Frequently Asked Question

Internal Only Email
Last Updated 3 hours ago

Internal-only email is an email service designed to work only inside your organisation or private business network. It gives staff normal-looking email addresses, but those addresses are not published to the public internet, cannot receive mail from outside, and cannot send mail to external domains.

A typical example would be:

  • fred.bloggs@sales.gen

This looks like a normal email address, but it exists only within a controlled private environment. It is intended for internal communication between staff, departments, sites, or approved connected businesses, not for general internet email.

What internal-only email means

With standard business email, a mailbox is part of the global email system. Anyone on the internet can potentially send to it, and the user can usually send out to any public address.

With internal-only email:

  • the mailbox exists only within a private mail system
  • the domain is private and not publicly routable
  • incoming mail is accepted only from approved internal systems
  • outbound mail to the public internet is blocked
  • the service is usually available only from:
  • the office network
  • a site-to-site private link
  • VPN
  • a secure communications platform
  • approved managed devices

In simple terms, it is email as an internal messaging platform, not as an internet-facing communications tool.

How GEN provide addresses such as fred.bloggs@sales.gen

GEN can provide internal-only email by building the mail service so that it operates inside a private namespace and private mail environment, rather than on the public internet.

This is commonly done using a combination of the following controls:

  • Private domain naming
  • Internal domains such as sales.gen are used only inside the business environment.
  • They are not set up as public internet email domains for normal global mail exchange.
  • No public mail exposure
  • No public-facing mail routes are provided for those addresses.
  • External mail servers on the internet cannot deliver messages to them.
  • Restricted mail transport
  • Mail servers are configured to accept and relay messages only for approved internal domains and approved internal sources.
  • Sending to external public domains such as gmail.com or outlook.com is blocked.
  • Private DNS and directory control
  • The address may only resolve inside the company network or GEN-managed secure environment.
  • Outside users cannot meaningfully discover or use the address.
  • Network access restrictions
  • Access is limited to office connections, VPN, private WAN links, or GEN secure communications platforms.
  • This prevents use from arbitrary public networks unless specifically authorised.
  • Authentication and device policy
  • Only approved users on approved devices can log in.
  • Access can be tied to MFA, device compliance, location policy, and account controls.

In practice, the mailbox behaves like normal email for the people who are supposed to use it, while remaining invisible and unusable to the outside world.

Why it is not sendable or reachable from the public internet

Internal-only email is deliberately prevented from functioning as public email. That is achieved by policy and technical design.

Typical measures include:

  1. No public mail exchange path
  • The system does not accept mail from unknown internet mail servers.
  1. No external delivery rights
  • Users are not permitted to send to public domains.
  1. Private-only routing
  • Messages are routed only within the internal mail estate or approved private interconnects.
  1. Firewall and access controls
  • Mail services are not openly exposed for public access.
  1. Directory isolation
  • Address books and mailbox details stay inside the private environment.

This creates a strong boundary between internal communications and internet communications.

Why this satisfies so many risk metrics

Internal-only email reduces risk because it removes one of the biggest attack surfaces in most businesses: internet email.

Public email carries substantial exposure:

  • phishing
  • malware attachments
  • malicious links
  • spoofing
  • impersonation
  • business email compromise
  • credential theft
  • spam
  • data leakage
  • accidental disclosure
  • harassment and unwanted contact
  • OSINT-driven targeting of staff

When a mailbox cannot exchange mail with the outside world, many of those risks are greatly reduced or removed entirely.

Key risk reductions

  • No inbound phishing to those users
  • External attackers cannot email those internal-only addresses.
  • No spam
  • Public spam campaigns cannot reach the mailbox.
  • No malicious attachments from the internet
  • Common malware delivery methods are removed.
  • No malicious links arriving by email
  • Many credential theft attempts never reach the user.
  • Reduced impersonation risk
  • Attackers cannot easily pose as customers, suppliers, banks, or executives via public email to those accounts.
  • No accidental emailing to the wrong external recipient
  • Users cannot send sensitive information to the outside world from that mailbox.
  • Reduced data exfiltration channel
  • Internal-only mailboxes cannot be used as a simple route to leak information externally.
  • Lower staff exposure
  • The address is not a public contact point, so it is less useful for stalking, abuse, social engineering, or targeted reconnaissance.
  • Simpler compliance position
  • It is easier to demonstrate reduced exposure where mail is not internet-facing.
  • Smaller monitoring and filtering burden
  • Security teams spend less effort dealing with hostile internet mail flow for those users.

Why this is attractive for audits, insurers, and security frameworks

Many security assessments look favourably on reducing unnecessary exposure. Internal-only email helps because it supports principles such as:

  • least privilege
  • users only get the communication capability they actually need
  • segmentation
  • internal messaging is separated from public messaging
  • attack surface reduction
  • fewer systems and users are exposed to hostile inbound traffic
  • data loss prevention
  • fewer opportunities to send sensitive data externally
  • zero-trust thinking
  • access and communication paths are tightly controlled
  • role-based access
  • only staff with a genuine external communication need are given internet email

This is often useful for:

  • cyber insurance questionnaires
  • ISO-aligned security controls
  • supply chain security reviews
  • internal governance reviews
  • regulated or high-sensitivity departments

Why many people do not need to email the world

In many companies, a large number of users do not actually need unrestricted internet email to do their job.

Examples include:

  • warehouse staff
  • factory floor staff
  • internal operations teams
  • dispatch teams
  • service desk back-office teams
  • finance processing roles
  • HR administration support
  • shift supervisors
  • internal approval chains
  • facilities teams
  • project coordination staff working only with internal stakeholders

These users often need to communicate with:

  • colleagues
  • managers
  • internal departments
  • site teams
  • approved group companies

They may not need to directly contact:

  • customers
  • suppliers
  • the general public
  • unknown third parties

For these roles, full public email can introduce unnecessary risk without providing meaningful business value.

Why internal-only email is often a perfect fit

Internal-only email works well where the business wants the familiarity of email without the danger of unrestricted internet messaging.

It is a strong fit when an organisation wants:

  • a familiar mailbox and address structure
  • simple internal communication
  • departmental address books
  • message records and auditing
  • controlled access across sites
  • reduced phishing exposure
  • reduced data leakage risk
  • better separation between internal and external communications

It is especially useful for:

  • operational teams
  • privileged users
  • sensitive departments
  • junior staff
  • temporary staff
  • kiosk and shared-device users
  • high-risk roles frequently targeted by attackers
  • businesses with strong compliance or confidentiality requirements

Summary

Internal-only email is a private email system for communication inside a business, not across the public internet. GEN can provide addresses such as fred.bloggs@sales.gen by hosting the mail service inside a controlled private environment, restricting routing, blocking external send and receive, and limiting access to approved users, devices, and networks.

This approach satisfies many security and compliance objectives because it removes a major attack path. For a significant number of staff, public email is unnecessary, while internal-only email provides exactly what they need: simple, familiar, auditable communication without the risks that come with being reachable from the world.


This website relies on temporary cookies to function, but no personal data is ever stored in the cookies.
OK
Powered by GEN UK CLEAN GREEN ENERGY

Loading ...