Security & Abuse

Break-glass access to stored email: what good controls look like

Write who, when, and how. Curiosity is not a control.

MailerZ editorial · Secuno LLC16 min read

Email break glass access is a rare, logged look at stored hops or held messages when the usual destination owner is unavailable. Good controls: named people, a ticket, a time box, and the store window. MailerZ is not an archive and not HIPAA. Free keeps fourteen days. Paid ninety. Do not dump bodies into Slack. Do not invent SOC 2. Exclusive MX so the store you look at is complete.

email break glass access: the decision
Rare, named, time-boxed, inside the store window.

Quick answer for email break glass access

Break-glass is for missing owners and expired time, not curiosity.

The store is short. Fourteen or ninety days. Plan around that.

RFC 5321 hops are evidence. Bodies are still someone else’s mail.

Remap to a live human when you can. That is cleaner than reading.

Security page states controls. This article will not add badges.

Start free and write the policy before the first emergency.

Authoritative mail transport is defined in IETF RFC 5321 — Simple Mail Transfer Protocol. Product path: security, features, and aliases and catch-all.

User problem and decision criteria

Decision criteria: is the owner unreachable, is the window open, is remap enough.

Founders who read everyone’s held mail as sport fail the control.

Agencies need a named client approver.

Legal hold fantasies need an archive product.

Shared staff logins destroy accountability.

No inboxing angle.

HOLD reduces how often you need glass.

Secrets in tickets are a second incident.

Technical mail flow

email break glass access flow
Exclusive MX. SRS envelope. Header From intact.

Incident → approval → open store in product → act (remap/recover/reply) → close and log.

If expired, ask a resend. Do not invent a copy.

MX exclusive so you are not looking at a partial world.

Step-by-step setup / decision path

email break glass access steps
Map, exclusive MX, third-mailbox probe.
  1. Write the policy: who, when, how logged.
  2. Prefer remap.
  3. If open, time-box and ticket.
  4. Act inside the product.
  5. Do not export to Slack.
  6. Close the access.
  7. Review quarterly who still has seats.
  8. Keep store clocks in the policy.

Classify the next failure before a second DNS edit.

HOLD unknown unless you wrote a FORWARD reason.

Quote live pricing before promising alias counts.

Failure modes and proof

Curiosity browsing.

Slack dumps.

Shared login.

Expired store promises.

Catch-all instead of policy.

SOC 2 invented.

HIPAA invented.

No ticket.

MX flap as access.

Header rewrite.

Forever admin seats.

No clock in the policy.

MailerZ workflow and product boundary

MailerZ is custom-domain aliasing and forwarding with optional paid send-as. Secuno LLC operates mailerz.net. The app is mail.mailerz.net. Not Workspace, not IMAP, not an open relay, not a campaign ESP.

Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME stay intact. Exclusive MX. Hold unknown on Free. Copy SMTP host, port, and TLS or STARTTLS from the dashboard when you send.

Free: one domain, three aliases, one seat, fourteen-day store, fifty outgoing a month, no send-as. Solo forty dollars a year, fifteen aliases, ninety-day store, one hundred outgoing, five send-as per hour. Starter eight or eighty. Business nineteen or one hundred ninety. Agency thirty-nine or three hundred ninety. Quote pricing. No SOC 2, ISO, HIPAA, SLA, or inboxing percentage.

Cost, alternatives, and trade-offs

Unbounded reading is trust cost.

A short policy is cheap.

Ninety-day paid store is the honest longer window.

Slack archives are legal and leak cost.

Shared logins are audit fog.

Agencies: bill policy writing once.

No fake certification.

Remap is cheaper than reading.

Operational depth

Put break-glass in the security conversation honestly: short store, named seats, no badges.

Offboard seats when people leave. That is the same control family as SMTP rotate.

Agencies: client written approval for reading their held mail.

Prefer teaching HOLD and named aliases so glass is rare.

If you recover a message to a destination, that is an action, not a souvenir.

Do not build a shadow archive from screenshots. That is a worse store with no clock.

Exclusive MX so leftovers are not “missing” during glass.

Quote paid ninety days if the business needs a longer window. Do not invent longer.

No legal advice here. Talk to counsel for real holds.

Probe after remap.

Log UTC.

Review the policy when plans change.

What break-glass is allowed to see

Break-glass on MailerZ is a look at hop history and, inside the store window, a held or failed message the product still has. It is not IMAP search across years. Free keeps fourteen days. Paid keeps ninety. After that window the destination inbox is the archive. If the destination owner is gone and the window closed, you do not recover MIME from MailerZ. You recover process: remap the alias, probe from another mailbox, and accept that old bodies live only where Gmail or Outlook still has them.

Write the allowed objects on one page: hop rows, SMTP lines, held unknowns on Free, failed destination copies still inside retention. Write the forbidden objects: Slack dumps of full bodies, shared screenshots in a company-wide channel, “export everything just in case,” and any claim that this is e-discovery or HIPAA. Secuno LLC does not sell those products. The Security and Trust Center lists controls. It does not list an inbox SLA or a certification we do not have.

Name two people who may break glass and one person who reviews the log. A “leadership” group is how curiosity becomes a habit. Time-box the access. A ticket number goes in the note. UTC timestamps. When the box ends, the extra viewer is removed. Remapping a destination to a living inbox is usually better than opening bodies. The customer still writes hello@. You change who reads it.

Exclusive MX is a control. If leftover Google MX still wins for some senders, the store you open is incomplete. You will swear a message never arrived because it landed in a Workspace seat nobody monitors. Two public resolvers before any break-glass session. If they disagree on leftovers, stop. Fix the zone. Then look.

Self-send is invalid evidence in a break-glass ticket. Gmail can deliver to itself without asking the hop. The missing owner’s “I sent a test” does not prove the customer path. Use another mailbox and a unique subject. Match history to the destination copy.

HOLD on Free is often the reason someone wants break-glass. An unknown local-part sat in the hold. Creating the named alias is the fix. Opening every held item because you never listed printed names is not a control. It is a missing map. Catch-all FORWARD is paid and optional. Turning it on so you “never miss break-glass” hides the next missing name and dumps noise into the store you just unlocked.

Send-as is a different object. If the missing owner also held SMTP, revoke it. Unauthorized From is 550 / 550 5.7.1. Break-glass does not authorize a From. Free cannot send. Paid caps are 50/100/200/400/800 outgoing and 5/10/15/25 per hour. Those numbers are not a reason to leave a departed human’s identity live.

Agencies must not blend clients. One domain, one ticket, one pair of named viewers. Agency limits are 100 domains, 500 aliases, 50 seats, 800 outgoing, 25 per hour. That is not a reason to share one break-glass login across a portfolio.

Legal hold on a Gmail mailbox is a store problem. Remap the hop so new mail is not trapped in a departed user’s hold. Do not leave leftover MX pointed at that seat “so legal can see inbound.” That is leftover MX. Export what legal needs from the store. Point the public name at a living destination.

Quarterly: confirm the two names still work here, the log still exists, retention still matches the plan (14 versus 90), and leftover MX is still gone. If the plan changed from Free to paid, say so in the policy. People will look for ninety days of hops on a Free domain and call it a product bug.

If a stakeholder asks for SOC 2, ISO 27001, or an uptime clause as the break-glass control, decline the invented claim. Point at published caps and /security. If they need a hosted archive, they need a different product class. MailerZ will not grow Vault.

Probe after every remap that came from a break-glass ticket. Unique subject. Other mailbox. History plus new destination. If the probe is empty, you looked at the wrong hop because leftovers returned. The control failed before anyone opened a body.

Passwords for SMTP do not belong in the break-glass ticket. Hostnames and identity names do. The destination inbox password is the store owner’s problem. Do not collect it “to be helpful.”

Start free if you still need to prove the hop exists. Break-glass on a domain that never accepted mail is theater. Exclusive MX, three named aliases, one external probe. Then write the policy. Not the other way around.

Worked incidents and who owns each object

Incident A: founder on leave, invoices arriving, Free HOLD on billing@ because nobody created it. Break-glass viewers open holds, see the local-part, create billing@, remap to finance Gmail, probe from Proton. They do not dump MIME into Slack. They do not restore aspmx. The control is a created alias, not a body archive.

Incident B: paid 90-day store, destination 550 after 250. Viewers copy the SMTP line, stop the MX debate, and work Gmail. Opening the stored failure is allowed inside the window. Republishing TXT is not. The object is destination refuse.

Incident C: leftover Microsoft MX. History looks empty. Viewers who skip the two-resolver check will swear MailerZ lost mail. The control failed at DNS. Fix leftovers, then look again.

Incident D: departed human still has send-as. Break-glass inbound remap without SMTP revoke leaves the phone sending as hello@. 550 after revoke is success. Document both objects on the ticket: destination and identity.

Ownership: DNS human, alias human, destination human, break-glass pair, review human. If two of those are the same person on a three-person company, write it. Do not pretend you have a SOC function you do not have.

Tabletop once a quarter: pick a fake missing owner, run the resolver check, open a hold or a hop row, remap, probe, close the ticket in UTC. If the tabletop requires leftover MX to “make it interesting,” your production zone is already wrong.

Vendors who ask to “just log in and pull the email” should get a remapped destination or a hop screenshot, not a shared password. MailerZ is not IMAP. There is no shared mailbox password to give them.

If legal wants every body for a year, buy an archive or use the destination export. Do not write MailerZ 90 days into a one-year clause. That clause will fail and you will invent a feature under pressure.

Night CTA stays honest: start free to prove the hop. Break-glass policy on a domain that never accepted a stranger’s message is paper. Exclusive MX first.

Envelope SRS and intact Header From still apply when you view a stored item. If Header From was rewritten, you are looking at another hop’s copy. Stop. Change the hop, not the policy.

Seats: one dashboard seat is not a destination. Removing a seat does not have to delete aliases. Removing a destination without a replacement is an outage you will break-glass next week.

Catch-all FORWARD as a standing break-glass substitute trains the team never to list printed names. Turn it off until the map is real. Then decide FORWARD as a product choice.

Write the store window in the policy header: 14 or 90. When someone upgrades, update the header the same day. Stale policy is how people demand ninety days on Free and file a false outage.

No review counts. No inbox SLA. No HIPAA. If those words appear in a break-glass RFP, strike them before you sign.

Aftercare is leftover MX Monday. Someone will restore Google “so we have a copy.” That copy is split mail. Delete it. The hop you just used for break-glass must stay exclusive or the next incident is folklore.

Worked scenarios for email break glass access

A founder is on a flight. Billing@ is HOLD because a vendor used an old typo. Finance needs the invoice tonight. Break-glass here is not a Slack screenshot of the body. It is a ticket, a named deputy, a remap of billing@ to the deputy for twelve hours, and a probe. If the copy is still in the store, recover it in the product. If the store clock already expired, ask the vendor to resend. Do not invent a PDF from memory and call it the invoice.

An agency client fires their bookkeeper on a Friday. The destination mailbox is locked. The client asks you to 'just open everything in HOLD for the last month.' That is not break-glass. That is an archive request you cannot fulfill honestly. MailerZ Free keeps fourteen days. Paid keeps ninety. Write the window. Offer remap to a new destination the client still controls. Refuse a zip of other people's mail.

A hospital-adjacent startup asks for HIPAA-grade break-glass. Stop. MailerZ is not HIPAA. Do not write a control that pretends otherwise. Point them at /security for the real control set. If they need a covered entity archive, they need a different product class. Email break glass access on a forwarding hop is a short store plus named seats, not a clinical record system.

A shared 'ops' login has been reading held mail for sport. The control failed before the incident. Offboard that seat. Rotate SMTP if that identity could send. Write the policy so the next person cannot browse. Curiosity is the most common abuse of stored hops, and it never looks like an incident until counsel asks who opened what.

A destination Gmail is full. Messages accepted at MailerZ then fail onward. The operator opens the store, recovers one message, and pastes it into Slack. That paste is now a second store with no clock and a wider audience. Recover to the new destination or teach the owner to free quota. Do not build a souvenir archive.

Legal asks whether you can place a hold on all mail for a domain. You cannot invent legal hold in a fourteen- or ninety-day hop store. Say so. Counsel buys an archive. You keep exclusive MX so future mail is not split while they argue about the past.

Practice and anti-patterns for stored-mail access

Practice: name two people who may open the store, and one who may approve. Anti-pattern: 'anyone with the workspace password.' Shared passwords destroy the log even if the product is honest.

Practice: prefer remapping a destination over reading a body. Anti-pattern: opening every held item because it feels faster. Faster for whom? The original recipient still owns that mail.

Practice: act inside the product and close the ticket with UTC. Anti-pattern: phone screenshots in a group chat titled urgent. Those images outlive the store window and travel to the wrong laptop.

Practice: write the store clock into the policy—fourteen days on Free, ninety on paid. Anti-pattern: promising 'we can always pull it' after a quarter. That promise is a second incident when it fails.

Practice: HOLD unknown so glass is rare. Anti-pattern: catch-all FORWARD into a shared folder so nobody needs policy. You traded a rare control for a permanent confidentiality leak.

Practice: quote /security and refuse invented SOC 2 or HIPAA badges. Anti-pattern: a vendor questionnaire that copies a suite vendor's appendix. Buyers notice. So does the next auditor.

Practice: offboard seats when people leave, same day as SMTP rotate if they could send. Anti-pattern: leftover admin because 'we might need them for the next fire.' That leftover is the fire.

Operator closeout after a glass event

Closeout is a dated packet: who approved, who opened, which message IDs, what action (remap, recover, refuse), and when access ended. If you cannot write that packet, you did not have a control. You had a peek.

If you remapped, probe from a third mailbox to the public alias. Self-send still lies. Confirm Header From is intact and the new destination received the unique subject. Then write the revert time if the remap was temporary.

If the store had expired, the packet says expired and names the resend request. Do not pad the packet with a reconstructed body. Reconstruction is fiction. Fiction in an incident file is worse than an empty store.

If SMTP could have been used by the missing owner, decide whether to rotate. Break-glass on inbound is not automatically an outbound revoke. Write the decision. Caps and plan names belong on /pricing, not in folklore.

Agencies attach the client's written approval. Your retainer does not silently authorize reading their vendors' invoices. If they will not sign, you remap or you wait. You do not freelance as their archive.

Schedule the policy review. Plans change. Seat lists rot. A closeout without a next date is how last quarter's deputy still has the keys.

Edge cases that break naive break-glass stories

Two deputies approve each other with no third person. That is not a control. It is a club. Need a founder or a client approver who does not hold the same seat.

The only copy is in a destination that the missing person still owns, and MailerZ already forwarded. You cannot unsend from Gmail. Break-glass on the hop store will not retrieve what already left. Ask the destination owner, or wait.

The incident is leftover MX. Some senders never reached MailerZ. Opening HOLD will not invent those messages. Fix exclusive MX first. Glass after you have one inbound owner, or you will keep looking in the wrong building.

A catch-all FORWARD filled the store with guessed names. You now have a haystack. That is why HOLD is the default on Free. Do not enable FORWARD as a substitute for a named alias map, then complain that glass is slow.

An employee used personal Gmail as the destination and then left. Remap the alias. Do not ask MailerZ to open that personal account. The product is not their IMAP. The map is yours to change.

Someone wants to export the entire store 'for backup.' That is an archive product. MailerZ is a hop with a clock. Say no, point at the window, and keep exclusive MX so the next week is complete.

Field notes from real tickets

The tickets that go well have a unique subject from a third mailbox already on file from launch day. You compare that hop shape to the incident hop. The tickets that go badly start with 'just look around until you see it.'

Founders confuse delivery history with a filing cabinet. History is hops and codes. It is not a folder they can browse like Outlook. Teach the difference before the first emergency, not during it.

Agencies that bill a one-time policy workshop have fewer Friday-night glass requests. Agencies that skip the workshop get the 11 p.m. call and then a scope argument. Write the workshop into the retainer.

UTC in the ticket beats 'this afternoon.' Destination providers and MailerZ clocks will not argue if you picked one timezone at the start. Local time plus 'I think' is how you search the wrong day.

If you recover a message, treat it as an action that fulfilled a business need, not as a trophy. Delete local copies you should not have made. The store clock is a feature. Your laptop is not a longer store.

Read RFC 5321 when someone claims a hop 'must exist' without a transcript. Transport is not telepathy. No code, no proof. See also /troubleshooting when leftover MX is the actual class.

Handoff memo for the next on-call

Here is the map: named aliases, destinations, HOLD vs FORWARD, store window for this plan, and who may open the store. If that memo is missing, write it before you go on holiday. Glass without a map is rummaging.

Name the registrar and DNS panel owners. Exclusive MX still matters during glass. If a website builder republishes Google MX while you are reading HOLD, you are debugging two incidents. Morning re-query is still the rule.

Name the cancel owner for old mailbox seats. Break-glass does not replace a leftover Google hop. If the old host still answers, some customers never reach the store you are opening.

Link /aliases-catch-all and /security in the memo. Juniors will try to invent a catch-all FORWARD 'so we can always find it.' That sentence is how you lose the control you just wrote.

If send-as is in use, the memo says copy dashboard SMTP, never invent a port. Free has no send-as. A 550 during an emergency is not a reason to dual-publish MX.

Acceptance criteria for the control

You can name the approver and the opener without looking at Slack. A stranger can read the policy and know they are not allowed to browse. That is the first gate.

A remap drill completed this quarter: change a lab alias destination, probe from a third mailbox, revert. If you have never remapped, you will not do it cleanly at midnight.

Store clocks in the policy match /pricing for the plan you actually bought. Fourteen versus ninety is written. Nobody promises forever.

No Slack dumps in the last review period. If you find one, treat it as a leak and delete it. Then fix the habit, not only the file.

Seats match living people. Offboarded contractors are gone. SMTP rotated if they could send. Exclusive MX still exclusive on two public resolvers.

No SOC 2, ISO, or HIPAA claims in the customer-facing appendix. /security is the page you hand them. This article will not add badges.

Operations review of email break glass access

Review who still has workspace seats the same week you review SMTP users. They are the same trust class. A leftover seat is leftover authority over other people's mail.

Review whether HOLD is still the unknown policy. If someone enabled FORWARD to 'be helpful,' glass became a haystack and a leak. Revert unless there is a written reason per zone.

Review the last three glass tickets. If two of them were curiosity, the policy is theater. If two of them were remaps that worked, the control is doing its job.

Review leftover MX. Partial inbound makes the store look empty and tempts people to open more things. Exclusive MX is a privacy control as much as a delivery control.

Confirm live pricing before you tell a client they have ninety days. Free does not. Quote the card. Do not recite last year's blog comment.

If the business now needs a real archive, buy one. Do not stretch MailerZ into that job. Fit the hop. Leave the filing cabinet to a filing cabinet.

Quarterly review questions

Who left, and did their seat die the same day? Who joined, and did they get a deputy role they should not have? Those two questions catch most rot.

Did any website save republish MX? Re-query two resolvers. Dual MX is not a glass problem until it silently is.

Did we invent a badge in a sales deck? Delete it. MailerZ is not SOC 2. Honesty is cheaper than a clawback.

Did we dump a body into chat? Find it. Delete it. Write the reminder in the runbook, not only in a scolding email.

Does the policy still match the plan's store window? Upgrades and downgrades change the clock. The policy must change with it.

Start free on a lab if the junior has never remapped. The first glass event should not be a hospital invoice. Product path: /features, /email-forwarding, /security.

Closing notes on stored-mail discipline

Email break glass access is a rare, logged look at a short store. It is not a culture of reading other people's mail. Write who, when, and how. Prefer remap. Stay inside the window. Keep exclusive MX so the store is the whole inbound world, not a coin flip.

MailerZ will not become an archive because a ticket was loud. Fourteen or ninety days is the honest clock. Slack is not a longer clock. Screenshots are not a control. Named seats are.

If you need anonymity, a mask, a suite, or a campaign ESP, buy those. If you need the hop plus a boring policy, start free on one domain, write the two sentences, and keep curiosity out of HOLD.

Author: MailerZ editorial, Secuno LLC. Review this policy when seats, pricing, or scope change. Do not invent SLAs or inboxing percentages while you are writing about trust.

Policy text you can adopt without inventing certifications

Purpose: recover a living destination or read hop evidence when the usual owner cannot. Not curiosity. Not HR browsing. Not a substitute for Gmail export.

Window: fourteen days on Free, ninety on paid. After that, destination only. We will not write a longer number into a contract.

Viewers: two named people. Reviewer: one named person. Log: ticket id, UTC start, UTC end, objects opened (hop / hold / failed dest), remap yes/no, probe subject.

Forbidden: Slack bodies, shared mailbox passwords, leftover MX “so we have a copy,” catch-all FORWARD as standing access, SMTP secrets in the ticket, SOC 2 or HIPAA language.

Required before open: two public MX answers showing exclusive MailerZ. If leftovers exist, fix DNS first. Incomplete store is not a store.

Preferred action: remap the public alias to a living inbox, then probe from another mailbox. Opening MIME is last.

Send-as: revoke departed identities. Free cannot send. 550 after revoke is success. Caps 50/100/200/400/800 and 5/10/15/25 do not justify leaving a phone AUTH-ing.

Agencies: one client per ticket. Agency 100/500/50 is not a shared break-glass user.

Tabletop: quarterly. Fake missing owner. Resolver check. Remap. Probe. Close UTC.

Upgrade: when the window is the problem, pay for ninety days. When the map is the problem, create aliases. When Calendar is the problem, buy a suite. Do not mix those sentences.

Operator: Secuno LLC. App mail.mailerz.net. Site mailerz.net. Envelope SRS. Header From intact. Not IMAP. Not an open relay.

CTA: start free to prove exclusive MX and one probe. Write this policy the same week. An emergency on an unproven hop is not break-glass. It is archaeology.

If legal wants seven years, buy an archive. If sales wants an inbox SLA, decline. If marketing wants a quote, do not invent one.

After every real incident: leftover MX Monday, policy date stamp, seat list still accurate, destination still living.

Header From on a stored item must still be the original sender. A rewrite means you opened the wrong hop’s copy. Stop the session.

Null MX plus a real MX means some senders never arrive. Break-glass will not find them. Remove the refuse if you intend to receive.

Self-send during tabletop is a failed tabletop. Use another mailbox. Unique subject. Match history to destination.

This policy is shorter than a suite DLP manual on purpose. A hop is a hop. Keep it operable by a small team.

FAQ

What is the safest way to handle email break glass access?
Write who may open stored mail, for what incidents, and how you record it. Prefer remapping a destination over reading bodies. If you must open a held item, do it in the product, not a screenshot pile. No catch-all FORWARD as a substitute for process.
Does this require a new mailbox?
No. MailerZ is not IMAP. Keep Gmail or Outlook unless you need a suite for other reasons.
Will it work with Gmail or Outlook?
Yes as destinations. Self-send is not proof. Use a third mailbox and open original.
What DNS records are involved?
Exclusive MX, verification TXT, one SPF if you send-as. Leftover MX is a hard stop. Dashboard values only for sending.
What should I test before production?
A uniquely titled probe from an unrelated provider to each public alias. Confirm Header From and hop history.

Key takeaways

  • Named, rare, logged.
  • Prefer remap.
  • Store clocks are real.
  • No Slack dumps.
  • No invented badges.
  • Exclusive MX.
  • Offboard seats.
  • HOLD reduces need.

Conclusion

Break-glass should be boring and rare. Write who, when, and how. Stay inside the store window.

Start free, write the two-sentence policy, and keep curiosity out of other people’s mail.

Start free on MailerZ