
Cloud & Infrastructure / Deep Dive
Register a domain, set up branded mailboxes, configure SPF, DKIM, and DMARC — and ship email that lands in the inbox, not the spam folder.
Same email, professionally delivered
Email is still the default channel for sales, contracts, support, and operations — and the easiest way to lose deals is to land in the recipient's spam folder. Mailbox providers (Gmail, Outlook, Apple Mail, every corporate filter) make that decision before the human reads the message, based on three pieces of evidence: the domain's authentication records, the sending IP's reputation, and the message's structural quality. Get those right and a small business sending from its own domain is treated the same as a Fortune 500. Get them wrong and even legitimate one-to-one email gets quarantined. This guide covers the full setup — registering the right domain, choosing the mailbox host, configuring SPF, DKIM, and DMARC, and tightening the things that actually move the deliverability needle.
Authentication baseline
SPF + DKIM + DMARC
Branded sender
you@yourcompany.com
Mailbox options
Workspace, 365, self-hosted
Domain registration done right
The domain is the foundation — it shows up on every business card, every contract, every email. The setup is small but durable: register the right TLD, lock the domain so it cannot be transferred without confirmation, enable WHOIS privacy, and configure registrar-level DNS that you actually understand. We also check for typo-domains and lookalike registrations that competitors or scammers might exploit.
- TLD selection (.com / regional / industry-specific)
- Multi-year registration with auto-renew protection
- Registrar lock and WHOIS privacy enabled
- DNSSEC where supported
- Defensive registration of common typos when relevant
Mailbox host selection
There is no single right answer for the mailbox host — the right pick depends on team size, existing tooling, compliance requirements, and budget. We map the trade-offs and pick once, consciously, instead of drifting into whatever the previous IT person installed.
- Google Workspace — best for collaboration-heavy teams
- Microsoft 365 — best when Office and Teams are already core
- Zoho / Fastmail — strong value at small team sizes
- Self-hosted (Mailcow, Mail-in-a-Box) — full ownership
- Hybrid setups for distinct departments or brands

Why SPF, DKIM, and DMARC are non-negotiable
These three records tell receiving mail servers three things: SPF declares which servers are allowed to send email for your domain, DKIM cryptographically signs every outgoing message so a recipient can verify it really came from your infrastructure, and DMARC tells receivers what to do when a message fails the first two checks — and reports back so you can see who is trying to spoof you. Major mailbox providers now require all three for bulk sending, and increasingly for transactional and one-to-one mail. A correctly configured setup also protects you from phishing — without DMARC enforcement, anyone can send mail that appears to come from your domain, and your customers' filters might not catch it. The configuration is a one-time DNS task with one ongoing piece (the DMARC report review) and it dramatically changes how reliably your email is delivered.


What changes after the setup
The most visible change is that customers stop saying 'your email went to spam'. Behind the scenes, four things shift. Outbound deliverability climbs because every message is signed and authenticated. Spoofing attempts get blocked because DMARC enforcement tells the world's receivers to reject mail that isn't really from your infrastructure. The DMARC report stream gives you visibility into who is trying to impersonate the domain — useful for incident response and for measuring how well the protection is working. And mailbox sprawl gets cleaned up: aliases, distribution groups, and shared inboxes are organised so the right person sees the right mail and nobody is logged into seven different mailboxes at once.
Already on a domain but emails go to spam?
Most deliverability problems trace back to broken or missing DMARC, a soft-fail SPF, or a long-forgotten third-party sender. Send us the domain — we will run the diagnostics and quote a fix.
Audit my email deliverabilitySPF + DKIM + DMARC
Authentication
Workspace / 365 / Self-hosted
Mailbox hosts
Inbox > 95%
Deliverability target
FAQ
Frequently asked questions
Answers built for decision-makers who need clarity before committing.
Yes. Most modern mailbox hosts let you add a custom domain to an existing account, route inbound mail through their filter, and rewrite outbound mail to send from your domain. The migration usually involves an MX record change, a DKIM record per sending platform, and a few hours of mail-in-flight handling. There is no need to create new mailboxes from scratch unless you want to.
What is DMARC, and do I really need it?
DMARC ties together SPF and DKIM by telling receivers what to do when a message fails authentication. Without DMARC, anyone can send mail that claims to be from your domain and the receiver has no canonical instruction on how to handle it. With DMARC at enforcement, spoofed mail gets rejected and you get aggregated reports of every attempt. Major receivers now require it for bulk senders, and increasingly weight it for normal business mail. So yes — at this point it is non-negotiable.
Do I have to host my own mail server?
No. For most businesses, a managed host (Google Workspace, Microsoft 365, Fastmail, Zoho) is the right answer — the deliverability, the spam filtering, and the calendar/file integrations are part of the package. Self-hosting makes sense in three cases: regulatory requirements, very high volume where the per-mailbox price stops working, or a deliberate full-stack-ownership policy. We deploy both, and we tell you honestly which one fits.
How long does the full setup take?
From a fresh domain, a typical small-team setup takes 1–3 business days: registration and DNS configuration on day one, mailbox creation and DKIM signing on day two, DMARC moved to enforcement after a one-week reporting window. Migrations from existing setups take longer because of the in-flight mail handling, usually 1–2 weeks end-to-end with no user-visible downtime.
What about email signatures and aliases?
Both are part of the setup. Branded HTML signatures are deployed centrally so every outbound message carries the same identity. Aliases (sales@, support@, hello@) are configured to land in the right inbox or shared mailbox. For larger teams, distribution groups and shared inboxes are organised so the right person handles the right inbound message, instead of one mailbox accumulating thousands of unrelated threads.
How do I know my deliverability is actually improving?
Three signals: the DMARC aggregate reports show authentication pass rates climbing toward 100%, third-party deliverability tools (GlockApps, Mail-tester) score the domain in the inbox-grade range, and seed-list testing across major mailbox providers confirms the mail lands in the primary inbox. We deliver a baseline measurement before the work and a follow-up two to four weeks after, so the change is visible in numbers, not anecdotes.
Land in the inbox. Every time.
Tell us the domain (or what you want to register) and the team size — we will deliver registration, mailbox setup, full authentication, and a deliverability report you can verify.
Set up branded emailContinue exploring
Each guide stands alone, but the full picture is built from all four. Pair this with the related deep dives or jump back to the Cloud Hosting & Infrastructure pillar.
Self-hosted business tools on VPS
If you choose a self-hosted mailbox, it lives next to the rest of the self-hosted stack.
Read this guide →Secure remote access without a static IP
Webmail and admin consoles can be published through tunnels for an extra access layer.
Read this guide →Disaster recovery & backup solutions
Mailboxes are part of the backup plan — accidental deletion and account compromise both recover from snapshots.
Read this guide →
