Webmail has two halves. cPanel creates and manages the mailboxes; IMAP and SMTP read and send the mail. You configure both on Settings → Webmail, and there is a test button for each.
This connects to your own hosting account’s cPanel, using an API token you create there. It is not a service WBAMS provides.
Create the cPanel API token
- Sign in to cPanel on the account that hosts the mail domain.
- Open Security → Manage API Tokens.
- Create a token, name it something you will recognize later such as
wbams-webmail, and set no expiry unless you have a process for rotating it. - Copy the token immediately. cPanel shows it once and will not show it again.
It can act on the account. Store it only in WBAMS, never in a ticket, a chat message or a screenshot, and revoke it in cPanel the moment it is no longer needed.
Connect cPanel
- Open Settings → Webmail in WBAMS.
- Hostname — the cPanel server hostname, for example
server.example.com. Not the website domain, unless they are the same machine. - Port — the cPanel API port. The default is correct for most hosts; change it only if your host says otherwise.
- cPanel username — the account username, not an email address.
- API token — paste the token you just created.
- Leave Verify the server certificate on. Turn it off only for a staging server with a self-signed certificate, and never in production.
- Press Test cPanel connection. Fix any failure before going further — nothing downstream works until this passes.
IMAP and SMTP
These are the servers the webmail app itself talks to when a customer reads or sends mail.
- IMAP host and IMAP port — usually the same server, port 993 with SSL/TLS.
- IMAP security — SSL/TLS for 993, STARTTLS for 143. Do not run either without encryption; mail passwords cross this connection.
- SMTP host, SMTP port and SMTP security — usually 465 with SSL/TLS, or 587 with STARTTLS.
- Press Test IMAP. A failure here with a passing cPanel test is almost always a firewall or a port, not a credential.
Offer it to customers
- Turn on Offer webmail.
- Mail domain — the domain addresses are created under, for example
example.com. - Webmail address — the URL the webmail app is served from. Point a subdomain such as
email.example.comat the installation’swebmaildirectory and enter it here. - Who can use it — decide whether every customer sees it or only those whose products include mailboxes.
- Administrator roles — which of your own roles may administer mailboxes.
- Set Name, Accent color and Logo so the webmail app looks like yours rather than generic.
Mailbox allowances
How many mailboxes a customer may create comes from their product. Set the allowance on the product rather than per customer, so it follows upgrades and downgrades automatically.
Verify end to end
- As an administrator, create a mailbox from Webmail → Mailboxes.
- Sign in to the webmail address with that mailbox and confirm the folder list loads.
- Send a message to an outside address and confirm it arrives.
- Reply from outside and confirm it appears in the mailbox.
- Finally, sign in to the client area as a test customer and confirm the mailbox manager appears for them.
When it does not work
webmail directory.