How QCST Protects Stored Inbound Mailbox Passwords

This article explains encrypted-at-rest credential storage, server crypto requirements, and why passwords are not exposed in diagnostics.

Where this fits in QC Support Ticket

Inbound email is a Max/All Access feature. Each enabled mailbox connects to an ordinary IMAP account, routes new tickets to one Department, can accept replies to existing tickets, and can process attachments and supported Agent commands according to the mailbox settings.

Inbound processing is intentionally defensive: it checks sender authority, ticket identity, deduplication, loop/bounce/automatic-message signals, attachment policy, and mailbox state before it changes ticket data.

Primary location: Joomla Administrator → Components → QC Support Ticket → Email Templates → Inbound Mailboxes.

Before you begin

  • Confirm the site currently has Max / All Access effective access before expecting the controls described here. A preserved configuration may still exist after downgrade even when the feature is locked.

Credential handling

  • Inbound mailbox passwords are stored through QCST/Joomla server-side secret protection rather than intentionally printed back into ordinary diagnostics.
  • The server must have the required cryptographic/runtime support for protected secret storage.
  • Connection Test/processing errors are sanitized; support requests should never include the mailbox password.
  • Leaving/changing password fields should follow the form's saved-secret behavior rather than copying a secret into screenshots or notes.

Important behavior and limits

  • Do not include IMAP passwords or full private mailbox content in screenshots/support posts; use QCST's sanitized diagnostics.

Verify the result

  • Mailbox Test succeeds before unattended processing is relied upon.
  • Process Now handles one controlled message exactly once and records a safe result without duplicate ticket/reply creation.

If it does not work as expected

  • If connection fails, verify PHP IMAP, host/port/encryption/certificate settings and credentials before changing routing.
  • If connection succeeds but processing fails, inspect sender policy, ticket reference matching, duplicate/loop checks, mailbox capabilities, and attachment policy.

Community Discussion

For practical QC Support Ticket workflows and discussion with other Joomla site owners, visit the QC Support Ticket Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.