Docs / Obsidian Suite / Connect your mail
Sending outbound mail
You can route the mail your organization sends through Obsidian Suite as well. Outbound mail is checked for viruses and spam before it leaves, so a compromised account cannot get your domain blocklisted. Checks that only make sense for incoming mail, such as impersonation and AI review, are skipped.
What needs to be in place
- Allow outbound relay is on for the domain (domain page, Routing).
- Obsidian Suite must know your sending servers. The list of servers allowed to relay is a platform setting that Larström Technologies manages: contact us with your platform, or with your mail server's public IP address, and we add it.
- For Microsoft 365 and Google Workspace, set an outbound relay key (below).
Microsoft 365
- Exchange admin center > Mail flow > Connectors: add a connector from Office 365 to Partner organization, with smart host
mx1.obsidiansuite.netand TLS required. - Add a transport rule that sets the message header
X-Obsidian-Relay-Keyto your domain's relay key on mail routed through that connector.
Google Workspace
- Google Admin console > Gmail > Routing > Outbound gateway:
mx1.obsidiansuite.net. - Add a routing rule that adds the custom header
X-Obsidian-Relay-Keywith your domain's relay key.
Exchange Server
Point the Send connector at the smart host mx1.obsidiansuite.net, and ask us to allow your Exchange server's public IP address. Microsoft 365 and Google sign their own mail; for Exchange, set up DKIM signing too.
Outbound relay key
Microsoft 365 and Google send every customer's mail from the same IP ranges. Allowing those ranges alone would let any tenant on the platform send "as" your domain through Obsidian Suite. The relay key closes that gap:
- On the domain page, under Outbound relay key, click Generate key, then Copy.
- On your platform, make the outbound rule add the header
X-Obsidian-Relay-Key: <key>to mail routed to Obsidian Suite (steps above). - From then on, mail from this domain without the correct header is refused with "Relaying denied". The header is removed before the message is delivered, so the key never leaves.
Rotate key replaces it. Outbound mail fails until the platform rule has the new key, so change both together. Remove drops the requirement; the card then says that any relay client may send as your domain.
DKIM signing
Microsoft 365 and Google sign their own mail, so this is for Exchange and other mail servers that relay through Obsidian Suite.
- On the domain page, under DKIM signing (outbound), enter a Selector (default
obsidian) and click Generate key. The key is 2048-bit RSA; the private key is stored encrypted. - Publish the TXT record shown: Name
<selector>._domainkey.<your-domain>, Value copied with Copy value. - From then on, outbound mail from the domain relayed through Obsidian Suite is signed.
Regenerate creates a new key. Publish the new DNS record first, or signatures fail to verify.
SPF
If Obsidian Suite relays your outbound mail, your domain's SPF record must allow it to send for you, alongside your platform. The domain page shows the pattern: v=spf1 ip4:<Obsidian Suite address> include:... -all. Ask us for the address to use.
"Relaying denied"
- Allow outbound relay is off for the domain, or the sending server is not on the list of allowed relay clients: contact us.
- The domain has a relay key and the message did not carry the correct
X-Obsidian-Relay-Keyheader: check that your platform rule has the current key.