Prepare access and ownership

Have the domain’s DNS administrator and the new mail administrator available. Confirm that the business can recover both accounts without depending on one departing employee. Save an export of the current DNS zone and record the existing mail provider before making changes.

List every address that receives mail, including website forms, invoices and role addresses. For an existing domain, this is a migration rather than a fresh setup; incoming messages must keep reaching a monitored destination during the change.

Create destinations before changing delivery

Create the required users, role mailboxes or aliases at the new provider first. Assign the people allowed to read and send through each role. Enable the available MFA controls and retain recovery material through the business’s approved process.

Use a fictional example: alex@example.com is a person; sales@example.com is a business role. Decide whether sales needs its own history and shared access. Forwarding everything to Alex may be convenient today but complicate tomorrow’s handover.

Apply the provider’s DNS instructions

MX records direct incoming domain mail. Sending authentication uses SPF, DKIM and DMARC. Use the values issued for your own service and domain, rather than copying another business’s example. Preserve unrelated website records.

Make the change during a staffed period. Record the previous values and the intended rollback procedure. DNS caches can retain old values, so one successful test does not demonstrate that every sender has switched.

Test more than a login

Send an external message into each important address, reply, and inspect the identity shown to the recipient. Test a message with a harmless attachment and a website enquiry if the website sends mail. Review authentication results using the provider’s instructions.

  • Named users can sign in with the required security controls.
  • Role addresses receive mail and replies use the intended address.
  • An unauthorized employee cannot open a restricted mailbox.
  • Mobile and desktop clients work, and support contacts are recorded.

Finish with a handover record

Keep the domain owner, provider, administrator, recovery procedure and test results in a secure operational record. Do not put passwords or private keys in a shared setup document. If replacing a service, keep the old data available until the migration checks and retention requirements are satisfied.