Agency & Multi-domain

Agency email routing runbook: DNS, aliases, SMTP and testing

Per-client NS, MX, map, SMTP, probe. Offboard is revoke, not courtesy leftover.

MailerZ editorial · Secuno LLC17 min read

An agency email routing runbook is a repeatable order: confirm NS, publish exclusive MailerZ MX, map named aliases, test from a third mailbox, then add paid SMTP if the retainer includes send-as. It is not a vibe and not a dual-publish QA week. Free is one domain. Fleet plans exist. Copy dashboard SMTP. Do not invent ports. Leftover MX is a hard stop. Write the runbook so a junior can run it on Sunday without a call.

Name the third mailbox like a labeled tool. Name one exclusive MX owner. Name the cancel owner before the window. If SMTP is not in the SOW, write inbound-only so a Free 550 is not a fire. Reviewer reads listings. Cutter pastes. Design knows a site save can republish MX. Inverse offboard is the same runbook backwards and is practiced on a lab when the junior joins. Dual MX is not QA. Folklore ports are not chapter 4. Shared catch-all is not a shortcut. Confirm live pricing before you quote a fleet. Start free on a lab so the first Sunday is not a hospital client.

Agency email routing runbook covering DNS, aliases, SMTP, and tests
Four chapters, one exclusive hop. No dual MX in the test chapter.

Quick answer for agency email routing runbook

Chapter 1: NS and exclusive MX. Chapter 2: named aliases and HOLD. Chapter 3: tests from a third mailbox. Chapter 4: paid SMTP if sold. Delete leftovers in chapter 1, not in chapter 4.

The runbook is per zone. A roster is many runbooks with the same shape.

If SMTP is not sold, chapter 4 says inbound only so nobody knows 550 as a severity-one.

IETF RFC 1035 — Domain names and IETF RFC 5321 — Simple Mail Transfer Protocol. Paths: features, migration planner, delivery recovery.

User problem and decision criteria

Agencies fail when tests are dual MX and SMTP is folklore ports. The runbook exists to make those fails impossible to do politely.

Decision criteria: who can change TXT, who owns the old seat cancel, whether send-as is in the SOW, whether HOLD is written, whether the junior can reach the dashboard.

If the client needs a badge, the runbook starts with no. Do not discover that in chapter 4.

If two people 'handle email,' the runbook names one exclusive owner.

If the designer can publish a site that rewrites MX, the runbook includes morning re-query.

If the plan cannot count the zones, the runbook stops at pricing.

How the four chapters move mail

DNS makes the world send to MailerZ only. Aliases decide which human reads. Tests prove both. SMTP lets WordPress or Gmail send-as if paid.

SRS on inbound envelope. Header From intact. Unauthorized SMTP 550 5.7.1.

A test that uses the client's own Gmail as sender is not a test. The runbook forbids it.

A test that adds the old MX back is leftover MX. The runbook forbids it.

Rollback is an exclusive old screenshot, not both names.

Runbook chapters: DNS, aliases, tests, SMTP
Tests never add the old MX back.

The runbook order

  1. Confirm registrar and DNS host logins. Confirm NS.
  2. Create or open the MailerZ workspace. Confirm plan caps.
  3. Copy MX and TXT from the dashboard. Publish exclusive. Delete leftovers.
  4. Query two public resolvers. Stop if two brands remain.
  5. Create named aliases. HOLD unknown unless the SOW says otherwise.
  6. Lower TTL only if you still control the old MX before a planned window.
  7. Probe each public alias from a third mailbox. File IDs.
  8. Morning re-query. Disable builder email products.
  9. If SMTP is in scope: upgrade, copy dashboard, prove unique send, fail closed.
  10. Write close date for the old seat. Inverse offboard when they leave you.

Failure modes and proof

Junior dual-published for QA. Donor hit the old host. Proof: two brands in resolvers.

SMTP invented 587. 550 or timeout. Proof: dashboard disagreement.

Shared catch-all into agency Slack. Proof: the wrong brand in the channel.

Self-send green, customer red. Proof: empty hop for the customer probe.

Builder republish Monday. Proof: morning listing.

Proof the runbook ran: resolvers, IDs, HOLD policy, SMTP transcript or 'not in scope,' cancel owner.

MailerZ workflow and product boundary

The runbook uses MailerZ as the hop. Visibility is hop history, not an inbox SLA.

Free cannot cover a fleet. Agency is capacity. Confirm /pricing.

Not IMAP. Not SOC 2. Not an open relay.

Delivery-recovery is for hops MailerZ saw. Empty hop means leftovers or wrong NS.

Support wants IDs and listings. Support does not want a Slack mood.

White-label does not remove leftover physics.

Cost and alternatives

Quote the hop from MailerZ pricing, then quote the suite you are replacing, then quote labor. Free is one domain, ten aliases, one seat, a 14-day store, unknown mail hold or reject, and send-as, SMTP, and API off. It is a lab, not a client fleet. Solo is $40 per year: five domains, 25 aliases, 2,500 outgoing, 20 per hour. Starter is $8 monthly or $80 yearly: eight domains, 50 aliases, 5,000 outgoing. Business is $19 or $190: 25 domains, 200 aliases, 12,000 outgoing. Agency is $39 or $390: 100 domains, 500 aliases, 20,000 outgoing. Unlimited is $99 monthly or $990 yearly, with a 180-day store and 100,000 outgoing. Every paid plan includes unknown-mail Forward, send-as, SMTP, and API. Confirm those numbers on the pricing page before a retainer quote. They are capacity, not an inbox SLA.

A runbook on a suite seat per freelancer is a different invoice. Write both numbers so the client can choose Calendar and Drive instead of a hop. No runbook plus leftover MX is the most expensive option because Sunday labor never appears on a price card.

Cloudflare Email Routing without hop IDs makes chapter 3 thin. Score that honestly. Self-hosted mail makes the runbook a second company. Only sell that if you already operate it. Paying for Agency and still dual-publishing wastes the card. Time to write the runbook once is cheaper than ten Sunday calls.

Worked scenarios

Sunday cut, junior alone: they follow the ten steps, file IDs, stop on two brands. That is the runbook working.

Launch week pressure to dual-publish: they show the signed coin-flip clause or they refuse. That is the runbook working.

SMTP in a brochure form: chapter 4 after inbound. Reverse order is how 550 becomes a war.

Client leaves: inverse runbook. New exclusive owner first.

Two brands, one registrar gift MX: chapter 1 deletes both gifts. Chapter 3 proves both zones.

Practice and anti-patterns

Practice: one exclusive owner. Anti-pattern: two agencies.

Practice: third mailbox. Anti-pattern: founder self-send.

Practice: dashboard SMTP. Anti-pattern: remembered ports.

Practice: morning re-query. Anti-pattern: 11 p.m. close.

Practice: named aliases. Anti-pattern: agency catch-all.

Practice: inverse offboard. Anti-pattern: cancel while published.

The runbook is the product you sell even when the hop is MailerZ.

Operator closeout

All four chapters checked or marked not in scope. Packet in the ticket. Deputy named. Review date set.

Old-seat cancel owner written before the window.

Plan cap versus roster written.

Junior completed a lab loop this quarter.

Edge cases

NS at a dead reseller. Chapter 1 stops. Do not edit a ghost zone.

Client on Microsoft 365 for Teams who still wants forwarding. Suite can stay. MX must be exclusive if MailerZ should receive.

IDN or punycode. Copy dashboard values. Do not hand-roll.

A zone that only sends. Chapter 3 still needs a probe if anything is public inbound.

A security questionnaire mid-runbook. Answer no on badges. Do not invent.

Staff change mid-window. Rotate registrar and MailerZ. Continue the same exclusive set.

Field notes

The runbook that lives only in your head fails when you fly.

Clients remember brand names. The sheet needs a brand column.

Website builders are chapter 1's enemy. Treat them as such.

SMTP folklore is chapter 4's enemy. Dashboard only.

Dual MX is chapter 3's enemy. Refuse it.

If you cannot refuse, write the coin flip and make them sign.

Start free on a lab so the junior's first runbook is not a hospital.

Handoff memo

Runbook URL, sheet, workspace, plan, per-zone NS, last IDs, leftover products, SMTP scope, deputies, inverse rule, lab loop date.

Forbidden list in bold: dual MX, invented ports, self-send gate, shared catch-all, badge fiction.

Acceptance criteria

A junior completed the lab loop. A production zone has exclusive listings and probe IDs. SMTP either proved or marked out of scope.

No two-brand resolvers. Morning re-query exists. Cancel owner named.

Retainer points at this runbook.

Operations review of the runbook

A junior should complete the lab loop this month. An agency email routing runbook that only the founder can run is not a runbook.

Sample three production zones for exclusive listings and probe IDs. Missing IDs are missing chapter 3.

Confirm SMTP chapter is either proved or marked out of scope. 550 on Free is a scope error.

Confirm morning re-query happened after the last website launch.

Confirm no dual MX appeared in 'QA.' If it did, write the coin flip or delete the leftover.

Confirm shared catch-all is still forbidden. Slack should not see every brand typo.

Confirm inverse offboard dates for anyone leaving.

Confirm dashboard SMTP still matches any WordPress you sold. Folklore ports are regressions.

Confirm plan caps versus roster. Confirm /pricing.

Confirm the retainer still points at this runbook, not a personal Notion.

Quarterly review

Rewrite the four chapters from memory, then diff the sheet. Memory loses.

Lab loop dated. Deputy named. Badge answers still no.

Builder products sampled for republish.

Send-as scope versus live From headers.

Self-send still forbidden as a gate.

NS-to-panel mismatches hunted. Ghost zones are chapter 1 fails.

Write the review date next to domain renewals.

Closing notes

Four chapters, exclusive MX in each, third-mailbox tests, dashboard SMTP, morning re-query. That is the runbook.

Refuse dual MX. Refuse invented ports. Refuse a fleet on Free.

Start free on a lab. Paste the order into the retainer. Then keep it boring.

Field depth on Sunday cuts

Sunday cuts fail when chapter 1 is skipped. NS mismatch plus pretty MailerZ rows is a ghost. The agency email routing runbook starts at public NS, not at the dashboard.

Chapter 3 fails when the junior uses the founder's Gmail. Write the third-mailbox address in the runbook as a named tool, like a screwdriver.

Chapter 4 fails when SMTP is sold on Free. Quote Solo or above in the SOW or mark inbound only.

Website launches are unscheduled chapter 1 tests. Put re-query on the launch checklist the design team already uses.

White-label does not remove hop physics. Clients still lose mail to leftovers if leftovers exist.

A coin-flip clause you never intend to honor should not be in the SOW. Refuse dual MX or lose the client.

Inverse offboard is the runbook run backwards. Practice it on a lab when a junior joins, not when a client is angry.

Probe IDs named by zone and date beat a Slack thumbs-up.

People and deputies

Junior, reviewer, TXT approver, old-seat cancel owner, SMTP owner. Five roles, sometimes two humans. Write the names.

The reviewer does not perform the cut. They read listings and IDs. That split catches dual MX.

Design must know they can republish MX. Show them once.

The client contact who can approve TXT must be reachable in the window. Otherwise there is no window.

On-call reads this runbook, not your memory, if you fly.

Proof packet

NS, exclusive listings, alias map, probe IDs, HOLD, morning re-query, SMTP transcript or not-in-scope, cancel owner, lab loop date.

Retainer points here. Forbidden list attached.

Junior completed lab this quarter.

Appendix

Appendix: chapter 1 is public NS, then exclusive MX, then leftover delete. Skipping NS is a ghost zone.

Appendix: chapter 2 is named aliases and written HOLD. Shared agency catch-all is forbidden by name.

Appendix: chapter 3 is two resolvers and a named third mailbox. Founder self-send is forbidden by name.

Appendix: chapter 4 is paid dashboard SMTP or inbound-only in the SOW. Free 550 is a scope error.

Appendix: morning re-query belongs on the design launch checklist, not only the email ticket.

Appendix: inverse offboard is the runbook backwards. Practice on a lab.

Appendix: white-label does not suspend leftover physics.

Appendix: a coin-flip clause you will not honor should not be in the SOW.

Appendix: probe IDs named by zone and date beat emoji.

Appendix: the reviewer reads listings and does not perform the cut.

Appendix: TXT approver must be reachable in the window or there is no window.

Appendix: on-call reads this page if you fly.

Appendix: folklore ports are regressions. Dashboard only.

Appendix: builder republish is an expected enemy. Disable the product.

Appendix: plan caps versus roster before you quote.

Appendix: junior lab loop this month or the runbook is fiction.

Final pass

Final pass: lab loop dated, production sample exclusive with IDs, SMTP proved or out of scope, morning re-query exists, cancel owner named.

No two-brand resolvers. No shared catch-all. Retainer points here.

Start free on a lab. Keep Sunday boring.

Extended operator narrative

Write the runbook where the retainer already lives so a junior can open it on Sunday without your Notion. Chapter 1: public NS, exclusive MailerZ MX, leftover delete, two resolvers. Chapter 2: named aliases, HOLD written, no shared agency catch-all. Chapter 3: named third mailbox, unique probes, IDs filed by zone and date, morning re-query after builders. Chapter 4: paid dashboard SMTP if sold, else inbound-only in the SOW. Free 550 is a scope error, not a night emergency. Folklore ports are regressions.

Refuse dual MX in chapter 3. QA that adds the old host is leftover MX with a test plan. If a client demands both names, show the coin-flip clause or refuse. Do not put a clause in the SOW you will not honor. Rollback, if needed, is exclusive restore from a snapshot, not both names. That process lives in the reversible-migration article. This runbook assumes you will not 'test' by splitting the world.

People: junior cuts, reviewer reads listings and IDs, TXT approver is reachable, old-seat cancel owner is named before the window, SMTP owner exists only if chapter 4 is in scope. Design knows website saves can republish MX. On-call reads this page if you fly. White-label does not suspend physics. Inverse offboard is the runbook backwards and is practiced on a lab when a junior joins, not when a client is angry.

Sample three production zones monthly for exclusive listings and probe IDs. Missing IDs mean chapter 3 did not happen. Confirm plan caps versus roster. Confirm /pricing. Confirm the third-mailbox address is written like a tool name. Confirm self-send is still forbidden as a gate. Confirm no Slack catch-all. Confirm builder products sampled after launches. Write the review next to domain renewals.

Start free on a lab so the first runbook is not a hospital. Paste the four chapters into the retainer. Keep Sunday boring. MailerZ shows hops it accepted. It does not merge leftover Google. It does not provide an inbox SLA or a badge. The runbook is the product you sell even when the hop is ours.

More operator notes

Give the third mailbox a name in the runbook, like a labeled screwdriver, so the junior does not use the founder's Gmail. An agency email routing runbook that allows self-send as a gate will ship green tickets and red customers. Two resolvers and filed IDs are the rest of chapter 3. Morning re-query after launches is how builders get caught.

Chapter 4 exists only if the SOW sold send-as and the plan is paid. Otherwise write inbound-only so 550 is not a severity-one. Dashboard values only. One credential per site if WordPress is in scope. Fail closed. Folklore ports are regressions. Caps versus expected volume written next to the quote.

Reviewer and cutter are different roles even if they are the same human on a small team. The review step is reading listings and IDs, not repeating the paste. That split is what catches dual MX. TXT approver reachable or there is no window. Inverse offboard practiced on a lab when the junior joins.

Monthly sample of three zones. Junior lab loop. Retainer points here. Forbidden list in bold. Start free on a lab. Keep Sunday boring. MailerZ does not merge leftover Google.

One last note

One last note: name the third mailbox in the runbook like a tool. An agency email routing runbook that lets the junior self-send will ship green and fail customers. Chapter 1 is NS then exclusive MX. Chapter 2 is named aliases. Chapter 3 is two resolvers and filed IDs. Chapter 4 is paid dashboard SMTP or inbound-only. Dual MX is forbidden. Folklore ports are forbidden. Shared catch-all is forbidden.

Reviewer reads listings. Cutter pastes. TXT approver is reachable. Cancel owner is named before the window. Design knows saves republish MX. On-call reads this page. Inverse offboard is practiced on a lab. White-label does not suspend physics. Coin-flip clauses you will not honor do not belong in the SOW.

Monthly sample three zones. Junior lab loop this month. Caps versus roster. Confirm /pricing. Morning re-query after launches. Retainer points here. Forbidden list in bold.

Start free on a lab so the first Sunday is not a hospital. MailerZ shows hops it accepted. It does not merge leftover Google. Keep the runbook boring and the hop exclusive.

If SMTP was not sold, write inbound-only so 550 is not a severity-one. If it was sold, prove a unique send and fail closed. Packet in the ticket. Review next to renewals.

Last checks

Last check: four chapters present in the retainer ticket. Third mailbox named. Dual MX forbidden. Folklore ports forbidden. Agency email routing runbook closeout is a junior who can run Sunday without a call.

Last check: lab loop dated this month. Three-zone sample exclusive with IDs. SMTP proved or inbound-only. Morning re-query on the launch checklist. Cancel owner named.

Last check: reviewer role exists. TXT approver reachable. Inverse offboard practiced. White-label does not suspend leftovers. Caps versus roster written.

Last check: self-send is still not the gate. Shared catch-all still absent. Coin-flip clause absent or refused. Start-free lab exists.

Endnote

Endnote: Sunday works when the third mailbox has a name, the reviewer reads IDs, and dual MX is impossible to do politely. An agency email routing runbook is those constraints plus exclusive MX. Folklore ports stay out. Shared catch-all stays out. Self-send stays out.

If SMTP was sold, prove it on a paid plan after inbound. If it was not sold, write inbound-only so 550 is not a fire. Inverse offboard is practiced. Morning re-query sits on the design launch list. Junior lab loop is this month, not someday.

Start free on a lab. Paste the four chapters into the retainer. Keep the hop exclusive. MailerZ will not merge leftover Google. The runbook is what you actually sold.

If two people 'handle email,' the runbook still names one exclusive owner. Split-brain is leftover MX with two invoices. Write the owner on page one.

FAQ

What is the safest way to handle an agency email routing runbook?

NS, exclusive MX, named aliases, third-mailbox probes, leftover delete, then paid SMTP from the dashboard. Never dual-publish to test.

Does this require a new mailbox?

No. Keep client Gmail or Outlook unless they asked for IMAP.

Will it work with Gmail or Outlook?

Yes as destinations. Self-send is not the runbook gate.

What DNS records are involved?

NS that name the live panel, exclusive MX, verify TXT, leftovers gone. SPF and DKIM when that zone sends.

What should you test?

Two resolvers, unique probes per public alias, HOLD, morning re-query, and SMTP only after paid plan.

Where do we write the runbook?

In the ticket system the retainer already uses. Not in a personal Notion only one person can see.

Key takeaways

  • Four chapters: DNS, aliases, SMTP, tests.
  • Exclusive MX in every chapter.
  • Named aliases. No shared catch-all.
  • Third mailbox. Self-send is not the gate.
  • SMTP from the dashboard on a paid plan.
  • Morning re-query after builders.
  • Confirm /pricing before quoting.
  • Not IMAP, not SOC 2, not an inbox SLA.

Conclusion and next action

Run DNS, aliases, SMTP, and tests as four chapters with exclusive MX in every chapter. MailerZ shows hops it accepted. It does not merge leftover Google. Start free on a lab, then scale with a sheet.

Need a runbook a junior can run

Start free on a lab zone, then paste this order into the retainer.

Inbound first. SMTP second. Sign in if the workspace already holds clients.

Review quarterly, or sooner if provider behavior, pricing, or MailerZ scope changes. Author: MailerZ editorial, Secuno LLC.