Layer 1
Domain registrar
Legal and operational control of the domain. Use strong recovery, MFA and named ownership.
Domain email setup
A durable business-email setup separates registrar ownership, DNS control and mailbox hosting. That makes migration possible and reduces the chance that one lost login becomes a company-wide outage.
Layer 1
Legal and operational control of the domain. Use strong recovery, MFA and named ownership.
Layer 2
Controls mail routing and authentication. Document who can change records and how rollback works.
Layer 3
Hosts mailboxes, calendars and related services. It should be replaceable without transferring the domain.
Safe setup order
Add the provider's verification record without changing mail flow.
Users, aliases, shared addresses and catch-all behaviour must exist before MX cutover.
Authorise legitimate senders and maintain one consolidated SPF record.
Publish the provider's signing records and confirm messages are signed.
Begin with visibility, review reports and move enforcement carefully.
Route inbound mail only after addresses and tests are complete.
External inbound, outbound, replies, aliases, forms, invoices and calendar invitations.
Store ownership, provider, records, renewal dates and rollback values outside the mailbox being protected.
Good architecture
Fragile architecture
Provider choice
Focused email, domains, aliases, calendars and contacts.
Privacy-led email and encrypted services.
Email within a browser collaboration suite.
Email within Outlook, Exchange, Office and Teams standardisation.
Final rule
The provider can be bundled with other tools. Ownership, recovery and exit documentation cannot be outsourced.
Primary evidence
Evidence reviewed 20 July 2026. Product details and commercial terms can change; verify final configuration with the provider.