WMU Email Rules

Responsible officeInformation Technology
Enforcement officialChief Information Officer

Statement of Rule

Western Michigan University email services are provided for authorized university purposes and must be used in a manner that protects university information, supports legal and regulatory obligations, maintains the security and integrity of university systems, and ensures the reliable delivery of electronic communications. This rule establishes the standards governing the use, management, and administration of university email services and related technologies.

1. Purpose of Rule

Establish consistent requirements for secure, reliable, supportable, and compliant use of University email services.

2. Stakeholders Most Impacted by the Rule

  • Students, faculty, employees, alumni, affiliates, and other authorized users with a university-issued email account
  • University system administrators and business leads that utilize email services for mass or transactional email services.

3. Key Definitions

  • WMU Email Address: The official email address assigned when a user's Bronco NetID is created or used for mail lists and system-generated messages.
  • Bronco NetID: A unique username assigned to university affiliates (person) or a departmental account to authenticate technology services.  
  • Delegated Access: Authorized access granted to another user for email account management.
  • Email Client: A software application or service used to send, receive, read, store, or manage email, calendar and related system data.
  • Sensitive Information: Confidential, regulated, restricted, or otherwise protected information per the University Data Classification Policy
  • Domain (Domain Name): The portion of an email address to the right of the "@" symbol. For example, "wmich.edu".
  • External Sender: An email sending service provider that is not managed by Western Michigan University. 

4. Full Rule Details

4.1 Account Management, Authentication, and Access

  • 4.1.1 Email addresses are assigned at the time of Bronco NetID creation.
  • 4.1.2 Student email addresses are in the format of firstname.middle initial.lastname at wmich.edu.
  • 4.1.3 Faculty and staff email addresses are typically in the format of firstname.lastname at wmich.edu. Middle initials may be used in faculty or staff email addresses when more than one person exists with the same first and last names.
  • 4.1.4 Numbers will be added to any email addresses if more than one first, middle initial, and last name exists.
  • 4.1.5 University business must be conducted through a university-issued email account using approved email clients, applications, protocols, and integrations.
  • 4.1.6 Access to university email systems is restricted to the email clients, and applications that support secure protocols and information protection technologies.  
  • 4.1.7 Third-party email clients and applications will be reviewed for approval if:
  • 4.1.8 The currently supported desktop or web application cannot be accessed on the user’s primary computing device.
  • 4.1.9 The third-party application is required for systematic data integrations with other university-managed or licensed systems or services.
  • 4.1.10 The third-party application provides functionality that is critical to academic or administrative purposes that cannot be performed with the currently supported application or other university-managed system or service.
  • 4.1.11 Personal email accounts must not be used to send, receive, forward, or retain university information. Automatic forwarding to personal accounts is prohibited.
  • 4.1.12 Identity misrepresentation, and concealment of message origin are prohibited.
  • 4.1.13 Delegated mailbox access must be formally authorized by the account owner, limited to business need, follow least-privilege principles, and be removed when no longer required.

4.2 Information Handling and Retention

  • 4.2.1 Users must verify recipients, attachments, and links before sending email.
  • 4.2.2 Sensitive data and information may be transmitted only through approved protections and must not be placed in subject lines.
  • 4.2.3 Messages and attachments must be retained, deleted, preserved, or disclosed in accordance with applicable classification, privacy, records-retention, legal-hold, and regulatory requirements.
  • 4.2.4 Users must not evade retention, auditing, monitoring, discovery, or legal-hold controls.
  • 4.2.5 The University may monitor, filter, preserve, quarantine, inspect, retain, or disclose email as permitted by law and University policy.
  • 4.2.6 Automated sending services must comply with the Mass Email Policy.

4.3 Abuse and Phishing

  • 4.3.1 Phishing, malware, spoofing, and related threats must be reported using official processes and procedures.
  • 4.3.2 Email must not be used to distribute malware, commit fraud, harass others, or violate law or policy.

4.4 External Senders

  • 4.4.1 Messages sent on behalf of the University by external senders must use an authorized university domain, approved by the Office of Information Technology, in the From address and accurately identify the originating department, program, service, or business function.
  • 4.4.2 External senders must support and maintain DomainKeys Identified Mail (DKIM), an email authentication technology that verifies that an email was sent and authorized by the owner of a domain.
  • 4.4.3 External senders must support Sender Policy Framework (SPF), which verifies whether the sending mail server is authorized to originate WMU mail from the email sender's domain
  • 4.4.4 External senders must comply with Domain-based Message Authentication, Reporting, and Conformance (DMARC), an email authentication, policy, and reporting protocol that works with SPF and DKIM to determine the authenticity of an email message.
  • 4.4.5 Email sent to university email addresses from external senders that do not comply with these rules may not be delivered or may be detected as spam.
  • 4.4.6 External senders that do not comply with these rules or are not properly configured may be restricted, blocked, or removed from service by the Office of Information Technology. 

5. Accountability 

  • 5.1 Users are responsible for protecting credentials and using email in accordance with these rules and university policies.
  • 5.2 Managers and business owners approve access based on business need.
  • 5.3 The Office of Information Technology maintains University email system configurations, security and standards.
  • 5.4 The Office of Legal Affairs, Risk and Compliance defines records management, legal, retention and regulatory obligations.
  • 5.5 Technology vendors and information technology system administrators are responsible for maintaining secure and supported systems. 

7. Related Procedures and Guidelines

8. Related Policies:

History

Effective date of current versionSeptember 2026
Date first adoptedApril 2019
Proposed date of next review2026