Setup Guides

Provider-Specific Email Setup Guides

Documentation that starts where the official docs stop: each guide walks the exact setup for one provider, then covers the failures we actually find in audits - the forgotten toggle, the truncated record, the default signature that never aligns. Every guide ends with a way to verify the fix on a real message.

Microsoft 365 SPFOne record, the right include, and the 10-lookup trapThe v=spf1 include:spf.protection.outlook.com record, how to add third-party senders without blowing the 10-lookup limit, when to switch to -all, and the five failures we find.Read the guide →Microsoft 365 DKIMThe selector1/selector2 CNAMEs everyone forgetsWhy the tenant-default onmicrosoft.com signature never aligns, the 5-step Defender walkthrough with exact CNAME shapes, and the six failures that break it.Read the guide →Microsoft 365 DMARCThe monitor-then-enforce path to p=rejectWhy the onmicrosoft.com default makes alignment the real work, the exact _dmarc record, the safe path from p=none to p=reject, and the connector/relay traps.Read the guide →Google Workspace SPFinclude:_spf.google.com and the 10-lookup trapThe v=spf1 include:_spf.google.com record (which alone spends four of your ten lookups), adding senders safely, ~all vs -all, and the five failures we find.Read the guide →Google Workspace DKIMThe google._domainkey record and the gappssmtp trapGenerate the key, survive your DNS host's TXT limits, remember Start authentication - and the six failures that leave Workspace mail signing as gappssmtp.com.Read the guide →Google Workspace DMARCgappssmtp alignment and the path to p=rejectWhy the gappssmtp default makes alignment the real work, the _dmarc record, the safe path to p=reject, and the Workspace traps (Groups forwarding, relay).Read the guide →Zoho Mail SPFOne record, the right include and the 10-lookup trapThe v=spf1 include:zohomail.com record, the Admin Console verification, and the five failures that break Zoho SPF - including the include:zoho.com permerror many guides still teach.Read the guide →Zoho Mail DKIMThe selector, the key and how to verify itEnable DKIM in the Admin Console, publish the zoho._domainkey TXT record and verify it - plus the failures we find: split keys, CNAME instead of TXT, wrong host, unverified selectors.Read the guide →Zoho Mail DMARCMonitor first, then enforce to p=rejectThe _dmarc TXT record, a safe rollout from p=none to p=reject, and reading the reports with Postbox DMARC Monitor so you enforce only once every legitimate sender aligns.Read the guide →SendGrid AuthenticationDomain Authentication: the CNAMEs for SPF, DKIM and DMARCThe three CNAME records SendGrid generates, why they keep SPF off your root domain, the s1/s2 DKIM selectors and DMARC alignment, link branding, and the failures we find (verifying too early, proxied CNAMEs, single-sender-only).Read the guide →Amazon SES AuthenticationEasy DKIM, a custom MAIL FROM for SPF, and DMARCThe three Easy DKIM CNAMEs, the custom MAIL FROM (MX + SPF) that aligns SPF, why SES never creates your DMARC record, leaving the sandbox, and the failures we find (SPF unaligned by default, wrong-region MAIL FROM MX, partial DKIM).Read the guide →DMARC EnforcementFrom p=none to p=reject, safelyThe provider-agnostic playbook: what alignment means, every DMARC tag explained, and the monitor-then-enforce path that gets you to p=reject without quarantining your own mail.Read the guide →BIMIYour logo in the inbox, and when you need a VMC or CMCPublish BIMI on top of DMARC enforcement - the SVG Tiny 1.2 P/S logo, the default._bimi record, and the VMC-vs-CMC decision: what shows in Gmail, Yahoo and Apple, and the blue verified check.Read the guide →
More on the wayExchange Online sending limits and the restricted-entities trap, and more provider guides are queued. Meanwhile, test any setup with Postbox Mailtester.
Chat with us!