Board Reporting by Email and the Limits of Written Governance: Implications in the Era of Mailbird

Email-based board communications create serious vulnerabilities in confidentiality, compliance, and governance quality. This article examines the legal, regulatory, and technical limitations of conducting board reporting through email, and explores how email management tools fit within a landscape where email itself remains inherently insecure.

Published on
Last updated on
+15 min read
Michael Bodekaer

Founder, Board Member

Oliver Jackson

Email Marketing Specialist

Abraham Ranardo Sumarsono

Full Stack Engineer

Authored By Michael Bodekaer Founder, Board Member

Michael Bodekaer is a recognized authority in email management and productivity solutions, with over a decade of experience in simplifying communication workflows for individuals and businesses. As the co-founder of Mailbird and a TED speaker, Michael has been at the forefront of developing tools that revolutionize how users manage multiple email accounts. His insights have been featured in leading publications like TechRadar, and he is passionate about helping professionals adopt innovative solutions like unified inboxes, app integrations, and productivity-enhancing features to optimize their daily routines.

Reviewed By Oliver Jackson Email Marketing Specialist

Oliver is an accomplished email marketing specialist with more than a decade's worth of experience. His strategic and creative approach to email campaigns has driven significant growth and engagement for businesses across diverse industries. A thought leader in his field, Oliver is known for his insightful webinars and guest posts, where he shares his expert knowledge. His unique blend of skill, creativity, and understanding of audience dynamics make him a standout in the realm of email marketing.

Tested By Abraham Ranardo Sumarsono Full Stack Engineer

Abraham Ranardo Sumarsono is a Full Stack Engineer at Mailbird, where he focuses on building reliable, user-friendly, and scalable solutions that enhance the email experience for thousands of users worldwide. With expertise in C# and .NET, he contributes across both front-end and back-end development, ensuring performance, security, and usability.

Board Reporting by Email and the Limits of Written Governance: Implications in the Era of Mailbird
Board Reporting by Email and the Limits of Written Governance: Implications in the Era of Mailbird

The evolution of electronic communication has fundamentally transformed how boards of directors receive information, deliberate, and record their decisions. Yet this digital transformation has exposed significant weaknesses that organizations can no longer afford to ignore. Directors routinely receive sensitive board materials via email, often to personal accounts, creating vulnerabilities that threaten confidentiality, legal compliance, and governance quality itself. Research from BoardEffect highlights how email-based board communications expose organizations to cyberattacks, metadata exposure, misrouting, and discovery in litigation , while the formal requirements of board governance—minutes, resolutions, and structured deliberation—often exceed what email can reliably support. For busy directors managing multiple board seats, the email problem compounds daily. Important governance communications compete with hundreds of routine messages, buried in overflowing inboxes where spam filters may intercept critical materials and where tracking who has actually reviewed board documents becomes nearly impossible. Meanwhile, governance guidance from regulators and standard setters increasingly emphasizes structured information flows, robust documentation, and integrated reporting —all of which highlight the limitations of relying on unstructured email trails as a primary record of board activity. This article examines the legal, regulatory, technical, and practical dimensions of board reporting by email, explores the limits of written governance when conducted through informal channels, and positions email management tools like Mailbird within this landscape. While Mailbird offers powerful capabilities to manage high volumes of email efficiently and securely at the client level, it operates within an ecosystem where email itself remains inherently vulnerable. Understanding these boundaries is essential for boards seeking to balance convenience with compliance, security, and governance excellence.

Conceptual Foundations: Board Reporting, Email, and Written Governance

Conceptual Foundations: Board Reporting, Email, and Written Governance
Conceptual Foundations: Board Reporting, Email, and Written Governance

The Role of Board Reporting in Corporate Governance

Board reporting sits at the heart of modern corporate governance because directors can only fulfill their oversight duties when they receive timely, relevant, and reliable information about the company's performance, risks, strategy, and stakeholder relationships. The UK Financial Reporting Council stresses that boards must agree on and oversee the flow of information to and from the board, specifying the nature, source, format, and frequency of the information they require, and monitoring its quality to ensure it supports effective decision-making.

These expectations place substantial demands on the systems and channels through which board reporting occurs. Academic surveys of information flows within corporations emphasize that frictions in communication—such as delays, asymmetries, and noise—can impair both managerial decisions and board oversight, thereby affecting firm value and risk outcomes. The quality of board decisions depends not only on content but also on the structure and traceability of the information flows that precede them.

The International Corporate Governance Network argues that boards must present a balanced and understandable assessment of the company's position and prospects through integrated reporting that links strategy, risks, performance indicators, and long-term value creation in a coherent narrative. This requirement naturally raises questions about whether unstructured email threads, often fragmented across multiple accounts and devices, can serve as a reliable basis for the board's official record, particularly in complex or contested situations.

Written Governance: Minutes, Resolutions, and Formal Records

Written governance refers to the body of formal documents that record the decisions, deliberations, and oversight activities of the board and shareholders, including board minutes, resolutions, committee reports, and written consents. In jurisdictions such as the UK, companies are legally required under section 248 of the Companies Act 2006 to keep minutes of all directors' meetings and retain these minutes for at least ten years as part of the company's statutory records.

Board resolutions—whether passed in meetings or in writing—are legally binding actions taken by the board, while board minutes are the official written record of what occurred during a meeting, including discussions, votes, and follow-up actions. Irish company law recognizes written resolutions of directors and shareholders as legally valid decisions with the same effect as decisions taken at meetings, provided that statutory time limits and constitutional procedures are respected.

These formal written instruments serve multiple governance objectives beyond mere compliance. Law firm guidance notes that formal board materials are often the primary record of the actions directors approved or directed, and that well-designed communication and documentation protocols help ensure that the board's process and decisions are accurately reflected in the official record when subjected to scrutiny in litigation, regulatory investigations, or shareholder demands for books and records.

Email as a Ubiquitous but Problematic Governance Channel

Email remains one of the most ubiquitous tools for business communication, including board-related correspondence, because it is familiar, asynchronous, and widely accessible across devices and geographies. Surveys cited by governance technology providers indicate that a substantial proportion of directors still use email, including personal email accounts, to receive board materials and communicate with fellow directors and executives, often because it appears easy and convenient.

For many small companies and private boards, written resolutions and routine approvals are commonly circulated and agreed by email, reflecting a pragmatic approach to governance where scheduling formal meetings for every decision would be impractical. Tools such as Mailbird, which consolidate multiple accounts into a unified inbox and provide productivity features for managing large volumes of email, further reinforce the centrality of email in organizational workflows by making it easier for directors and executives to stay on top of their communications.

However, the very ubiquity and informality of email also create significant problems when it is used for board reporting and written governance, especially given increasing regulatory and investor scrutiny of board processes. Governance-focused vendors and law firms highlight that email is notoriously insecure, prone to phishing and spoofing, and difficult to control once messages are sent, exposing organizations to data breaches, ransomware attacks, and unauthorized dissemination of sensitive board materials.

Email's unstructured nature complicates version control, makes it hard to ensure that all directors see the same up-to-date information, and impairs the creation of a single authoritative record of board deliberations and decisions. Moreover, reliance on email for written resolutions and approvals can erode opportunities for deliberation, raise questions about the authenticity of votes, and blur the line between informal exchanges and formal board actions, thereby undermining the clarity and defensibility of governance records.

Mailbird as a Contextual Anchor

Mailbird enters this landscape as an email management platform designed to maximize team and individual productivity by consolidating multiple email accounts, including personal and business addresses, into a single, unified interface for Windows and macOS users. Mailbird's security analysis acknowledges that email privacy settings and basic encryption often fail to protect users fully, because common implementations like Transport Layer Security (TLS) only encrypt messages in transit between servers and do not protect email content once stored on servers or devices.

The platform emphasizes that it stores email data exclusively on users' computers, with no server-side storage of message content by Mailbird itself, thereby limiting the extent to which Mailbird can access or mine users' email content and reducing exposure to certain categories of centralized data breaches. Mailbird's privacy policy underscores its commitment to processing personal data in accordance with data protection laws, limiting retention periods, and allowing users to exercise rights such as access, deletion, and objection to certain processing activities.

Within the context of board reporting and written governance, Mailbird should be understood as a client-side tool that can help directors and governance professionals manage email more efficiently, but that does not—and cannot—alter the fundamental properties of email as a protocol or the legal and governance obligations that attach to board communications. It can support better organization of board-related email, enable integration with shared mailboxes used by governance or investor-relations teams, and reduce the cognitive load associated with switching between multiple accounts, but it cannot eliminate the security risks inherent in email or transform informal email threads into formal board records without appropriate supporting governance structures.

Legal and Regulatory Landscape for Electronic Board Communications
Legal and Regulatory Landscape for Electronic Board Communications

SEC Guidance on the Use of Electronic Media in the United States

In the United States, the Securities and Exchange Commission has long recognized and regulated the use of electronic media for delivering information to investors and other stakeholders, offering guidance that indirectly shapes how boards and issuers use email and related tools. The SEC clarifies that issuers and intermediaries may deliver required documents electronically, including in portable document format (PDF), provided that investors have consented and can effectively access the materials.

The SEC further notes that embedded hyperlinks within a prospectus or other filed document can cause the hyperlinked information to be treated as part of that document for securities law purposes, illustrating how digital communication structures can affect the legal status of information. While this guidance primarily addresses external investor communications rather than internal board reporting, it underscores the regulatory sensitivity around electronic communications and the importance of clarity, consent, and accessibility.

However, the SEC's focus on ensuring that investors receive required information in a clear, accessible, and compliant manner indirectly highlights the shortcomings of unstructured email as a primary vehicle for formal board reporting, especially when compared with purpose-built portals that can track delivery, receipt, and access. Moreover, in litigation or enforcement contexts, emails and other informal communications among directors can be subject to discovery and may be scrutinized for inconsistencies with formal disclosures, emphasizing the need for disciplined governance practices in how email is used.

E-Discovery, Privilege, and AI-Related Electronic Records

US litigation practice has increasingly recognized that electronic records—including emails, texts, and, more recently, generative AI prompts and outputs—can be discoverable and may affect privilege protections. A 2024 alert from law firm Baker Donelson warns that whenever employees, officers, or directors use consumer AI tools to analyze legal exposure, research complaints, or prepare for dispute resolution, they may create records that opposing counsel or regulators can seek in discovery.

The alert advises clients not to use consumer AI platforms to research legal questions or input information received from attorneys, because doing so risks waiving attorney–client privilege and generating discoverable prompts and outputs outside secure legal channels. For boards, this guidance extends the logic applied to email: both email and consumer AI tools can create written records that may be exposed in litigation if not carefully managed and segregated from privileged communications.

Baker Botts stresses that board communications and records routinely address strategically significant, competitively sensitive, and legally consequential matters, making them prime targets in litigation and regulatory investigations. The firm recommends that substantive written or electronic communications between directors occur either through secure board portals or company-hosted email accounts, and that directors avoid substantive company-related communications via personal email, texts, or chats to reduce the risk of inadvertent discovery and contextual misinterpretation.

Written Resolutions and Minutes Under UK and Irish Law

In the UK, guidance for directors clarifies that board resolutions can be adopted either during a board meeting or as written resolutions, with different voting thresholds and procedural requirements depending on the method used. Under standard Model Articles for UK private limited companies, board resolutions passed at a meeting usually require a simple majority of eligible directors present, whereas written board resolutions generally require unanimous agreement from all eligible directors unless the articles state otherwise.

Practical Law guidance notes that companies' articles of association often provide for written resolutions and that a resolution in writing, signed by all directors entitled to receive notice of a board meeting, is as valid as a resolution passed at a duly convened meeting. This guidance also discusses the possibility of circulating resolutions electronically, with directors signing copies and returning them electronically, and highlights that electronic communications evidencing unanimous agreement can be effective provided the articles do not preclude such procedures and appropriate safeguards—such as using nominated email addresses—are in place.

In Ireland, directors and shareholders can make decisions without holding meetings by signing a written resolution, which has the same legal effect as if a meeting had been held. For shareholder written resolutions, Irish law imposes a statutory time limit: resolutions must be passed within 28 days of circulation, failing which they automatically lapse, whereas director written resolutions have no statutory time limit but may be subject to constraints in the company's constitution.

Both UK and Irish practice stress that written resolutions, whether circulated on paper or electronically, must be retained with company records and kept available for inspection like meeting minutes, often for periods of at least six years or longer depending on jurisdiction and company law. This retention requirement raises practical issues when written resolutions are circulated primarily via email, because organizations must ensure that signed copies—whether physical or electronic—are centrally archived and not left scattered across individual directors' inboxes or personal devices.

Governance Codes, Investor Expectations, and Communication Channels

Beyond formal company law, governance codes and investor guidance shape expectations for how boards communicate and report on their activities, influencing the perceived adequacy of email-based reporting. The FRC's Corporate Governance Code guidance, updated in 2024, emphasizes that the board should ensure appropriate information and communication systems are in place, including mechanisms for timely information flows between reporting lines, units, and individuals.

The ICGN's Integrated Business Reporting Guidance articulates investor expectations that boards provide holistic disclosures linked to the company's business model, strategy, risks, and opportunities, using key performance indicators and objective metrics where possible. It encourages boards to ensure that disclosures are accessible, appropriately integrated across different information sources, and, where appropriate, strengthened by independent assurance, reflecting a preference for structured, curated reporting systems rather than ad hoc communication methods.

Taken together, these frameworks suggest that while email can play a role in supporting board reporting and shareholder communication—for example, by distributing reports or notices—it is not generally viewed as an adequate primary vehicle for the formal, integrated, and assured reporting that regulators and investors expect from boards. Instead, boards are encouraged to adopt more structured solutions such as board portals, integrated reporting platforms, and secure governance systems that can provide centralized, auditable, and role-based access to information, while using email more sparingly and cautiously for supplementary communications.

Risks and Limitations of Board Reporting by Email

Email security risks and confidentiality concerns in board governance and reporting
Email security risks and confidentiality concerns in board governance and reporting

Security, Confidentiality, and Cyber Risk

One of the most frequently cited risks of using email for board reporting is security, especially given the high value of board-level information to cybercriminals and malicious actors. BoardEffect describes a scenario in which a spear phishing email, masquerading as a message from the board secretary and containing a malware-laden attachment about an upcoming board meeting, leads two directors to inadvertently download malware that infiltrates the organization's email system and exposes passwords, bank account numbers, employee social security numbers, and other sensitive data.

The article notes that hackers increasingly deploy sophisticated spear phishing and ransomware attacks targeting board members, who may be busy and more inclined to trust emails that appear to come from familiar colleagues or officers. When board materials and communications are routinely sent via email, especially to personal accounts with weaker security, the attack surface expands and the potential damage from a successful compromise becomes severe.

Diligent's white paper on secure communications for directors emphasizes that email remains a highly vulnerable attack vector, with Symantec's 2017 ISTR report estimating that around 8,000 businesses per month were targeted by business email scams. The paper notes that many directors use personal email accounts, such as Yahoo or Gmail, for board communications, which are inherently risky because they sit on shared, third-party platforms where confidential information can be forwarded—intentionally or inadvertently—to unauthorized users and where account compromises can expose large volumes of sensitive correspondence.

Mailbird's security analysis explains that TLS encryption, the most common form of email encryption, protects emails only while they travel between servers and does not provide protection once emails are stored on servers or local devices, leaving messages exposed to attackers who gain access to those systems or intercept emails after delivery. Even end-to-end encryption schemes can be undermined when messages are sent between different providers or systems, because the sending system may temporarily decrypt messages to deliver them in plaintext to recipients using incompatible encryption, creating windows of vulnerability.

Furthermore, encryption typically does not protect email metadata—such as sender, recipient, timestamps, subject lines, and message size—which can reveal sensitive patterns about board communications even if the content remains encrypted. These factors make email an inherently fragile medium for board reporting, particularly where highly sensitive information such as merger plans, cyber incident responses, regulatory investigations, or executive misconduct is discussed.

Compliance, Data Protection, and Archival Obligations

Beyond security, the use of email for board reporting raises compliance challenges related to data protection, privacy regulations, and record retention requirements. BoardEffect notes that data privacy regulations such as the EU General Data Protection Regulation (GDPR) treat email as personal and protected information, and that laws like the US Federal Rules of Civil Procedure (FRCP) require organizations to keep and store an archive of emails for discovery purposes.

This dual status—email as both personal data and corporate record—creates tensions for boards and organizations that use email heavily for governance communications, because they must simultaneously preserve emails for legal and regulatory reasons and minimize the retention of personal and sensitive data to reduce risk and comply with privacy obligations.

Mailbird's privacy policy explains that it retains personal data for 36 months after users stop using its services, unless a longer retention period is required or permitted by law, and provides users with rights to access, correct, delete, and object to certain processing activities. While Mailbird does not store email content server-side, the organizations whose email accounts are managed through Mailbird remain responsible for their own retention policies and compliance with laws governing email archives, records, and litigation holds.

Law firm guidance reinforces that informal communications, including emails and texts involving directors, are often highly sought after in litigation and may be reviewed alongside formal board materials to assess the board's process and state of mind. Baker Botts advises that directors should avoid creating unofficial records of meetings, such as personal notes or emails discussing board business outside official channels, because such records can complicate privilege analyses and create inconsistent narratives when compared with formal minutes.

Process, Deliberation, and Governance Quality Limitations

Even if security and compliance risks could be mitigated, board reporting by email poses substantive governance challenges related to deliberation, context, and decision quality. Irish guidance on written resolutions emphasizes that such resolutions work best for routine or straightforward decisions where everyone agrees and no discussion is needed, while more complex, contentious, or strategic matters benefit from the discussion and question-and-answer opportunities that meetings provide.

Similarly, UK guidance notes that while written board resolutions can save time and reduce administration—especially when directors are in different locations or when decisions are urgent—they inherently lack the transparency and richness of discussion that occur in meetings, and they may encourage directors to sign without fully considering implications if not accompanied by adequate deliberation.

When board reporting and decision-making are conducted largely via email, these concerns are amplified because email threads can fragment discussion, obscure who has read or responded to which messages, and encourage quick, informal replies that may not reflect considered judgment. BoardEffect points out that administrators have no reliable way to know if board members have received or read emailed materials, particularly given spam filters and overloaded inboxes, and that tracking responses or votes across large boards becomes cumbersome when conducted through email.

The volume of email many directors receive increases the risk that important communications will be overlooked or delayed, undermining the timeliness and effectiveness of board oversight. When email serves as the default channel for most board reporting, the board's information architecture effectively relies on individual directors' personal inbox management practices, which may vary widely in discipline and effectiveness, rather than on a centrally governed system with consistent structures and access rights.

Authentication, Identity, and Integrity of Email-Based Votes and Approvals

A further limitation of email as a governance channel concerns authentication and the integrity of votes, approvals, or consents communicated via email. Nonprofit lawyer Ellis Carter, cited by BoardEffect, warns that voting by email poses risks because there are no clear assurances that the email vote was executed by the specified board member, given the prevalence of hackers and imposters in cyberspace; email votes could be fraudulent or improperly obtained, potentially undermining the validity of decisions.

Practical Law guidance on board resolutions by email acknowledges that electronic communications evidencing unanimous agreement can be effective, but suggests safeguards such as ensuring that each director's agreement comes from a nominated email address and that the company secretary confirms receipt of consents from all directors.

Mailbird's email security analysis highlights the importance of technical controls such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC) policies, enforced with reject settings rather than monitoring-only, to combat email spoofing and business email compromise. It also recommends multi-factor authentication (MFA), preferably using phishing-resistant methods like hardware security keys, and the use of AI-driven email filtering to detect anomalous communication patterns suggestive of compromise.

However, even with these controls, email-based approvals or votes may still be questioned in high-stakes contexts, particularly where legal frameworks or company constitutions anticipate written signatures or formal meeting procedures. Electronic signature laws, such as the UK Electronic Communications Act 2000, generally recognize e-signatures as legally admissible, and practical guidance notes that directors can sign copies of resolutions and return them electronically, with signed originals retained as company records. However, this approach still treats email primarily as a delivery mechanism for signed documents rather than as the record of consent itself, reinforcing the distinction between the formal written resolution and the email that transmits it.

Alternative Channels and Tools for Governance Communication

Alternative Channels and Tools for Governance Communication
Alternative Channels and Tools for Governance Communication

Board Portals and Governance-Specific Collaboration Tools

In response to the limitations of email, an entire category of governance technology—board portals—has emerged to provide secure, structured, and role-based platforms for board communication and collaboration. BoardIntelligence describes a board portal as a secure digital platform designed to support the entire life cycle of board activity, from preparing and distributing board papers to managing approvals, and emphasizes that it is not a general-purpose file-sharing tool or a one-way broadcast like email.

According to BoardIntelligence, board portals offer several advantages over email and generic collaboration tools, including being designed specifically for governance, providing time-saving automation, implementing enterprise-grade security with role-based access and audit trails, serving as a single source of truth for board documents, and supporting hybrid and remote governance.

Praxonomy highlights that board portals implement multi-defense security frameworks to prevent data breaches and protect board communications, while email security often falls short. It notes that board portals are designed from the ground up with security considerations and adhere to strict data privacy policies, often aligned with standards such as ISO 27001, and that they offer secure storage, retention, and archiving of board documents for audit, historical tracking, transparency, and compliance purposes.

These solutions effectively re-architect the information environment in which boards operate, replacing the dispersed, unstructured nature of email with centralized repositories, structured agendas, and controlled workflows. Directors can access board materials through dedicated apps or web interfaces that require secure authentication, and they can collaborate on documents, annotate materials, and record decisions within the portal, creating a unified audit trail. While such systems may still use email for notifications—such as alerts that new materials are available—the substantive content and records of board activity reside within the portal, reducing reliance on email as a governance medium.

Secure Messaging and Company-Hosted Email for Directors

Recognizing that not all board communication will take place within a portal, governance advisors advocate for secure messaging and company-hosted email accounts as secondary channels, particularly when directors must communicate between meetings about time-sensitive issues. Baker Botts recommends that substantive written communication between directors occur either through secure board portals or through company-hosted email accounts, while discouraging the use of personal email accounts or accounts provided by other entities for company-related communications because such use exposes those accounts to discovery and may undermine confidentiality and privilege.

The firm also advises against informal methods such as text or chat for substantive board communications, noting that such methods may fail to capture directors' considered thinking and may be taken out of context. Diligent's white paper similarly urges boards to move away from email, text, and other insecure communication channels for board-related materials, arguing that while no solution is 100 percent secure, boards should adopt communication tools built with robust encryption and governance features.

This emphasis on secure channels does not eliminate the role of email but reframes it as a supporting medium that should be carefully configured, monitored, and integrated with governance tools rather than relied upon as the primary vehicle for board reporting and decision-making.

Hybrid Approaches Combining Written Resolutions and Meetings

As seen in UK and Irish practice, hybrid approaches that combine written resolutions with meetings can provide flexibility while preserving the benefits of deliberation and formal records. Open Forest advises boards to ask whether a decision will benefit from discussion, and if so, to hold a meeting—even an informal video call—rather than relying solely on written resolutions, while using written resolutions liberally for routine decisions where everyone agrees and no discussion is needed.

This hybrid model can also be applied to digital governance architectures by using board portals for formal agenda items, minutes, and resolutions, while allowing limited use of email or secure messaging for preparatory exchanges, clarifying questions, or logistical coordination. Email in such a model becomes a conduit for notifications and links rather than the content repository itself, and written governance documents—such as signed resolutions and approved minutes—are centrally stored and controlled within a governance system.

For Mailbird users, this suggests a governance-aware configuration where board-related email accounts are clearly separated, notifications about portal updates are managed efficiently, and directors minimize substantive governance discussions in email while relying on formal systems for records.

AI, Digital Tools, and Emerging Governance Challenges

The rise of generative AI tools introduces new dimensions to digital governance, as directors and executives experiment with using AI to summarize board papers, draft reports, or explore scenarios. Baker Donelson cautions that prompts and AI-generated content may become discoverable, and that using consumer AI platforms to analyze legal exposure or prepare for conversations with counsel can jeopardize privilege, especially if confidential information is input into systems whose terms of service allow data reuse or third-party access.

This risk intersects with email-based governance because directors may share AI-generated content via email or store AI prompts in email drafts, thereby further entangling informal channels with potentially sensitive and discoverable records. From a Mailbird perspective, AI-driven email filtering and anomaly detection can help protect email channels from compromise, but they do not address the separate governance risks associated with how boards use or share AI outputs in their decision-making processes.

Mailbird in the Governance Context: Capabilities and Limits

Mailbird in the Governance Context: Capabilities and Limits
Mailbird in the Governance Context: Capabilities and Limits

Overview of Mailbird's Capabilities and Architecture

Mailbird positions itself as a unified email client for Windows and macOS designed to maximize team productivity by consolidating multiple email accounts into a single, streamlined interface. Its business offering emphasizes features such as unified inbox views, integration with multiple email providers via standard protocols like IMAP and POP3, and the ability for individual team members to manage both personal and shared accounts without sharing passwords, aligning with best practices on accountability and access control.

Mailbird's 2026 guide on managing team email without shared logins explains that professional shared inbox solutions enable multiple team members to access a common email address using individual credentials, thereby creating individual access logs and audit trails that satisfy regulatory requirements and improve accountability. It notes that Microsoft 365 shared mailboxes, for example, allow users to access shared addresses through their personal accounts, with auto-mapping in Outlook and per-user logging of actions such as reading, responding, or forwarding messages.

Mailbird's security analysis highlights that its architecture stores email data exclusively on users' computers, with no server-side storage of message content by Mailbird, which means that Mailbird cannot read email contents after download or build behavioral profiles based on content. This local-storage design reduces the risk that Mailbird itself could be compelled to disclose email content in response to government requests or data breaches, although the underlying email providers and local devices remain subject to their own risks and obligations.

For board members and governance professionals, these features mean that Mailbird can serve as a powerful front-end for managing the email aspects of their governance roles, particularly when they must monitor multiple corporate and personal accounts or shared governance inboxes. It can consolidate notifications from board portals, corporate counsel, regulators, and investor relations into a single view, reducing the cognitive cost of switching between interfaces and helping ensure that important messages are not overlooked.

Mailbird's Security Posture and Constraints

Mailbird's July 2026 security analysis underscores the need for organizations to adopt layered defenses beyond encryption, noting that TLS protects data only while it travels between servers, and that even end-to-end encryption cannot hide metadata or protect against phishing, business email compromise, or human errors. The article recommends technical controls such as SPF, DKIM, and DMARC enforcement with reject policies; multi-factor authentication using phishing-resistant methods; AI-enhanced email filtering; encryption for data both in transit and at rest; and role-based access controls to restrict access to sensitive communications.

It also suggests organizational policies that prohibit sending sensitive information via email when alternative methods exist, implement balanced email retention policies, and segment email access to limit exposure. These recommendations align closely with broader governance advice on limiting the use of email for highly sensitive board communications and favoring secure portals or dedicated messaging solutions.

Mailbird's local-storage design can mitigate some centralized security risks but cannot protect against threats such as compromised local devices, malware, or unauthorized physical access to endpoints, which remain key concerns when board materials are stored on personal laptops or home desktops. Furthermore, because Mailbird connects to email providers via IMAP or POP3, its security is bounded by the configuration and policies of those providers, including whether they enforce modern authentication, encryption, and spam/phishing defenses.

From a governance perspective, Mailbird's shared inbox guidance illustrates how organizations can improve accountability and auditability in email workflows by moving away from shared logins and toward individual credentials for shared addresses. It explains that shared mailbox architectures allow every action performed in the shared mailbox to be tied to a specific individual user account, creating audit trails that satisfy regulatory requirements and enabling investigations when problems occur.

Governance-Compliant Use of Mailbird for Board-Related Email

To use Mailbird in a governance-compliant manner, boards and organizations need to align its deployment with their broader communication and documentation protocols, as articulated by legal advisors and governance codes. Baker Botts advises that directors avoid substantive company-related communications through personal email accounts and instead use secure board portals or company-hosted accounts, suggesting that Mailbird configurations should prioritize corporate accounts and create clear separation between board-related and personal email.

Organizations can, for example, provision board-specific corporate email addresses for directors, configure them with strong authentication and security policies, and enable directors to access them via Mailbird alongside their other professional accounts, thereby maintaining convenience without relying on personal addresses.

Mailbird's support for unified inboxes and multiple accounts also facilitates the separation of governance-related communication from routine operational email by allowing directors to visually distinguish messages by account and to adopt specific folders or labels for board communications. Combined with shared mailbox architectures, Mailbird can help governance teams manage communications to and from the board more effectively, ensuring that messages sent to shared addresses are promptly handled and that responsibility for responses is clearly tracked.

However, organizations should still adopt policies that limit the use of email for formal board reporting, preferring to send links to board portal materials rather than attaching sensitive documents, and that require directors to use portal or governance systems for voting, approvals, and access to formal records. Additionally, Mailbird users involved in board governance should adhere to Mailbird's own recommended security practices, such as enforcing MFA on all accounts, implementing robust spam and phishing filters, and regularly auditing access permissions, particularly for shared mailboxes.

Integrating Mailbird with Board Portals and Governance Systems

In practice, many organizations will adopt a hybrid communication architecture in which board portals serve as the primary governance system, while email—and, by extension, Mailbird—functions as a notification and coordination channel. BoardIntelligence argues that portals outperform email and generic collaboration tools by acting as single sources of truth for board documents, providing audit trails, and enabling role-specific access, thereby reducing the risk of confidential materials ending up in the wrong hands.

In such a model, Mailbird can be used to receive portal notifications—such as emails informing directors that new board packs are available—while directing directors to log into the portal for accessing materials and recording decisions. Mailbird's unified inbox allows directors who sit on multiple boards, each with its own portal and corporate email account, to manage their communications more efficiently without conflating content across organizations, which is important for preserving confidentiality and complying with multiple sets of governance policies.

Governance teams can also use Mailbird-managed shared inboxes to handle communications with external stakeholders, such as shareholders or regulators, while ensuring that formal disclosures and submissions are filed through appropriate channels and systems. This integrated approach reflects a broader trend in governance toward multi-channel communication architectures, where different tools are used for different purposes depending on sensitivity, formality, and regulatory requirements.

Case-Based Analysis: Scenarios Illustrating Email Governance Limits

Spear Phishing Through Board Email

BoardEffect's spear phishing example offers a vivid case study of how email-based board reporting can lead to catastrophic security breaches. In the scenario, every board member receives an email that appears to come from the nonprofit's board secretary, personally addressed to each member, with a message asking them to open an attachment containing information about an upcoming board meeting.

Two board members open the attachment, unwittingly downloading malware that infiltrates the organization's email system, enabling a hacker to steal passwords, bank account numbers, employee social security numbers, and other financial data. This incident illustrates how the combination of email-based board communication, personal trust in familiar senders, and inadequate technical controls can facilitate sophisticated attacks that exploit both human and system vulnerabilities.

Had the organization relied on a secure board portal to distribute meeting materials, directors would have received notifications pointing them to the portal rather than attachments in email, and the portal's authentication and malware scanning could have mitigated the risk of malicious content reaching the board. Even if Mailbird or another client had been used to access the compromised email, the underlying vulnerability would still lie in the trust placed in email attachments and the absence of governance protocols directing board members to safer channels for accessing materials.

Email-Based Written Resolutions and Disputes Over Validity

Consider a scenario in which a UK private company's directors attempt to pass a significant board resolution—such as approving a major acquisition—by email, without following formal written resolution procedures or holding a meeting. One director emails the others proposing approval, several directors reply "agreed" via email, and the company proceeds on the assumption that the resolution has been validly adopted, even though not all directors respond and no centralized record of consents is created.

Later, a dispute arises when a non-responding director claims the resolution was never validly adopted and that the process did not comply with the articles' requirements for unanimous written resolutions or proper meeting procedures. Practical Law's guidance suggests that electronic communications evidencing unanimous agreement by all directors can be effective, but only if the articles do not preclude such procedures and if safeguards—such as ensuring consents come from nominated email addresses and confirming receipt from all directors—are in place.

In this scenario, the absence of unanimous agreement and the lack of a formal written resolution signed by all directors or properly minuted meeting undermine the resolution's validity. Had the company instead circulated a formal written resolution document, obtained signatures (including via e-signatures) from all eligible directors, and retained the signed document with its company records, the risk of later disputes would have been reduced.

This example highlights the limits of email as a substitute for formal written governance instruments and underscores the need for clear board policies that distinguish between informal email discussions and formal decision-making procedures.

AI Prompts, Email, and Discoverable Records

A third scenario involves directors using consumer AI tools to analyze board materials or draft responses to regulatory inquiries, and then sharing those AI-generated outputs via email. For example, a director might paste confidential board reports into an AI chatbot to generate a summary, then email that summary—and perhaps even the prompt—to other directors for discussion, believing this to be an efficient way to digest complex information.

Baker Donelson's guidance warns that both the AI prompts and outputs may be discoverable in litigation and that using consumer AI tools in this way risks waiving privilege and exposing sensitive information to third-party platforms whose terms of service allow data reuse.

If these AI-generated summaries and prompts are shared and stored via email, especially across personal accounts, they further complicate the organization's e-discovery and data protection obligations, as both the AI platform and the email providers become repositories of sensitive information. Instead, boards should work with counsel to establish AI policies that align with privilege and governance requirements and ensure that any AI use occurs within controlled, enterprise-grade environments rather than ad hoc consumer tools.

Strategic Implications and Recommendations

The evidence from governance codes, legal guidance, technology providers, and Mailbird's own security analysis converges on the conclusion that email, while indispensable as a general communication tool, is ill-suited to serve as the primary channel for board reporting and written governance. Security vulnerabilities, metadata exposure, discoverability, and authentication challenges undermine the confidentiality and integrity of board communications conducted purely via email, especially when personal accounts and attachments are involved.

Legal frameworks for written resolutions and minutes, such as those in the UK and Ireland, recognize that electronic circulation and signatures can facilitate governance, but they still require formal documentation and retention practices that go beyond informal email exchanges. Board portals and governance-specific collaboration tools offer more secure and structured alternatives, providing centralized, role-based access to materials, audit trails, and integrated approval workflows that meet the demands of regulators, investors, and litigants for robust records.

Law firm guidance underscores the importance of confining substantive board communications to secure portals or company-hosted email accounts and avoiding personal email, texts, and consumer AI tools for legally sensitive matters. Within this ecosystem, Mailbird stands out as a powerful email client that can enhance productivity, support shared inbox architectures, and reduce the cognitive load of managing multiple accounts, but it does not alter the fundamental governance limitations of email as a medium.

Boards and organizations that wish to harness Mailbird effectively should therefore adopt a layered strategy: using board portals and governance systems as the primary repositories for formal records; configuring corporate email accounts and shared mailboxes with strong security controls; deploying Mailbird to manage these accounts efficiently; and establishing clear policies that limit the use of email for highly sensitive or formal board activities. In doing so, they can balance the convenience and familiarity of email with the demands of modern governance, leveraging tools like Mailbird as part of a broader, governance-aware digital communication architecture rather than relying on email alone to carry the weight of board reporting and written governance.

Frequently Asked Questions

Can board resolutions be legally passed by email?

Based on UK and Irish legal frameworks, board resolutions can be passed electronically, but specific requirements must be met. A resolution in writing, signed by all directors entitled to receive notice of a board meeting, is as valid as a resolution passed at a duly convened meeting, provided the company's articles of association do not preclude such procedures. However, safeguards are essential: each director's agreement should come from a nominated email address, and the company secretary should confirm receipt of consents from all eligible directors. The signed resolution document—not the email chain itself—must be retained as the official company record. For significant or contentious decisions, holding a formal meeting remains preferable to ensure proper deliberation and create a clear governance record.

What are the main security risks of using email for board communications?

Email-based board communications face multiple security vulnerabilities, including spear phishing attacks targeting directors, business email compromise, ransomware, and unauthorized access to sensitive materials. Even with TLS encryption, emails are only protected during transit between servers and remain vulnerable once stored on servers or local devices. Email metadata—sender, recipient, timestamps, subject lines—typically remains unencrypted and can reveal sensitive patterns about board activities. Personal email accounts used for board communications are particularly risky, as they sit on third-party platforms where confidential information can be forwarded inadvertently and where account compromises can expose large volumes of correspondence. These risks make dedicated board portals with enterprise-grade security and audit trails a more appropriate choice for sensitive governance communications.

How does Mailbird improve email management for directors serving on multiple boards?

Mailbird consolidates multiple email accounts into a single, unified interface, allowing directors to manage corporate accounts from different boards alongside personal email without constantly switching between applications. This unified inbox approach reduces cognitive load and helps ensure that important governance notifications are not overlooked amid routine messages. For governance teams, Mailbird supports shared mailbox architectures where multiple team members can access common addresses using individual credentials, creating audit trails that satisfy regulatory requirements. However, Mailbird's value is as an email management tool—it cannot transform email into a secure governance platform or eliminate the inherent vulnerabilities of email as a protocol. Directors should use Mailbird to efficiently manage notifications and links to board portals, while conducting substantive governance activities within dedicated, secure governance systems.

Are AI-generated summaries of board materials discoverable in litigation?

Yes—both AI prompts and AI-generated outputs may be discoverable in litigation, and using consumer AI platforms to analyze board materials or legal exposure can jeopardize attorney-client privilege. When directors input confidential board reports into consumer AI tools to generate summaries or analyses, they create records that opposing counsel or regulators can seek in discovery, and they may expose sensitive information to third-party platforms whose terms of service allow data reuse. If these AI-generated materials are then shared via email, the discovery and data protection challenges multiply. Boards should establish clear AI policies that prohibit the use of consumer AI tools for analyzing sensitive governance or legal matters and should work with counsel to ensure that any AI use occurs within controlled, enterprise-grade environments that preserve privilege and confidentiality.

What retention requirements apply to board-related emails?

Data privacy regulations such as GDPR treat email as personal and protected information, while laws like the US Federal Rules of Civil Procedure require organizations to keep and store an archive of emails for discovery purposes. This dual status creates tensions: organizations must preserve emails for legal and regulatory reasons while minimizing retention of personal and sensitive data to reduce risk and comply with privacy obligations. In the UK, companies must retain board minutes for at least ten years as part of statutory records, and similar retention periods often apply to written resolutions and formal governance documents. Organizations using email for board communications must implement retention policies that balance these competing demands, ideally by moving formal governance records out of email and into structured governance systems with appropriate retention controls, while applying shorter retention periods to routine email correspondence.