hosting only — it is not a generic mail tool

It talks to cPanel's own API, so it needs cPanel or WHM hosting with PHP 8 or newer. It does not work with Plesk, DirectAdmin, Microsoft 365 or Google Workspace, and there is nothing to buy from us to make it work elsewhere.

It creates mailboxes; it does not send mail

There is no newsletter, no bulk sending and no campaign tool here, and it will never send anything on your behalf. It provisions inboxes and opens them — that is the whole job.

Custom setup

We install it, configure it and hand it over working.

This is not a download-and-figure-it-out product. Every deployment is configured against your cPanel account and your way of working, then handed to your team.

What a deployment covers

Priced per deployment, depending on how many cPanel accounts and staff logins you need.

  • Installed on your own server Runs on your existing cPanel hosting with PHP 8 or newer. No extra services to buy, no third-party cloud in the middle of your client data.
  • Connected to your cPanel account We set up a scoped API token, connect the account, and confirm a test mailbox is created and deleted cleanly before we hand over.
  • Your domains, quotas and password policy Every domain and subdomain you want to create on, your default storage, your ceiling, and whether staff may type their own passwords.
  • A login for each staff member Individual accounts, with access limited to the cPanel accounts each person actually needs. Add or remove people later without touching the code.
  • Training and documentation A walkthrough for your team, plus the built-in help page that ships inside the console — searchable, written for staff, and one click from the header. Alongside clear documentation of how your deployment is configured, so you are never dependent on us to explain your own tool.
  • Nothing for your staff to install They open a URL and sign in with their own account — from the office, from home, or from a phone. No software, no browser extension, no desktop client to keep updated.
  • Yours to keep It runs on your hosting under your control. No subscription is required for it to keep working, and your client data never passes through us.
Questions

The things buyers ask before saying yes.

Including the ones where the honest answer is no.

Deployment and hosting

Can we host it on our own web server?

Yes — that is how it is meant to run. It is a PHP application, so it goes on the cPanel hosting you already have: upload two folders, point a domain at them, and it is live. Nothing gets installed into cPanel itself.

We use it on a laptop during development, which is convenient for testing but not the real thing — your staff need it somewhere they can reach.

Our staff work from different locations. Does that work?

Yes. Everyone signs in with their own account over HTTPS, from any network — different offices, home, a phone on mobile data. There is no office-IP restriction to maintain and no VPN involved. This mattered enough that it is the reason we replaced the original single shared key with per-person logins.

What does the server need?

Ordinary cPanel hosting with PHP 8.0 or newer — set per domain in cPanel's MultiPHP Manager — and HTTPS, because the console sends a session token and shows mailbox passwords. No database, no Node, no build step, no cron job.

Do we need a dedicated server, or a fixed IP address?

No. It runs comfortably on shared hosting, and neither your staff nor the server needs a static address.

Does anything need installing on the cPanel account it manages?

No. It talks to cPanel's API from the outside — it is a client of cPanel, not a plugin inside it. Your mail server, DNS, and every existing setting are left exactly as they are.

Where should we host it — on the same account it manages?

It works on the same account, and for a single account that is the simplest option.

If you manage several cPanel accounts from one console, hosting the console somewhere separate keeps its fate separate from theirs. We will recommend based on your setup.

What if our server cannot reach the cPanel API?

Rare, but it happens: some hosts block outbound connections to the cPanel ports, or a server calling its own public hostname.

The usual fix is to point the configuration at the server's hostname rather than the domain. If the host blocks it outright, the console can be deployed on a different server — it only needs to reach the API over HTTPS.

Day to day, and the honest noes

Do we have to hand over our cPanel password?

No. It uses a scoped API token that you create in cPanel and can revoke whenever you like. The token stays on your server and is never sent to a browser.

Can staff just type something instead of filling in the form?

Yes, and most people end up doing that. There is a box at the top of the screen that takes a name, a pasted address, or a short command — /new, /open, /find, /pass, /del. Typing /help lists them, and the slash is optional.

Those commands are handled inside the browser: no API key, no network call and no cost. There is also an optional AI mode for full sentences, which is off by default — it needs your own provider key and it sends the text you type to that provider, so it is a deliberate choice rather than something that happens quietly.

Can we create a batch of mailboxes at once?

Yes. Paste a list of names, or bring a CSV, JSON or plain text file, and it works out the whole batch before it starts: what will be created, what already exists on the server, what is duplicated inside your own list, and what needs fixing first. A list longer than your hourly allowance is flagged before it runs rather than stopping halfway through.

One honest limit: creation is bulk, reading is not. The codes still have to be read one inbox at a time.

Does it read our clients' email?

No. It opens the mailbox in webmail, already signed in and pointed at the inbox. Reading the activation mail or the OTP is done there, by a person, exactly as it is today.

Can it copy the OTP automatically?

No — and we would not claim otherwise. It removes every step before and after the code. Reading the code is the part that stays human.

Do our existing mailboxes have to change?

No. They keep their passwords, their mail and their settings. This creates ordinary cPanel mailboxes, and it can open or reset the ones you already have.

What if the mailbox already exists?

The form tells you while you are still typing, and cPanel refuses a genuine duplicate outright — so you cannot end up with two mailboxes that nobody can tell apart six months later.

One standard password for everything — is that safe?

It is a policy you choose, per account: a standard password for throwaway mailboxes, a fresh random one each time, or one you type yourself. Many teams use the standard password for temporary inboxes and random ones for anything long-lived.

Worth knowing: cPanel never reveals a mailbox's password through any API, so a random password has to be copied at the moment the mailbox is created.

Where are the passwords kept?

In the browser that created the mailbox, not in a server-side vault. That is a deliberate trade: there is no central store of client credentials to steal, but a password does not follow a staff member to another machine.

A shared, encrypted vault is something we can build into your deployment if you need one.

Who can see which mailboxes?

Each staff member has their own login, and you decide which cPanel accounts each one can reach. Removing someone's access takes effect on their next click, not at the next restart.

Is there an audit trail?

Yes: who created or deleted what, when, and from which address. Passwords are deliberately left out of it — a record of what happened should not become a second place to leak from.

What happens when a mailbox fills up?

It starts rejecting mail silently, and that includes the OTP you were waiting for. The list shows how full each mailbox is and warns as it approaches the limit, so set a larger quota for the mailboxes you plan to keep.

Do mailboxes get deleted automatically?

Never. Deleting is manual, one mailbox at a time, behind a confirmation. A timer that deletes an inbox somebody was still using cannot be undone.

Can we use more than one cPanel account or server?

Yes. Each cPanel account is configured separately with its own token, and a staff member can be given access to one, some or all of them. One account having a problem does not affect the others.

Can staff use it from home, or a different office?

Yes. Everyone signs in with their own account, so there is no office-IP restriction to maintain — which is one of the reasons we moved away from a single shared key.

What do you need from us to set it up?

cPanel hosting on PHP 8 or newer; a scoped API token from your cPanel account; the domains or subdomains you want to create mailboxes on; and how many staff need logins.

Will our staff need training to use it?

Very little — and we would rather under-promise here. The tool is deliberately small: one box to type in, one list, and a handful of buttons. There is a searchable help page built into the console, one click from the header, covering the everyday tasks, the shortcuts, and what to do when something looks wrong.

We walk your team through it at handover, and the help page is the part that stays with them afterwards. It is a page, not a support desk — anything structural is a call to us.

How is it priced?

Per deployment — tell us how many cPanel accounts and staff logins you need, and we will quote. The contact buttons below reach us directly, and WhatsApp is usually the fastest.

Next step

Tell us about your setup and we'll come back with a plan and a price.

Send us your domain and roughly how many mailboxes you create in a month. If you already know how many staff need logins, and whether you want resets and deletions enabled, that is everything we need to quote.

Cloud84

Phone and WhatsApp
+91 83510 91922 · Message on WhatsApp
Address
Galua Road, Una, Himachal Pradesh 174303, India
Website
cloud84.in