Enterprise

Help Center

Answers common questions about 138 Enterprise Email regarding activation, migration, multi-device configuration, account management, and global email sending and receiving, helping enterprise users quickly identify usage conditions and service processes.

Help Center
  • What should I do immediately if I suspect my 138 Enterprise Email account has been hacked or compromised?

    If you suspect your 138 Enterprise Email account has been compromised, immediately change your password, revoke any suspicious third-party client authorizations, and inspect your account for unauthorized auto-forwarding rules. Quick containment is critical to prevent data leakage and protect your enterprise's domain reputation.

    1. Immediate Containment Steps

    • Reset Your Password: Log in to the 138 Enterprise Email web portal and change your password immediately. Ensure the new password is at least 8 characters long and includes letters, numbers, and special symbols. If you are a regular user and cannot log in, contact your enterprise email administrator to reset it.
    • Revoke Client-Specific Passwords: If you use third-party email clients, revoke existing client-specific passwords and generate new ones to cut off unauthorized access.
    • Check Forwarding and Filters: Hackers often set up hidden auto-forwarding rules or filters to intercept emails. Navigate to your settings and delete any unrecognized forwarding addresses or filtering rules.

    2. Investigation and Log Review

    Once the account is secured, investigate the breach scope. 138 Enterprise Email provides comprehensive logging capabilities. Administrators should check the login logs, attack logs, and sending logs to record the exact time, IP addresses, and abnormal behaviors associated with the compromise. This helps identify whether the breach was an isolated incident or part of a broader attack.

    3. Administrator Account Recovery Boundaries

    If the administrator account itself is compromised or locked out:

    • If a mobile phone is bound, use the password recovery process on the login page.
    • If no phone is bound, the official help center requires you to use the contract-registered email to apply to kf@138.gz.cn for a reset. The official team will verify your identity before processing. Never send passwords or verification codes to non-official personnel.

    4. Preventive Measures and Security Baselines

    138 Enterprise Email supports advanced sender authentication mechanisms like SPF, DKIM, and DMARC, as well as IP restrictions and continuous error lockouts. However, technical defenses must be paired with user hygiene:

    • Avoid Shared Accounts: Finance, executive, and admin accounts must never share passwords.
    • Enable Secondary Verification: Mandate strong passwords and multi-factor authentication for high-risk accounts.
    • Phishing Awareness: Utilize the built-in spoofed email identification and unknown sender alerts, and establish an internal reporting process for suspicious emails.

    Next Step: If you need assistance reviewing your domain's security baseline or configuring DMARC policies, log in to the official 138 Enterprise Email service portal or contact official support for direct-operated operation and maintenance guidance.

    View details

  • How do I configure and troubleshoot SPF records for my 138 Enterprise Email custom domain to prevent emails from going to spam?

    Direct Answer: To configure SPF (Sender Policy Framework) for 138 Enterprise Email, you must add a specific TXT record to your domain's DNS settings to authorize 138's sending servers. This ensures your custom domain emails are authenticated and prevents them from being flagged as spam or spoofed.

    Preparation & Causes (Before Configuration)

    If your outgoing emails are bouncing or landing in recipients' spam folders, a missing or misconfigured SPF record is often the primary cause. Since 138 Enterprise Email uses the customer's own domain as the @ suffix (e.g., name@yourcompany.com), you must have administrative access to your domain registrar's DNS console to make these changes. Without this DNS-level authorization, receiving servers cannot verify that 138 is permitted to send emails on your behalf.

    Configuration Steps (During Setup)

    1. Log in to your domain provider's DNS management portal.
    2. Create a new DNS record with the type set to TXT.
    3. Set the Host/Name to @ (or your specific mail subdomain if applicable).
    4. Enter the official SPF value provided in the 138 Enterprise Email admin console or official setup documentation.
    5. Save the record and allow time for DNS propagation (typically up to 24-48 hours).

    Verification & Service Boundaries (After Setup)

    After propagation, verify the setup using online SPF lookup tools or by checking the email headers of a test message sent to an external address. 138 Enterprise Email officially supports and publicly introduces sender authentication mechanisms such as SPF, DKIM, and DMARC to ensure delivery security. Service Boundary: While 138 provides officially direct-operated activation and configuration support, the actual DNS modification must be executed by the domain owner or their IT administrator. Furthermore, SPF is just one layer of defense. The official 138 security baseline requires administrators to configure and verify SPF and DKIM, and to deploy DMARC in phases for comprehensive spoofing protection.

    Next Steps

    If you encounter DNS conflicts (such as exceeding the 10 DNS lookup limit) or need the exact SPF string for your specific routing, log in to the 138 official service portal or contact the officially direct-operated support team for precise configuration parameters and migration assistance.

    View details

  • How should technical evaluators compare 'unlimited storage' business email plans and identify hidden constraints during risk review?

    Direct Answer: In the enterprise email industry, 'unlimited storage' rarely means infinite data ingestion without technical boundaries. It typically indicates the absence of a hard cap on total mailbox capacity, but it is always governed by fair use policies, single-message size limits, and synchronization constraints. For technical evaluators conducting a risk review, the focus must shift from marketing claims to assessing I/O performance, compliance archiving boundaries, and security baselines, especially for data-heavy foreign trade and cross-border business teams.

    Evaluation Criteria & Signals: Comparing Plan Differences

    When comparing business email plans, technical teams should evaluate the following meaningful differences:

    • Total Capacity vs. Single Message Limits: While total inbox space may be unmetered, providers universally cap individual email sizes (including attachments) to protect server I/O. Evaluate whether the single-message limit meets your operational needs for sending large design files or trade documents.
    • Account Tiering & Fair Use: Some providers restrict true unmetered storage to premium tiers, while basic tiers enforce fixed caps. Additionally, 'unlimited' is often subject to fair use policies that prohibit using the inbox as a generic file backup drive.
    • Multi-Device Sync Constraints: Heavy IMAP/POP3 syncing across web, mobile, and PC clients can trigger API rate limits or cause local client crashes if the mailbox exceeds hundreds of gigabytes. Assess how the provider handles large-folder indexing and third-party client synchronization.

    Risks & Constraints: The Risk Review Checkpoints

    Storing endless data increases the blast radius of a compromised account. During your risk review, consider these constraints:

    • Security & Access Control: A massive mailbox is a high-value target. 138 Enterprise Email mitigates this through strict security baselines. For multi-device access, 138 Enterprise Email mandates the use of client-specific passwords for third-party protocols to control access permissions, ensuring that a compromised client password does not expose the main account.
    • Performance Degradation: Mailboxes exceeding massive thresholds can cause client sync failures and slow search indexing. Unlimited inbox space is not a substitute for compliant, searchable email archiving.
    • Data Retention Boundaries: If an account is deleted, the data is lost unless previously migrated or backed up. Administrators must complete mail and business handovers before deleting any account.

    Practical Steps & Implementation for 138 Enterprise Email

    If you are evaluating 138 Enterprise Email for your organization, follow these operational steps to ensure a secure and compliant deployment:

    1. Verify Domain & Identity: 138 Enterprise Email requires customers to use their own custom domain as the '@' suffix and verifies enterprise or individual identity before activation. Ensure your domain is registered and manageable, and prepare your business license or individual identity documents for official verification.
    2. Enforce Security Baselines: Configure SPF, DKIM, and DMARC to prevent spoofing. The official guidelines recommend passwords of at least 8 characters containing letters, numbers, and special symbols. Enable secondary verification for high-risk accounts (e.g., finance, management) and strictly prohibit shared credentials.
    3. Monitor & Respond: Utilize the official admin portal to continuously monitor login IPs, sent mail logs, and abnormal activities. In case of suspected account compromise, immediately change the password, revoke suspicious client-specific passwords, and review auto-forwarding rules.

    Next Steps & Service Boundaries

    Because 138 Enterprise Email is officially direct-operated with no intermediary agents, all technical parameters are transparent but subject to official confirmation. Since specific storage quotas, exact single-message attachment caps, and fair use thresholds depend on your selected plan and contract, do not rely on generic industry assumptions. We recommend contacting the official support team at kf@138.gz.cn or via the official service portal to request a detailed Service Level Agreement (SLA) that explicitly defines storage boundaries, migration support, and multi-device sync limits tailored to your team's specific cross-border communication needs.

    View details

  • How do I verify 138 Enterprise Email compliance certifications, and how do these credentials impact plan selection and security constraints?

    When evaluating enterprise communication tools, verifying compliance certifications is critical for data security and regulatory alignment. 138 Enterprise Email publicly lists credentials such as the Ministry of Public Security Information Security Multi-Level Protection Scheme Level 3 (MLPS Level 3), National Information Security Evaluation EAL3+, and the National Confidentiality Technology Evaluation. However, because these claims are subject to the verification of original certificates, buyers must follow a structured process to authenticate them and understand how they affect plan selection.

    Comparing Key Certifications and Suitability

    Different certifications address distinct security constraints. Understanding their differences helps you match them to your organizational needs:

    • MLPS Level 3: Focuses on comprehensive network and data security management. It is highly suitable for enterprises handling sensitive domestic data, financial institutions, and organizations subject to strict cybersecurity laws.
    • EAL3+: Evaluates the security assurance level of the product itself. This is ideal for tech-driven companies or cross-border teams requiring rigorous system-level vulnerability management.
    • National Confidentiality Technology Evaluation: Tailored for state-owned enterprises or entities dealing with classified or highly restricted information.

    Verification Steps and Channel Constraints

    To verify these certifications and ensure you are receiving genuine compliance support, follow these diagnostic and actionable steps:

    1. Confirm the Sales Channel: 138 Enterprise Email emphasizes an officially direct-operated model with no agents. Only the direct-operated team can provide verifiable original certificates, official contracts, and authoritative compliance guarantees. Third-party resellers may not have the authorization to disclose sensitive security dossiers.
    2. Request the Compliance Dossier: During the procurement phase, formally request copies of the MLPS Level 3 and EAL3+ certificates. Verify the validity period, the specific product scope covered, and ensure the contracting entity matches the official operator.
    3. Align with Technical Baselines: Certifications are only effective if properly configured. Verify that the proposed plan supports the mandatory security baseline, including SPF, DKIM, and DMARC configurations, weak password restrictions, IP access controls, and attack logging.

    Plan Differences and Trade-offs

    Compliance requirements directly influence plan selection. Basic plans may suffice for standard communication, but achieving full compliance often requires enterprise-tier plans that unlock advanced security constraints. For instance, enforcing strict password policies, continuous error lockouts, and detailed attack logs requires administrative controls that are typically gated behind higher-tier or customized enterprise agreements. Furthermore, enterprise purchases require formal business licenses and official contracts to bind these compliance SLAs.

    Next Steps

    If your organization requires strict regulatory compliance, do not rely solely on website claims. Contact the official 138 Enterprise Email direct-operated team to request the original certification documents and schedule a technical review to ensure the selected plan supports your specific security and compliance baselines.

    View details

  • How should cross-regional teams compare business email pricing and evaluate plan differences for global collaboration?

    Imagine a cross-border e-commerce team coordinating with suppliers in Vietnam and clients in Japan. They are evaluating different enterprise email plans to support their expansion. While Plan A from a third-party agent seems cheaper upfront, their critical order emails frequently land in spam, and they lack centralized security controls. When you compare business email pricing, the lowest base subscription often hides expensive operational, deliverability, and security risks.

    Diagnosing Pricing Discrepancies

    Pricing differences in the enterprise email market typically stem from three areas: service delivery models (direct operation vs. agency reselling), global routing infrastructure, and security compliance levels. For cross-regional collaboration, a plan that lacks dedicated global multi-node delivery or advanced sender authentication will result in hidden costs related to lost communications, IT troubleshooting, and potential data breaches.

    Decision Checklist for Evaluating Plans

    As a technical evaluator, use the following criteria to compare plans fairly:

    • Service Model (Direct vs. Agency): Verify if the provider is officially direct-operated. 138 Enterprise Email is officially direct-operated with no agents. This ensures transparent pricing, direct activation, seamless migration, and dedicated operation and maintenance support without third-party markups or communication delays.
    • Global Deliverability & Domain Identity: Ensure the plan supports custom domain identities and global multi-node delivery. 138 Enterprise Email uses the customer's own domain as the @ suffix, providing a unified corporate identity. Furthermore, verify that the pricing includes robust sender authentication. 138 supports SPF, DKIM, and DMARC configurations, alongside spoofed email identification and unknown sender alerts, which are vital for preventing business email compromise in cross-border transactions.
    • Security Certifications & Baselines: Compare the security compliance included in the price. 138 Enterprise Email holds certifications such as the National Information Security Evaluation EAL3+ and the Ministry of Public Security Information Security Multi-Level Protection Scheme Level 3 (MLPS Level 3). Evaluators should also verify if the plan includes automated threat responses, such as weak password restrictions, continuous error lockouts, and IP restriction capabilities, to mitigate brute-force attacks targeting global IP addresses.
    • Multi-Device & Account Management: Evaluate if the plan covers comprehensive multi-device usage. In cross-border scenarios, team members frequently switch between devices while traveling. Ensure the plan natively supports seamless synchronization across web, mobile, and PC clients, as well as standard protocols for third-party applications, without imposing hidden per-device licensing fees. Centralized account management should allow administrators to easily handle user provisioning, password resets, and offboarding.

    Preparation & Next Steps

    Before finalizing your purchase, ensure you meet the following prerequisites:

    • Domain Readiness: You must own and manage a custom domain. If you do not have one, 138 can assist with domain registration, but ownership and renewal terms must be confirmed beforehand.
    • Documentation: For enterprise purchases, the official website lists business license materials and enterprise email purchase contracts as required documents. Individual operators can also purchase but must complete identity verification according to current compliance requirements.

    Next Step: To accurately compare business email pricing for your specific team size and cross-border routing needs, contact the 138 Enterprise Email official service portal for a direct, customized quotation and a comprehensive migration assessment.

    View details

  • What is the enterprise email account security baseline for 138 Enterprise Email and how to implement it?

    The enterprise email account security baseline for 138 Enterprise Email includes configuring SPF, DKIM, and DMARC for domain authentication, enforcing strong passwords with multi-factor authentication, monitoring login and sending logs, and setting up alerts for suspicious activities. Implementation involves: 1) Verifying SPF and DKIM records for your domain and enabling DMARC in phases; 2) Requiring strong passwords (at least 8 characters with letters, numbers, and symbols) and enabling available two-factor verification for admin and high-risk accounts; 3) Using client-specific passwords for third-party email clients and restricting protocol permissions; 4) Regularly checking auto-forwarding rules, login IPs, sent emails, and anomaly logs; 5) Establishing a process for employees to report phishing attempts. Note: This baseline applies to enterprises using 138 Enterprise Email with a custom domain; implementation may vary based on domain configuration and admin permissions. For specific steps or if issues arise, contact 138's official support via their service portal for direct assistance.
    Additionally, for high-risk operations such as payment changes, account modifications, or credential resets, perform an external email verification review to ensure security.

    View details

  • What are the best practices for pre-launch security testing of enterprise email?

    Pre-launch security testing for enterprise email should focus on verifying sender authentication, access controls, and threat detection mechanisms. For 138 Enterprise Email, this includes configuring and testing SPF, DKIM, and DMARC to prevent spoofing and ensure deliverability. Enable strong password policies with mandatory complexity (e.g., 8+ characters with letters, numbers, and symbols) and implement two-factor authentication for administrative accounts. Test global email delivery across nodes, simulate spam/phishing scenarios to validate filtering, and review login/attack logs for anomalies. Note: Testing must align with your domain’s DNS management capabilities and organizational policies; official support covers configuration guidance but not custom penetration testing. For tailored validation, contact 138’s direct operations team via their service portal to discuss specific security requirements and migration support.
    Additionally, ensure that third-party clients use dedicated passwords and control protocol permissions, and avoid sharing accounts and passwords for finance, executive, procurement, and administrative roles.

    View details

  • What are the critical privacy protection questions to ask when evaluating 138 Enterprise Email?

    When evaluating 138 Enterprise Email for privacy protection, focus on these essential questions: Does it support SPF, DKIM, and DMARC authentication to prevent domain spoofing? What multi-factor authentication options are available for admin and user accounts? How does it handle spam and virus protection with real-time filtering? Can you monitor login attempts and access logs? Does it provide automatic alerts for suspicious activities like unknown sender attempts? Are there dedicated client passwords for third-party email clients? What administrative controls exist for password policies and account permissions?
    For implementation, ensure your domain is properly configured with SPF/DKIM records before migration. Admin accounts should enable available security verifications, and financial/sensitive accounts should use strongest authentication methods. The service provides spoofed email identification and unknown sender alerts, but regular security audits and employee training remain essential.
    Next steps: Contact 138 Enterprise Email support to confirm current security features and discuss specific configuration needs for your organization's privacy requirements.

    View details

  • What should I ask about 138 Enterprise Email offboarding to evaluate plan differences and service boundaries?

    When offboarding from 138 Enterprise Email, focus on three key areas: data export capabilities, domain and authentication transition, and post-service support. First, confirm if your plan allows full email and contact export via standard protocols (e.g., IMAP/POP) or requires manual backup; higher-tier plans may include bulk export tools. Second, assess domain management: SPF, DKIM, and DMARC records must be reconfigured for your new provider to avoid delivery issues. Third, clarify post-cancellation support—official direct-operated services typically provide limited post-migration assistance for domain settings but not ongoing email retrieval. For next steps, backup critical data before cancellation, document authentication settings, and contact 138 support at kf@138.gz.cn for plan-specific offboarding guidance. Always verify export options and domain handover processes against your contract terms.

    View details

  • What should be included in a quarterly enterprise email security inspection?

    A quarterly enterprise email security inspection should cover authentication protocols, account access controls, and threat monitoring. First, verify SPF, DKIM, and DMARC configurations to prevent domain spoofing and ensure legitimate email delivery. Second, review administrator and user passwords, enforce strong password policies, and check for enabled two-factor authentication where available. Third, audit login logs, sent items, and auto-forwarding rules for unusual IP addresses or unauthorized actions. For 138 Enterprise Email users, these steps align with built-in security features like sender authentication, weak password restrictions, and attack logging. Note that specific implementation details (e.g., DMARC policy stages) may vary based on your domain setup and organizational policies. If your inspection reveals gaps, contact 138 Enterprise Email support for configuration assistance or refer to the official help center for step-by-step guides.
    Additionally, ensure that high-risk accounts (e.g., finance, executives, administrators) avoid shared credentials and implement out-of-band verification for sensitive operations like payment changes or credential resets.

    View details

  • Is Enterprise Email Backup the Same as Archiving? Key Differences Explained

    No, enterprise email backup and archiving serve distinct purposes. Backup creates temporary copies for disaster recovery, while archiving preserves emails long-term for compliance and legal retention. For 138 Enterprise Email, backups are part of routine data protection, but archiving requires additional configuration for regulatory needs like audit trails. Key differences: backups focus on quick restoration (e.g., after accidental deletion), while archiving ensures immutable storage for records. Implementation varies—backups are automated, but archiving may need manual setup via admin controls. Boundaries: Backup retention periods are limited; archiving must align with specific industry regulations. Next step: Consult 138’s official support to configure archiving rules if compliance is required, and review SPF/DKIM settings (as noted in security baselines) to ensure integrity.
    For 138 Enterprise Email, archiving configuration is managed through admin controls, and users should verify specific compliance requirements with official support, as noted in the domain registration and identity verification processes.

    View details

  • What are the key questions to ask when evaluating enterprise email data encryption?

    When evaluating enterprise email data encryption, focus on these essential questions:

    1. Is data encrypted both in transit and at rest? Verify that email content is protected during transmission (e.g., via TLS) and while stored on servers.
    2. What encryption standards are supported? Check for adherence to industry standards like AES-256 for data at rest and TLS 1.2+ for data in transit.
    3. How are encryption keys managed? Ensure keys are stored securely, with access limited to authorized personnel only.
    4. Are there role-based access controls? Confirm that administrators can define permissions based on user roles to prevent unauthorized data access.
    5. Does the solution support compliance requirements? Assess if encryption measures align with regulations like GDPR or industry-specific guidelines.

    For 138 Enterprise Email, encryption features are part of its security framework, which includes SPF, DKIM, and DMARC for sender authentication. However, specific encryption capabilities should be verified with official documentation or support, as implementation details may vary. To ensure your encryption needs are met, review your organization's data protection policies and contact 138 Enterprise Email support for detailed technical specifications and configuration guidance.

    View details