PressedMail
Home
Features
Pricing
Sign InChoose a Pro plan
    • Overview
    • Phishing Reports
    • Links & Images
    • Lock & Impersonation
    • Where Mail Lives
Documentation

Mailbox Lock and Impersonation

Put a second passphrase in front of your mail, and keep an administrator who switches into your account out of it.

Anyone with your WordPress session can normally read anything your role allows. Mail is not like other content, so PressedMail lets you put a second door in front of it, and it treats a switched-in administrator as a different person from you.

PressedMail Lock

Turn it on in your security settings with a passphrase of at least eight characters. From then on, plugin routes answer 423 Locked until this browser is unlocked. The unlock, status and settings routes stay reachable so the lock screen can render and take your passphrase.

Pick an inactivity timeout while you are there: never, 15 minutes, 30 minutes, 1 hour, or 4 hours. Change it later and the new value applies to every session immediately, because expiry is evaluated on read rather than stamped when the grant was made.

Grants are per browser

Unlocking one machine does not unlock the rest. PressedMail sets its own random cookie and stores an HMAC of that value against your user record. A different browser has a different cookie, so it has no grant. Logging out drops the cookie, which re-locks the mailbox on its own.

What is stored is a password_hash verifier and grant timestamps. Not the passphrase, not the raw cookie value, and nothing from your WordPress session. Up to twenty grants are kept. Ordinary activity slides the expiry on the current one, at most once a minute.

Locking again

  • Lock now revokes this browser.
  • Lock all sessions revokes every browser at once. No passphrase needed, because locking is always the safe direction.
  • Change passphrase requires the current one, revokes every grant, then re-grants only the browser you are sitting at.
  • Turn off requires the passphrase.

Forgotten it? Prove your WordPress password and the lock switches off. Nothing is encrypted under the passphrase, so a reset loses no mail, and someone who knows your WordPress password could sign in fresh anyway. That escape hatch is refused for a switched-in session.

Background sync keeps running

The lock gates interactive access, not the server. Mirror sync, scheduled sends and rules run inside a trusted system context bound to one account owner, so your mailbox keeps filling while you are locked out of looking at it. Unlock and the mail is already there.

Guessing is expensive

Five failed attempts start a lockout. It grows with each further failure, from 60 seconds up to a 15 minute ceiling, and it is stored against the user rather than the request, so hammering the REST endpoint from somewhere else does not reset it.

Impersonation blocking

PressedMail detects user switching through the User Switching plugin's own helper and through the switch actions firing on the request. When it sees one, mail access for that user is refused. So an administrator can still take over the account to fix a broken setting, and still cannot read the mail.

The preference lives on your user record and a missing value reads as protected. A brand new user, or one whose row was never written, is covered. Turning protection off is an explicit choice, and even then the security settings themselves stay out of reach of a switched session, so nobody can switch in and flip the toggle from underneath you.

Free and paid

Both are in every build. The lock and impersonation blocking ship in Free and in the paid editions alike.

Read Next

  • Where Your Mail Lives
  • Phishing Detection and Reports
  • Security and Privacy Intro
Previous

Link Analysis and Remote Images

What PressedMail checks before you click a link, and why remote images stay dark until you say otherwise.

Next

Where Your Mail Lives

What PressedMail stores in your WordPress database, how credentials are protected, and exactly what leaves the server.

© 2026 PressedMail. All rights reserved.
DocsSupportTermsPrivacyRefunds
PressedMail

A WordPress-Native Email Workspace. Connect your existing email accounts and manage messages, contacts, and calendar from your WordPress dashboard.

Product

  • Features
  • Pricing

Resources

  • Docs
  • Changelog
  • Roadmap

About

  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy

© 2026 PressedMail. A product of CurbSoftware Tech Innovations.

PressedMail processes email on your WordPress site and connects directly to your email provider. CurbSoftware’s OAuth relay does not receive message bodies or attachments.