Open your inbox, select Share, choose who may open it, and generate a link. The link opens a live read-only view of that whole mailbox. It does not give recipients the mailbox password, permission to delete messages or ownership. It does let an authorized viewer read sensitive content contained in the messages, including verification links.
Choose the access mode deliberately
| Mode in the share control | Who can open the link | Appropriate use |
|---|---|---|
| Anyone with the link | Anyone who obtains that active link | A deliberately non-sensitive test inbox |
| One registered account email | A signed-in TempMail Cloud account with the specified account email | One intended reviewer of a test mailbox |
| Private — owner only | The signed-in account that owns the mailbox | An owner-only shortcut, not a team invitation |
Restricted access matches a registered account email, not an arbitrary external mailbox or a guest address. Private owner-only mode needs an account-owned mailbox; a standalone guest mailbox has no registered owner who can pass that check.
What recipients can see and do
Recipients can refresh, search, filter and read the shared mailbox's messages. The view includes stored messages and new messages that arrive while the link is usable. It is not limited to the message you had selected when you copied the link.
They cannot use the shared view to see or change the mailbox password, star or delete mail, regenerate the address, or take ownership. Read-only describes those controls; it does not stop a viewer from copying text, saving a screenshot or using an actionable link in a message.
Worked example: let a reviewer check a signup email
Create a dedicated test inbox that contains no personal recovery messages. After your application sends the signup email, generate a link restricted to the reviewer's registered TempMail Cloud account email. Send it through your team's approved channel. The recipient signs in with that account and opens the link to inspect the received message.
After the review, deactivate the link from Existing links. If another confirmation arrives before you deactivate it, that message is also visible to the reviewer. Use a different mailbox when you need a different disclosure boundary; sharing does not provide message-by-message permission selection.
Stop or replace access
Open Share in the original authorized mailbox view, locate the link under Existing links, and choose Deactivate or delete it. Deactivation can later be reversed; deletion removes that link. Neither action retracts information that a viewer already copied.
Some older links show Replace & copy instead of Copy link. Replacing such a link creates a new link and makes the old token unusable. A replacement may need to be sent again to the intended recipient.
Changing the mailbox password does not automatically deactivate these links. Manage unwanted links separately, and contact support if you suspect a broader account or session compromise.
Keep the link out of public records
Do not paste a private inbox link into a public issue, analytics parameter or article. Treat an "anyone with the link" URL as a credential. Never share an inbox used for banking, primary account recovery, authentication secrets or other irreplaceable accounts.
Inbox sharing is separate from the 2FA tool and its setup-key sharing options. A mailbox share is not an invitation to sync authenticator secrets. For general access questions, use inbox recovery or the help index.