INKY: MX Record Setup

An MX record (Mail Exchange record) is a DNS record that specifies the mail server responsible for receiving email messages on behalf of a domain. It directs email traffic to the correct mail servers, so incoming emails are properly routed.

When using INKY, understanding your MX record is important because INKY processes emails inline after the MX record. INKY needs to know the upstream mail provider (the service behind your MX record) to accurately check mail hops for authentication and threat analysis. You can specify your upstream provider in the INKY Admin Center under Analysis > Upstream Provider. This ensures INKY validates the correct mail server and avoids issues with SPF and threat detection.

If you're using Office 365 as your MX, note that INKY does not require an upstream provider to be selected in that case. For other providers, INKY supports many common upstream mail filters like Mimecast, Proofpoint, Barracuda, and others.

For details on configuring your upstream provider related to your MX record, see the guide on Upstream Provider.

 

To set up MX records for INKY:

To set up MX records for INKY, you do not need to point your MX records to INKY. INKY operates inline behind your existing mail infrastructure (Microsoft 365 or Google Workspace) and is deployed via connectors and mail flow rules, not as a primary MX gateway. Here’s what you need to know:

  • Do not change your MX records to INKY.
  • Your domain’s MX records should continue to point to your actual mail provider:
    • For Microsoft 365: MX should be set to something like yourdomain-com.mail.protection.outlook.com
    • For Google Workspace: MX should be set to Google’s standard MX endpoints
  • INKY is integrated via API and mail flow connectors/routing within your mail platform. This means:
    • No DNS propagation delays
    • No business continuity risk
    • No single point of failure
    • No complex migration or downtime
  • The setup process involves:
    • Adding INKY connector information to Microsoft 365 or configuring routing in Google Admin Console
    • Creating mail flow rules to route email through INKY
    • Creating an INKY-Users security group for phased deployment
    • Verifying connection and enabling Journal Mode
    • Configuring essential allow/block lists and VIP protection

Summary:
INKY does not require MX record changes. Keep your MX records pointed to Microsoft 365 or Google Workspace. Deploy INKY by configuring connectors and mail flow rules within your mail platform. If you are migrating from another gateway (like Proofpoint), update your MX records to point back to your mail provider, not INKY.

 

For integrating INKY with Microsoft 365 and Google Workspace:

 Remember, you do not change your MX records for INKY, setup is done via connectors and mail flow rules.

 

Microsoft 365: INKY MX Record Setup

  1. Log in to Microsoft 365 Admin Center
  2. Create a Mail Flow Connector
    • Navigate to Exchange Admin Center > Mail flow > Connectors.
    • Click + Add a connector.
    • Choose “From: Office 365” and “To: Partner organization.”
    • Name the connector (e.g., “INKY Outbound”).
    • Set up the connector to route mail through INKY’s smart host (provided in your INKY deployment documentation).
    • Complete the wizard, ensuring only the desired domains or groups are routed through INKY.
  3. Create a Mail Flow Rule (Transport Rule)
    • In Exchange Admin Center > Mail flow > Rules, click + Add a rule.
    • Name the rule (e.g., “Route mail through INKY”).
    • Set conditions (e.g., for specific users, groups, or domains).
    • Set the action to “Redirect the message to the following connector” and select the INKY connector you created.
    • Save and enable the rule.
  4. Test the Configuration
    • Send test emails from affected users and verify that INKY banners and analysis are present.
    • Check for mail flow and authentication (SPF/DKIM/DMARC) continuity.
  5. Phased Rollout (Optional)
    • Use a security group (e.g., “INKY-Users”) to control which users’ mail is routed through INKY.
    • Update the mail flow rule to apply only to this group for staged deployment.

 

Google Workspace: INKY MX Record Setup

  1. Log in to Google Admin Console
  2. Configure Routing Rule
    • Navigate to Apps > Google Workspace > Gmail > Routing.
    • Click Add another rule.
    • Name the rule (e.g., “Route mail through INKY”).
    • Under Email messages to affect, select “Inbound, Outbound, and Internal.”
    • Under For the above types of messages, do the following, select “Modify message” > “Change route.”
    • Enter the INKY smart host (provided in your INKY deployment documentation).
  3. Set Up User/Group Targeting (Optional)
    • Apply the rule to specific organizational units or groups for phased deployment.
  4. Save and Apply
    • Save the routing rule.
    • Allow time for policy propagation.
  5. Test the Configuration
    • Send test emails and verify INKY banners and analysis.
    • Confirm mail authentication (SPF/DKIM/DMARC) is not disrupted.

 

General Notes:

  • Do not change your MX records; they should remain pointed to Microsoft 365 or Google Workspace.
  • INKY will provide the smart host address and any additional configuration details.
  • Always test with a small group before full deployment.
  • If you are replacing another gateway, update your MX records to point back to Microsoft 365 or Google Workspace—not INKY.

 

The official INKY deployment guides and resources are available at the following links:

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section