Service Access

Choose which IP addresses may connect to Webmail, email applications and FTP.

Where to find it: Account > Security Settings > Service Access.

Available to: The account user for their own account, root, and the owning reseller, subject to the assigned feature profile and installed services.

What this page does

Each service has its own IP access rules. The account policy provides defaults; individual mailboxes and FTP users can inherit them or use an allowed override.

Before you start

Identify the client’s actual public IP, including any VPN or NAT address. Keep a working management session while testing a restrictive policy. A service IP policy does not replace a password, app password, firewall rule, or account ownership check.

Services and policy modes

ControlMeaning
Webmail directSource policy for direct Webmail sign-in.
Mail protocolsSource policy for IMAP, POP3, and authenticated SMTP clients.
FTPDefault IP access rules for FTP connections.
OffNo additional restriction from this service policy; normal authentication and other protections still apply.
AccountUse the account IP Access Control list.
CustomUse the IP/CIDR list entered for this service. IPv4, IPv6, and network prefixes are supported; comments help identify each entry.

Mailbox and FTP overrides

Check the affected mailbox or FTP-user settings as well as the account defaults. An inherited policy and a custom policy can intentionally differ. Direct Webmail access is separate from an SHM sign-in handoff; the retired webmail_sso policy cannot be used to enable SSO.

How to use it

  1. Choose the service and Off, Account, or Custom mode.
  2. For Custom, enter the intended allowed IPs/CIDRs and labels.
  3. Save Service Access and reopen the affected mailbox or FTP user if it has an override.
  4. Test from an allowed source and a separate disallowed source while preserving your recovery session.

Result and next check

The intended clients can authenticate and the excluded sources are rejected for that service. If access fails unexpectedly, compare the settings currently in use and the observed client IP before changing passwords.

Theme color