Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Cloud & Email

Shared Mailboxes vs Distribution Lists vs Microsoft 365 Groups

Someone asks for "an info@ address" and gets the wrong thing. A decision-first guide to which Microsoft 365 object you actually need, and the traps that bite later.

“Can we get an info@ address?”

It sounds like the simplest request in Microsoft 365, and it’s the one most often answered wrongly. Depending on who does the work, that request produces a shared mailbox, a distribution list, a Microsoft 365 group, a forwarding rule, or — worst of all — a whole extra licensed user with a password three people share.

All five will receive email at info@. They behave completely differently six months later, when someone leaves, when a customer says they never got a reply, or when the finance director asks who answered a complaint. So it’s worth ten minutes to understand what each one actually is.

The four objects, honestly described

A shared mailbox is a real mailbox that several people open alongside their own. It has an inbox, folders, a sent items folder and a history. Nobody logs into it — you’re granted permission to it, and it appears in your Outlook automatically. In the normal case it doesn’t need its own licence. When you reply, you reply as info@, and the customer sees the company address.

A distribution list isn’t a mailbox at all. It’s a delivery instruction: mail arriving for the address gets copied to each member’s own inbox. There’s no shared history, no shared folders, nothing to look back through. If three people are on the list, three copies of every enquiry land in three separate inboxes. When someone replies, they usually reply from their own address, and the thread leaves the list entirely.

A Microsoft 365 group is the modern bundle. It gives you a group mailbox plus a shared calendar, a SharePoint document library, and an identity that Teams can attach itself to. Add a person to the group and they get the lot. Remove them and they lose the lot. It’s designed for a team that works together on something, not for a passive address that receives forms.

A mail-enabled security group is a distribution list that can also grant permissions — to files, sites or applications. Useful and dangerous in the same breath, for the reason in the FAQ below: membership starts controlling access as well as delivery.

Use this when

Here’s the guidance we give when someone asks. It covers most real situations.

  • info@, sales@, enquiries@ → shared mailbox. Several people need to see what came in, see what’s already been answered, and reply as the company. That’s exactly what a shared mailbox does and exactly what a distribution list can’t.
  • accounts@ or invoices@ → shared mailbox, and be strict about it. Finance mail is the highest-risk mail you receive. You need one place with a searchable record of what arrived and what was sent back, not three inboxes with three partial views. It also makes fraudulent bank-detail changes far easier to spot, because everyone in the mailbox sees the same thread.
  • all-staff@ announcements → distribution list. It’s one-way. Nobody needs a shared history of the fire drill notice, and you don’t want a mailbox filling up with copies.
  • A project team → Microsoft 365 group, usually surfaced as a Team. They need files, a calendar and conversation in one place, and membership should control all three together.
  • A department that mostly emails each other → start with a distribution list. Add a Microsoft 365 group only when there’s genuinely shared work, not just shared email. Creating a Team for every department gives you a graveyard of empty channels.
  • Granting access to a SharePoint site → security group, kept deliberately separate from your mailing lists.

Getting this structure right at the start is the cheap moment. Untangling it after two years of accumulated forwarding rules is the expensive one, which is why it’s one of the first things we settle in a Microsoft 365 setup.

The traps

Sent items vanishing into personal folders. This is the most common complaint about shared mailboxes and it’s entirely fixable. By default, when you reply from a shared mailbox, the copy is saved in your Sent Items, not the mailbox’s. Your colleagues see the customer’s original email sitting in the inbox with no sign that anyone answered it, so someone answers it again. An administrator can switch the mailbox to keep sent copies in the right place. Do it on day one.

Everyone replying to everyone. Distribution lists scatter conversations. Four people receive an enquiry, two reply independently, the customer gets two different answers, and neither replier knows the other exists. Then someone hits reply-all on a message to the whole company and you lose twenty minutes of everybody’s morning. If a thread needs coordinating, it needs a shared mailbox.

One login, one password, shared around. Tempting, and wrong. A shared password can’t be attributed to a person, so there’s no accountability for what was sent or deleted. It has to be changed and redistributed whenever anyone leaves. And it makes multi-factor authentication awkward at best, because the second factor sits on one person’s phone while four people need to get in. Permissions solve all of that: each person signs in as themselves, with their own MFA, and the mailbox simply appears.

The leaver’s mailbox. When someone goes, the instinct is to delete the account and forward the mail. That loses the history. The better path is usually to convert the mailbox to a shared mailbox, remove the licence, and grant access to whoever picks up the work — the address keeps working, the past correspondence stays searchable, and you stop paying for a user who’s gone. There’s a right sequence for this, and doing it in the wrong order can cost you the mailbox contents, so it belongs in your written offboarding checklist rather than in someone’s memory.

The licensing gotcha. A shared mailbox is free of a licence only within limits, and the limits move. Microsoft currently caps unlicensed shared mailboxes at a set size, and once you cross it the mailbox needs a licence. The same applies if you want an online archive on it, or need to place it on legal hold. Check the current figures on Microsoft’s own documentation rather than trusting a number in any article, including this one. The practical point stands regardless: an accounts@ mailbox that has swallowed a decade of PDF invoices will eventually cost you something, so plan for it instead of discovering it when mail starts bouncing.

The short version

If people need to see the same conversation, you want a shared mailbox. If you’re broadcasting to people who never reply, a distribution list is enough. If a group needs files, a calendar and chat together, that’s a Microsoft 365 group. And if you’re granting access to anything, use a security group and keep it away from your mailing lists.

Ten minutes of choosing correctly saves a great deal of unpicking later. If your addresses have already grown into a tangle of forwards, aliases and shared passwords, straightening out business email is usually quicker than people fear — and a good moment to review how the rest of your Microsoft 365 environment is put together while you’re in there.

Frequently asked questions

Why do my replies from a shared mailbox end up in my own Sent Items?

Because that's the default behaviour. Outlook sends the reply as the shared address but files the copy in the sender's personal Sent Items, so colleagues opening the shared mailbox can't see what was answered. It's fixed with a setting on the mailbox itself — "copy sent items to the shared mailbox" — applied by an administrator. Change it the day you create the mailbox, because retrofitting it doesn't move the messages that already went astray.

Can we just share one login for the info@ account?

You can, and it causes trouble. A shared password can't be tied to a person, so nobody knows who replied or who deleted something, and it has to be changed and redistributed every time a member of staff leaves. It also fights multi-factor authentication, because the second factor lives on one person's phone. Granting each person permission to open the mailbox with their own account solves all of that at once.

What's the difference between a distribution list and a mail-enabled security group?

A distribution list only delivers email to its members. A mail-enabled security group does that too, but can also be used to grant permissions — to a SharePoint site, a shared folder or an application. That sounds convenient, and it is, right up to the point where someone adds a person to the group so they'll get the emails and quietly hands them file access nobody intended. Keep mailing groups and permission groups separate unless you have a clear reason not to.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.