All services require authentication using the full email address as UserID, e.g. joebloggs@zelan.co.nz and password.
New accounts will be supplied with an inital password that will need to be changed on first use. It is highly recommended that you connect initially via Webmail to test connectivity and set your password, then proceed to configure an Email Client after that.
If you encounter problems connecting an Email Client, it's likely you've become blocked and will need to contact Zelan Support for assistance.

Branded Webmail for private domains hosted at Zelan can be reached using axigen.private-domain.co.nz, replace private... with your actual domain!! They can also be reached using the generic axigen.zelan.co.nz host using the icon above.
The existing Zimbra Server and Desktop Software versions became "End of Life" with effect from 31st Dec 2023 and no longer receive security updates.
Unfortunately there is no viable upgrade path, so we are migrating to a new product called Axigen.
The migration to the new system started on Saturday 5th September 2026. The process should be largely automated, assuming that your Email Client was originally configured correctly. If not we'll have to tweak as required.
Your 1st login to the new Axigen Server will cause emails to be migrated, but Address Books may need some manual intervention. The migration process may take a while if you have a lot of old emails.
Note: Calendar features are now a Premium (Paid) upgrade, contact us for pricing. Old Calendar events can be retrieved once the account is upgraded.
IMPORTANT: Automated migration can only occur using Webmail or an Email Client using the IMAP protocol with unencrypted password.
The old Zimbra Server will continue to be available for a period of time, but will only contain old emails, once migration has been initiated.
Do not change passwords on the old or new systems until the migration process for all accounts has been completed, doing so will break your access to email.
Only fully secure protocols, i.e. SMTPS and IMAPS using TLS/SSL are supported outside the Zelan network. STARTTLS is not supported.
Full access is available to Zelan Email services and for any private domains it hosts from within the Zelan network and more widely throughout New Zealand and Australia.
The Third Party database which determines origin countries can lead to false positives and false negatives, it should be fine for major and/or long established ISPs, but newly established IP blocks can change countries and take a while before the database gets updated.
Other countries are specifically blocked and will require a VPN or Dynamic DNS e.g. no-ip.com, to be implemented. In addition, due to the high volumes of SPAM and targetted attacks, all access is blocked from Belarus, Brazil, Russia, Seycelles and Ukraine. Anyone requiring to receive email from banned locations will need to provide comprehensive details of the sender in order for WhiteList entries to be created.
Before you start, ensure the time, timezone and date are set correctly and accurately on your device. Secure connections can fail if time/date is incorrect.
Due to the plethora of different email clients, the different terminology they use and the frequency with which things change, it is impractical to maintain an exhaustive list of specific instructions. The information below is generic, so you may need to seek expert help if you don't have the requisite skills. Whilst Zelan email is currently nominally FREE, this is only for access via Webmail, any support required for configuring email clients will incur a support charge.
Zelan Email Server Hostname = axigen.zelan.co.nz
(mail.zelan.co.nz can also be used, but is not guaranteed to be available long term)
(various zwi.co.nz hostnames will also work again eventually, but currently failing on connections configured to use STARTTLS, they work OK for TLS/SSL or unencrypted)
| Service | Description | Security | Protocol | Port | Notes |
|---|---|---|---|---|---|
| SMTP | Unsecured email submission | None or STARTTLS | TCP | 587 | 2nd Choice |
| SMTPS | Secured email submission | TLS/SSL | TCP | 465 | 1st Choice |
| POP | Unsecured email retrieval | None | TCP | 110 | Backstop choice |
| IMAP | Unsecured email retrieval | None or STARTTLS | TCP | 143 | 2nd Choice |
| IMAPS | Secured email retrieval | TLS/SSL | TCP | 993 | 1st Choice |
Whenever possible always use secure services with S suffix as first preference. For very old applications that do not support TLS v1.2 or higher you will need to use the unsecured services.
For nominally unsecured connections, where both ends support STARTTLS and this is successfully negotiated on connection, the connection will actually be encrypted, but do not bank on it. It is hard to tell whether any specific connection is encrypted or not, so always assume not.
The technical requirement is that all devices and applications must now support TLS v1.2 or higher.
"Secure Email" is actually badly named, since it doesn't guarantee end to end security, it primarily protects your email password when submitting email. Whilst it does also protect the email from your email client to the local server, it is likely to be transmitted in Clear Text thereafter. For full security you need to implement S/MIME or PGP. Both ends need to support this, so can be cumbersome to setup and maintain.
Due to security updates, very old applications may no longer be able to access the Zelan Email Server via the "secure" services. Regrettably due to increasing attacks on servers by malicious people, we cannot leave the server vulnerable simply to support very outdated applications. The following list is by no means exhaustive, but gives the minimum versions for some applications that are in widespread use. In general terms, if the application or device is newer than 2020 and/or is configured for regular security updates and the supplier is still actively maintaining the product, it should continue to work.
The workaround for very old applications that do not support TLS v1.2 and need to be retained, is to configure them for unsecured access to the email server.
The most likely applications to fail are old printers/fax machines/scanners that forward via email.