Sophos Email: manually add, import and manage mailboxes
The My Products > Email Security > Mailboxes page manages protected Sophos Email user mailboxes, distribution lists and public folders. Manual entry suits individual objects; CSV import suits a larger inventory. Before changing anything, establish whether Sophos Fusion (formerly Sophos Central) or a synchronized directory owns the object.
Quick path: check ownership and available licenses, choose the mailbox type, create one mailbox with Add Mailbox or several with Import Mailboxes & Aliases, maintain aliases and any sending privileges, then verify the inventory and test delivery.
Prerequisites and ownership boundary
You need a licensed Sophos Email tenant, administrative access to Sophos Fusion and an authoritative list containing display name, primary email address and mailbox type. Clean up addresses and types before import to avoid duplicates and incorrectly classified rows.
This guide applies to manually created or CSV-imported objects. A sync icon beside a mailbox identifies an object managed by AD Sync or Microsoft Entra ID. Don’t change its attributes, aliases or deletion in Sophos Fusion. Make the change in the source directory or synchronization filter, then wait for the next synchronization.
Mailbox types behave differently:
- User: a personal mailbox whose user details are available from the mailbox name.
- Distribution List: an address for a group. At most one owner can be assigned, who can manage quarantined messages sent to the list.
- Public Folder: an address used, for example, to collect surveys or feedback. It doesn’t create an account under My Environment > Users & Groups > Users, and Sophos applies only the Base Policy to it.
Manually add one mailbox
- In Sophos Fusion, open My Products > Email Security > Mailboxes.
- Select Add, then Add Mailbox.
- Choose User, Distribution List or Public Folder.
- Enter the display name and primary email address.
- Select Save to finish or Save and Add Another to enter the next mailbox immediately.
For a public folder, don’t expect a user account or freely assignable policies. Confirm that these type boundaries match the business requirement before creation.
Import mailboxes from CSV
The import file uses the columns Name, Email Address and Type. Valid Type values are User, DL and PF, for example:
Name,Email Address,Type
Robert Alamar,robert.alamar@example.com,User
Support DL,support@example.com,DL
Vacation Calendar,vacation@example.com,PF
Save the file as UTF-8 CSV and keep it at or below 2 MB. Under My Products > Email Security > Mailboxes, select Add > Import Mailboxes & Aliases, choose the file with Browse, then select Add. Sophos Fusion displays the results when processing finishes.
For large inventories, Sophos recommends batches of 1,000 entries. An upload that exceeds five minutes can leave the interface spinning without a useful completion status. Refresh and retry; if a batch of 1,000 also times out, reduce it to 500. Importing outside peak business hours in the tenant’s region can improve ingestion speed. Preserve the column names, type codes and email addresses in every split file.
Maintain aliases and address validation
An alias delivers mail for an additional address to the primary user mailbox. Sophos Email processes and scans messages for both the primary SMTP address and configured aliases. Aliases don’t add to license usage; only the primary mailbox is included in license calculations.
For a manually created user mailbox, open its name, select Edit under Aliases, enter the address under Add Alias, and select Add. Repeat as needed and select Close when finished. To remove one, return to the same alias table and use the delete icon for that entry.
External and directory-synchronized users aren’t editable here. For AD Sync, add or change the alias in the on-premises directory and let the next synchronization populate Sophos Fusion.
Important: Sophos processes and scans only addresses that exist as a mailbox or alias. Messages to or from nonexistent addresses are deleted as part of address validation. Don’t remove an old alias until senders have been moved and the replacement delivery path has been tested.
Review sending limits and bulk-sender privileges
Under My Products > Email Security > Mailboxes, open the user mailbox and check the Bulk email sender privileges section to see whether no request, a pending request or an existing privilege is shown. Standard users and privileged senders have different documented sending limits, and no more than 5% of an organization’s users can have bulk-sender privileges. Before requesting them, record the genuine sending need, expected volume and purpose.
For legitimate bulk sending, select the user mailbox and click Request bulk sender privileges. Enter the frequency, approximate number of emails per period and purpose, then click Save. If the action is missing, go to Global Settings > Products and Services > Email, open Gateway Domains or M365 Mailflow Domains, and verify that the relevant domain is set to Inbound and Outbound.
After Sophos reviews the request, check the displayed privilege status again and validate it with a controlled test below the currently documented limits.
Delete only after a dependency review
Deleting a mailbox removes all data associated with it. Back up important data and review at least the primary address, aliases, assigned Email Security policies and, for a distribution list, its owner.
Deleting a user under My Environment > Users & Groups also removes that user’s associated entry from Email Security > Mailboxes. It doesn’t delete associated devices or uninstall Sophos software. Sophos Fusion can recreate the user after a login on an associated device that is still managed, or after directory synchronization while the source object remains in scope. To suppress these triggers, follow Delete Sophos Fusion users safely, then verify that the user remains absent immediately after deletion, after the next relevant synchronization, and while monitoring device sign-ins.
For a manually managed mailbox, select the entry under My Products > Email Security > Mailboxes, click Delete, then confirm with Delete. You can’t delete a synchronized mailbox here: exclude it with the directory synchronization filter or delete it at the directory source.
Validate inventory and mail flow
Don’t rely only on the success message after manual creation or import:
- Find new users under People; verify distribution lists and public folders directly under Mailboxes.
- Compare display name, primary address, type and aliases with the approved inventory.
- Open each user mailbox and review the displayed aliases and policy memberships.
- Send a test message to the primary address and every new alias, then confirm delivery. If outbound sending is required, test a reply as well.
- Only then retain the import file and change record according to your internal retention policy.
Troubleshoot specific failures
- Duplicate address: Check primary addresses and aliases in both the protected inventory and CSV for the same address. Don’t bypass the conflict by creating another object.
- Wrong mailbox type: Use only
User,DLorPFin the CSV. Correct the business type before importing again. - Invalid import row: Check the Name, Email Address, Type header and order, required values, delimiter and address validity; reimport only corrected rows.
- Import spins indefinitely: Check UTF-8 and the 2 MB limit, refresh, use batches of 1,000 or 500, and retry outside peak hours.
- License exceeded: Reconcile protected primary user mailboxes with the entitlement. Don’t count aliases as extra licenses; resolve inventory or licensing before retrying.
- Alias isn’t editable: Check the sync icon and owner. Change an AD or Entra object only at its source and wait for the next sync.