# Set up Beam Email

> Provision tenant-owned domains and mailboxes without exposing platform provider credentials.

## Who owns what
Beam owns and operates the email transport. An agency can manage several client accounts, and each account can have several verified domains and mailboxes. Every domain, mailbox, user, thread, event, and usage entry belongs to exactly one workspace.
No client provider accountsClients never bring provider credentials and never see Beam infrastructure, another workspace, or raw provider identifiers.

## Domain onboarding
- An agency or platform administrator enters a dedicated sending domain for the client.- Beam returns a branded DNS checklist containing only the records the domain owner must add.- After DNS changes propagate, choose Verify. Beam requests verification and then reads the domain back before it reports Ready.
A pending or needs-attention state is not permission to send. Keep the domain paused until sending and, when required, receiving both show ready.

## Mailboxes
Create one or more mailbox identities under a verified domain. Each mailbox has a local part, display name, and inbound/outbound controls. Replies remain on the mailbox and RFC thread that received the message.

## Platform sending inventory
A platform operator can enable verified, unassigned Beam-owned domains for the platform Inbox composer. Beam performs a fresh provider read-back, creates a neutral hello@domain identity, and keeps any domain already owned by a client workspace unavailable outside that workspace.

## Agency operations
Agencies can deliver the DNS checklist in their own brand, monitor verification and delivery health, configure the client's allowance, and enter the client through Beam's audited support-access flow.
