Docs / Obsidian Suite / Connect your mail
Domains and routing
Each domain you receive mail for has its own page: Manage > Organizations > your organization > the domain. It controls where clean mail is delivered, whether the domain can send outbound through Obsidian Suite, and shows the exact steps to connect it on your platform.
Your organization page
Manage > Organizations lists your organization with its platform, domains, number of users and connectors. Click it to open the organization page:
- Domains: every domain, where it delivers, and whether inbound and outbound are on. Add domain takes the domain name and, optionally, Deliver to. Left empty, Microsoft 365 and Google Workspace hosts are filled in for you.
- API connectors: see API connectors.
- Settings: Name, Platform (Microsoft 365, Google Workspace, Exchange Server or Other SMTP) and Notes for your team. The platform decides which setup steps and connector are suggested. You can change it later.
- Administrators: the people with the organization administrator role. See Users and roles.
- The Users and Messages buttons at the top open those pages filtered to your organization.
The domain page
The line under the domain name shows its current MX records and whether they already point at Obsidian Suite.
Routing
| Setting | What it does |
|---|---|
| Deliver clean mail to | The server that receives mail after scanning. Microsoft 365: <domain-with-dashes>.mail.protection.outlook.com. Google: aspmx.l.google.com. Exchange or another server: its public name or address. |
| Port | Usually 25. |
| Look up MX records of the delivery host | Off (the default): deliver straight to that host name. On: treat it as a domain and use its MX records, useful when it has several mail hosts. |
| Require TLS to the delivery host | Refuse to deliver unencrypted. Leave it on for Microsoft 365 and Google. |
| Accept inbound mail | Off: Obsidian Suite stops accepting mail for this domain. |
| Allow outbound relay | Lets your mail platform send mail from this domain through Obsidian Suite. See Sending outbound mail. |
| Reject unknown recipients (needs a synced directory) | Refuse mail to addresses that are not synced users or aliases. This stops dictionary attacks and backscatter. Turn it on only after a connector's user sync is complete. |
Save applies the change within seconds. Test delivery host opens a connection to the delivery host and reports whether it answered and whether it offers STARTTLS. Run it after every change.
Set up mail flow
Numbered steps for your organization's platform, with Obsidian Suite's addresses and your domain filled in. They are explained in the platform chapters: Microsoft 365, Google Workspace, Exchange Server.
If you send outbound mail through Obsidian Suite, the card also reminds you to include it in your domain's SPF record. See Sending outbound mail.
Outbound relay key and DKIM signing
See Sending outbound mail and DKIM signing.
Remove domain
Remove domain stops accepting mail for the domain immediately. Its message history stays in Message trace.
Other mail servers
For any other mail server that receives mail over SMTP:
- Set Deliver clean mail to to your mail server's public name or address.
- Allow the Obsidian Suite addresses shown on the domain page to deliver to your mail server.
- Point the MX record at
mx1.obsidiansuite.net. - To send outbound mail through Obsidian Suite as well, see Sending outbound mail.