Microsoft 365 has several ways to route email. Three of the most common are user mailboxes, shared mailboxes, and distribution lists.
They look similar in Outlook, but they behave differently. Picking the wrong one is how you end up with:
- enquiries getting missed,
- duplicate replies,
- “who has the password?” messages,
- and one person quietly becoming the human spam filter for the whole business.
This article sticks to those three. (There are other options too, like Microsoft 365 Groups and mail forwarding, but that’s a separate conversation.)
1) User mailbox (a mailbox for a human)
Examples: alex@, sarah@, john@
This is the standard mailbox assigned to a person.
- Uses a Microsoft 365 licence
- Intended for one human
- Comes with proper identity controls (MFA, auditing, sign-in logs, etc.)
Use a user mailbox when…
- One person owns the communication
- The email address represents an individual
- You want clean security and accountability (you do)
2) Shared mailbox (a mailbox for a role or team)
Examples: info@, sales@, accounts@, support@
A shared mailbox is built for multiple people to access the same inbox.
- No licence required for the mailbox itself in most small-business setups (there are limits, but this is the normal case)
- Multiple users can be granted access
- People sign in with their own accounts, and access the shared inbox via permissions
Use a shared mailbox when…
- Multiple people need to see the same emails
- You want a single “company” address customers recognise
- You need handover, visibility, and continuity (someone’s on leave and work still happens)
Bonus: shared mailboxes make offboarding easy
When someone leaves, you remove their access. You don’t reset a “shared password” and hope nobody wrote it on a Post-it note.
3) Distribution list (send one email to many people)
Examples: staff@, all@, marketing-list@
A distribution list is not a shared inbox. It’s a routing list.
- One email gets delivered to multiple recipients
- Everyone gets their own copy in their own mailbox
Use a distribution list when…
- You’re broadcasting information (announcements, “FYI”, newsletters internally)
- You want one address to reach a changing set of people
Don’t use a distribution list when…
- The email represents work that needs ownership (“someone handle this”)
- You need to know who replied
- You want a single thread in one place
Distribution lists are great for broadcasting. They’re terrible for accountability.
The big warning: stop sharing logins
If you take one thing from this article, take this:
Do not create a user like reception@ and share the password between multiple people.
Microsoft doesn’t like it. We don’t like it. Security people don’t like it. Future you definitely won’t like it.
Shared logins break:
- MFA (whose phone gets the prompt?)
- auditing (who actually sent that email?)
- offboarding (who still knows the password?)
- accountability (everyone can plausibly deny everything)
If multiple people need to access one inbox, use a shared mailbox and give everyone their own login.
Quick “what should I use?” checklist
- This address is a person → user mailbox
- This address is a role and multiple people need access → shared mailbox
- This address should email lots of people at once → distribution list
The bottom line
Microsoft 365 gives you the right building blocks for each scenario. Most email chaos comes from using the wrong type (or using the right type in the wrong way).
If your setup currently involves shared passwords and “who’s watching the inbox?”, we can clean it up: pick the right mailbox types, set permissions properly, and make sure it works the same way on every device. Boring and reliable is the goal. 🎯