Looking for Mobile App directory email settings? This guide controls email visibility on your school website's public staff directory (/apps/staff/). To manage email and phone visibility in your mobile app, see Directory: Managing Contact Email & Phone Visibility (Mobile App).
Important Security Default: The staff directory email contact feature is set to off by default for all sites to protect school personnel from spam robots and phishing harvesting. When enabling email contact, Form-based email is always the strongly recommended route so actual staff inboxes are never publicly exposed on the web.
Overview
Understanding website directory email settings
This guide explains how to manage email contact options in your website Staff Directory (/apps/staff/). These settings govern whether website visitors can view staff email addresses directly or contact staff through a protected web contact form.
Accessing directory email settings
Navigate to Staff Directory in your CMS admin panel.
Click on Directory Options.
Scroll down to the Staff Info section.
Email display options
Option 1: Display "Send Email" link (Recommended)
Form-based emailing is always the recommended route for school websites.
Keeps staff addresses private: The staff member's actual email address is completely hidden from public website visitors and automated web scrapers.
Displays a "Send Email" link: Visitors click a link that opens a secure web contact form.
Direct delivery: Messages submitted through the form are delivered directly to the staff member's official inbox.
Direct reply: When staff reply from their email client, their response goes straight to the sender's email address.
Option 2: Display actual email address
Displaying plain-text email addresses publicly is not recommended because it leaves staff vulnerable to spam harvesting, spoofing, and phishing campaigns.
Shows the raw email address on the public staff directory page.
Clicking the link triggers the visitor's default email program (such as Outlook, Apple Mail, or Gmail).
Turning on Identity Verification for contact forms
Enforcing authenticated sender verification
To maximize security and eliminate anonymous spam sent to your staff, enable Contact Form Authentication. When turned on, any visitor wishing to send an email through a staff directory contact form or site contact form must authenticate their identity using Google, Microsoft, Facebook, or Yahoo before their message can be submitted.
How to turn on Contact Form Authentication:
In your CMS admin panel, navigate to Site Management > Settings (or open the menu and select Settings).
In the Settings menu tabs, click Contact.
Scroll down to the Security for All Contact Forms section at the bottom of the page.
Check the box for Contact Form Authentication: "Require website visitors to log into Google, Microsoft, Facebook or Yahoo to authenticate their identity before sending email through any contact form."
Click Save.
đ Identity Verification Benefit: Requiring visitors to log in via Google, Microsoft, Facebook, or Yahoo ensures that every submitted message includes an authenticated sender identity, deterring harassment and anonymous bot spam while keeping your staff protected.
Individual staff privacy settings
Suppressing email contact for a single user
If an individual staff member requests not to have an email contact link in the directory (even when directory email contact is globally enabled):
Navigate to User Management in your CMS dashboard.
Click the staff member's name to open their user profile.
Check the box labeled "Do not display an email link for this user" located directly beneath their email address field.
Click Save.
Disabling email contact completely
Removing all email links from the directory
To remove email contact options entirely across the entire website staff directory:
Uncheck the Email checkbox in Directory Options > Staff Info.
Click Save. No email addresses or contact form links will display anywhere on
/apps/staff/.
Related articles
More directory resources





