Enterprise

Help Center

Answers common questions about 138 Enterprise Email regarding activation, migration, multi-device configuration, account management, and global email sending and receiving, helping enterprise users quickly identify usage conditions and service processes.

Help Center
  • How to set strong passwords for 138 Enterprise Email accounts?

    To set strong passwords for 138 Enterprise Email, use a combination of uppercase letters, lowercase letters, numbers, and special characters, with a minimum length of 12 characters. Avoid common words, personal information, or sequential patterns. This aligns with 138's security baseline requirements for mitigating unauthorized access risks. Note that weak passwords may trigger system restrictions or temporary locks after consecutive failed attempts. For high-risk accounts (e.g., administrators, financial roles), enable available two-factor authentication if supported. After setup, verify login via web, mobile, or PC clients. If issues persist, contact 138's official support for password resets or security reviews, as custom configurations may vary by domain or subscription plan.
    For enhanced security, consider using client-specific passwords for third-party applications and restrict protocol permissions as part of 138's security baseline.

    View details

  • How to protect finance email accounts from phishing scams: key warning signs and immediate fixes

    To protect finance email accounts from phishing scams, implement sender authentication protocols (SPF, DKIM, DMARC), enable spoofed email identification, and use multi-factor authentication. Finance teams should watch for mismatched sender domains, urgent payment requests, and suspicious links. 138 Enterprise Email provides built-in security features including unknown sender alerts and global threat intelligence integration. Note that no solution guarantees 100% security—combine technical measures with employee training. For implementation, verify domain ownership and configure authentication records through the admin portal. If suspicious activity occurs, immediately quarantine the email, analyze headers, and update blocklists. Next steps: Contact 138 support for domain configuration assistance and request security training materials.

    View details

  • How to prevent similar domain scams on 138 Enterprise Email?

    To prevent similar domain scams (e.g., typosquatting or domain spoofing) on 138 Enterprise Email, implement sender authentication protocols like SPF, DKIM, and DMARC. These protocols verify email origins and block unauthorized senders. 138 Enterprise Email supports these mechanisms natively, alongside spoofed email identification and alerts for unknown senders, reducing the risk of phishing or fraud attempts. Ensure your domain's DNS records are correctly configured for SPF, DKIM, and DMARC alignment. Regularly monitor login and sending logs via the admin portal for suspicious activities. Note that while these measures enhance security, they require proper setup and ongoing management; for complex cases or full deployment guidance, contact 138's official support team to avoid misconfigurations.
    Additionally, enable two-factor authentication for administrator and high-risk accounts, use dedicated passwords for third-party clients, and establish employee phishing identification and reporting procedures as part of 138 Enterprise Email's security baseline.

    View details

  • How to configure and manage allowlist settings for trusted senders in 138 Enterprise Email?

    To configure an allowlist in 138 Enterprise Email, access the admin console, navigate to Security or Anti-Spam settings, and add trusted sender domains or specific email addresses. This ensures emails from these sources bypass spam filters and deliver directly to inboxes, which is essential for internal systems, key partners, or verified clients to prevent missed communications. However, overuse can increase spam risks; regularly audit and update the list. For domain-based entries, verify senders have valid SPF, DKIM, or DMARC configurations—138 supports these sender authentication mechanisms to enhance security and prevent spoofing. Note: Allowlists only affect inbound filtering; outbound security depends on proper DNS records like SPF declarations for your domain. If configurations involve multiple systems or migrations, consult 138's official support for current parameters and guidance, as specific hostnames, record values, and validation steps must align with their provided details to avoid service disruptions.

    View details

  • How to preserve evidence for email security breaches in enterprise environments?

    To preserve evidence for email security breaches, immediately isolate the affected account, capture logs of unauthorized access or sent emails, and retain original message headers with full routing and authentication data. Use your email administrator panel to export login records, IP addresses, and timestamps—138 Enterprise Email provides attack logs and sender authentication mechanisms (SPF, DKIM, DMARC) to trace spoofing or unauthorized activities. Ensure you document: 1) Time and source of breach, 2) Affected accounts/domains, 3) Actions taken (e.g., password reset, forwarding rules disabled). Note that forensic accuracy depends on timely action; logs may rotate periodically. For legal or compliance reporting, consult your IT team or legal advisor to validate evidence integrity. If using 138 Enterprise Email, access admin logs via the official service portal or contact support for assisted retrieval within contractual boundaries.
    Additionally, immediately change the password and revoke suspicious client or dedicated passwords, check automatic forwarding, filtering rules, aliases, and security verification information, and review login, attack, and sending logs to record time, IP, and behavior.

    View details

  • Is a shared mailbox account secure for business use?

    Shared mailbox accounts can be secure for business use if properly configured and managed, but they inherently carry risks such as unauthorized access, lack of individual accountability, and compliance gaps. For enterprises, especially those in cross-border trade or with security requirements, using a custom domain email service like 138 Enterprise Email enhances security through features like SPF, DKIM, and DMARC authentication, spoofed email identification, and multi-device access controls. Key steps to harden security include setting strong passwords, enabling two-factor authentication, regularly auditing access logs, and defining clear user roles. However, shared accounts may not support advanced individual tracking or meet specific regulatory needs—always verify capabilities with your provider. For a tailored assessment, contact 138 Enterprise Email to discuss your organization's requirements and implementation support.
    For enhanced security, ensure strong passwords and available security verification are set when creating mailbox accounts. Additionally, establish clear processes for onboarding, role changes, and offboarding to maintain accountability.

    View details

  • How to manage administrator access for corporate email?

    To manage administrator access in 138 Enterprise Email, log into the admin portal, navigate to 'Organization & Users—User Management,' and adjust permissions or reset passwords as needed. This is applicable for enterprises using custom domains, with admin rights pre-configured during service activation. Key steps include setting strong passwords (minimum 8 characters with letters, numbers, and symbols), enabling two-factor verification for high-risk accounts, and regularly reviewing login logs for anomalies. Note that official support handles admin password resets only via contract-verified channels (e.g., email to kf@138.gz.cn), not for standard user accounts. For unresolved access issues or complex scenarios like cross-region teams, contact 138's direct support for tailored configuration guidance.
    If an administrator forgets their password and has a bound mobile number, they can reset it via the password recovery process on the login page. If no mobile is bound, a request must be sent from the contract-reserved email to kf@138.gz.cn for official verification and handling.

    View details

  • Is monitoring employee email legal for companies using 138 Enterprise Email?

    Yes, employee email monitoring is generally legal for companies when properly implemented with 138 Enterprise Email, but requires specific compliance measures. Legal monitoring must serve legitimate business interests such as security protection, quality control, or regulatory compliance. Companies should establish clear email usage policies that employees acknowledge, implement monitoring through administrator capabilities provided by 138 Enterprise Email, and limit monitoring to business-related communications. The service supports security features including login verification, access logs, and suspicious activity alerts that facilitate compliant monitoring. However, companies must avoid monitoring personal communications without consent and should consult legal counsel regarding specific jurisdiction requirements, particularly for cross-border operations. For implementation guidance, contact 138 Enterprise Email support for administrator configuration assistance and policy templates.

    View details

  • How to enable two-factor authentication (2FA) for 138 Enterprise Email?

    Two-factor authentication (2FA) can be enabled through your 138 Enterprise Email admin console under security settings. This adds an extra verification step beyond your password, typically requiring a code from an authenticator app, SMS, or email. Before enabling, ensure your account has administrative privileges and that you have access to your chosen verification method (e.g., a mobile device for SMS or an app like Google Authenticator). Note that 2FA availability may depend on your subscription plan and regional support. For step-by-step setup instructions, log into your admin portal or contact 138 Enterprise Email support for guided assistance. If issues arise during activation, verify your internet connection and check for any service advisories on the official status page.
    Available 2FA methods include SMS, email, and authenticator apps, as confirmed in security capabilities.

    View details

  • Why should I use app-specific passwords with 138 Enterprise Email for third-party clients?

    App-specific passwords are required for third-party email clients (e.g., Outlook, Thunderbird, mobile apps) when two-factor authentication (2FA) is enabled on your 138 Enterprise Email account. They enhance security by generating unique, revocable passwords for each application, reducing risks if a device is compromised. Without them, standard login credentials might expose your account to unauthorized access.
    To set up: Log into the 138 web portal, navigate to security settings, generate a dedicated password for each client, and use it exclusively for that app. Regularly review and revoke unused passwords. Note that app-specific passwords do not replace 2FA but complement it for protocol-based access. For migration or bulk setup, consult 138's official support to ensure compliance with your organization's security policies.

    View details

  • What login history does enterprise email store and how long is it retained?

    138 Enterprise Email stores comprehensive login logs including timestamps, IP addresses, device/browser types, and success/failure status for each authentication attempt. These logs help enterprises monitor access patterns, detect unauthorized attempts, and meet compliance requirements. Retention periods vary by service tier but typically range from 30 to 90 days for standard plans, with extended retention available for compliance needs.

    To access these logs, administrators can use the official service portal's security audit section. The system supports filtering by user, date range, IP, or event type. For enterprises requiring longer retention or integration with SIEM systems, additional archival services may be available through official support channels.

    Key preparation includes ensuring proper admin permissions and understanding your organization's compliance requirements. Note that log accessibility and features may depend on your specific service plan. For exact retention periods and advanced audit features, consult your service agreement or contact 138 Enterprise Email support with your account details.

    View details

  • How to restrict login IPs for 138 Enterprise Email?

    To restrict login IPs for 138 Enterprise Email, administrators can configure IP whitelisting through the official management console. This feature allows only specified IP addresses or ranges to access email accounts, enhancing security for enterprises with fixed office networks or VPN setups. Common causes for setup issues include incorrect IP format entry, overlapping ranges, or lack of administrator permissions. Before implementation, verify your domain is fully activated and ensure you have documented all legitimate corporate IPs. Note that this feature may not support dynamic IP environments like mobile networks, and overly restrictive settings could block legitimate remote access. For step-by-step guidance or if configurations fail, contact 138's official support team via the service portal for direct assistance, as they manage activation and migration processes without third-party agents.
    For detailed configuration steps, administrators should log into the web management console and navigate to the security settings section to define permitted IP addresses or ranges.

    View details