Agency & Multi-domain

Multi-domain email forwarding: architecture and operational checklist

One owner per zone. Named lists. Separate secrets. No shared leftover template.

MailerZ editorial · Secuno LLC17 min read

Multi-domain email forwarding is an architecture: one exclusive inbound hop per zone, named aliases, a written destination map, and a plan that matches domain and alias caps. It is not one catch-all for the whole roster. MailerZ can hold many domains on paid plans. Free is one domain. Leftover MX on any zone splits that zone only, but the pager still rings. Confirm /pricing. Probe each public alias from a third mailbox. Do not dual-publish during 'architecture week.'

Put brand and zone on the same sheet so a junior can page at 2 a.m. without guessing the panel. Caps first. Lab first. Waves, not one leftover weekend.

Multi-domain email forwarding: one exclusive hop per zone
One workspace can hold many zones. Each zone still needs exclusive MX.

Quick answer for multi-domain email forwarding

Draw the roster. Each zone gets exclusive MailerZ MX, its own alias list, and its own leftover delete. The workspace can be one. The MX sets cannot be shared as a blob.

Check domain, alias, seat, store, and send-as caps before you promise the tenth zone. Free cannot do this architecture. Confirm /pricing.

Run the checklist below on a calendar, not after a client screams.

DNS: IETF RFC 1035 — Domain names. Mail: IETF RFC 5321 — Simple Mail Transfer Protocol. Paths: MailerZ pricing, features, migration planner, Mail Box, and MailerZ documentation. Solo is $40 per year with send-as, SMTP, and API On. Free keeps those Off.

User problem and decision criteria

Multi-domain setups fail when someone treats DNS as a bulk paste and catch-all as a personality. Architecture is per-zone exclusivity plus a map humans can audit.

Decision criteria: who owns each registrar, which destinations exist, whether send-as is in scope per zone, whether HOLD is the unknown policy, whether the plan can count that high.

If two agencies share a client, demand one exclusive owner. Split-brain is leftover MX with invoices.

If brands cannot see each other's mail, do not share a destination without filters and access control. Forwarding is not tenancy by itself.

If you needed IMAP folders per brand, you left the forwarding class for those brands.

If you needed a badge, write no. Do not hide it in architecture diagrams.

Technical mail flow across a roster

Each zone's public NS name a panel. That panel must show only MailerZ MX after cut. Senders never see your spreadsheet. They see MX.

MailerZ applies SRS on the envelope and leaves Header From intact. The destination is whatever you mapped for that alias on that zone.

Unknown recipients follow that zone's HOLD or FORWARD. Roster-wide FORWARD into one Slack is a leak.

Send-as is per identity and per plan cap. A blast across ten zones will hit hourly walls. Architecture includes the cap.

A leftover on zone B does not repair zone A. It still pages you because clients do not speak zone IDs. They speak brand names.

Per-zone exclusive MX and named alias maps
One workspace. Many exclusive sets.

Operational checklist

  1. Inventory zones, NS hosts, public aliases, destinations, send-as yes/no, old-seat owners.
  2. Confirm plan caps versus inventory. Upgrade before the cut wave.
  3. Lab a single zone to completion: exclusive MX, probe, HOLD, optional send-as.
  4. For each production zone: lower TTL if you control it, cut exclusive, delete leftovers, two resolvers.
  5. Probe each public alias from a third mailbox. File IDs under the zone name.
  6. Morning re-query after website builders.
  7. Disable leftover registrar email products so they cannot republish.
  8. HOLD review on a calendar.
  9. Offboard inverse: new exclusive owner before you drop MailerZ MX.
  10. Quarterly cap and leftover audit.

Failure modes and proof

One Free account expected to hold ten zones. Proof: pricing page.

Shared catch-all. Proof: a typo for brand A in brand B's mailbox.

Bulk paste MX into the wrong NS. Proof: resolvers still show the old host.

Send-as on one zone, leftover MX on another, one ticket. Split the tickets.

No probe IDs. Mood is not proof.

Proof package: roster sheet, per-zone resolvers, per-alias IDs, cap screenshot, HOLD policy.

MailerZ workflow and product boundary

Multi-domain routing, SMTP, migration, and operational visibility. Still not IMAP, not a suite, not SOC 2.

Agency plan is capacity: more domains, aliases, seats, outgoing. It does not buy dual MX or tenancy.

Store is fourteen or ninety days of hops MailerZ saw. Not a legal archive per brand.

Delivery-recovery and hop history are per message, not per vibe.

If you need a workspace per client for metadata reasons, that is allowed and sometimes required.

Confirm /pricing the day you add a wave of zones. Cards move.

Cost and alternatives

Per-user suites times brands is the usual overbuy. Forwarding is cheaper if people already have inboxes.

One mailbox host per brand is honest IMAP and heavy operations.

Cloudflare Routing per zone is cheap inbound and thin proof. Score it honestly.

A second forwarder 'for overflow' is leftover MX if published. Do not.

The cheap architecture is exclusive cuts and a spreadsheet. The expensive one is dual MX during launches.

Upgrade the plan before you invent a second vendor.

Worked scenarios

Franchise: twenty city zones plus a parent. Twenty-one exclusive sets. Parent hello@ is not a catch-all for cities.

Agency roster: ten clients, ten close dates. One junior, one sheet, one morning re-query cron.

Merger: forty zones. Wave cuts. No dual-publish PR week.

White-label: hiding the hop UI does not hide leftover MX. Still delete.

Nonprofit plus a shop brand: two destinations, two maps, one workspace or two. Do not mix donor mail into shop HOLD.

Practice and anti-patterns

Practice: per-zone exclusivity. Anti-pattern: one MX blob.

Practice: named aliases. Anti-pattern: roster catch-all.

Practice: cap math. Anti-pattern: surprise 550 on send-as.

Practice: probe IDs. Anti-pattern: 'we tested a few.'

Practice: inverse offboard. Anti-pattern: cancel MailerZ while still published.

Practice: split tickets. Anti-pattern: inbound plus SMTP in one blob.

Multi-domain email forwarding stays boring when the sheet is complete.

Operator closeout

Every zone: exclusive resolvers, probes, leftover products off, old-seat owner, review date.

Plan cap versus live count. Deputy for the sheet.

HOLD review scheduled. Send-as identities listed.

Offboard dates known for anyone leaving this quarter.

Edge cases

Two zones on one registrar login, one without 2FA. That login is the architecture's weak point.

A zone whose NS still point at a dead reseller. Fix delegation first.

IDN zones. Copy dashboard MX carefully. Do not punycode by hand if you are unsure.

A parked for-sale zone you still receive on. Decide. Parking MX will fight you.

A zone used only for send-as. Still do not leftover-MX inbound if you also receive.

Workspace export that joins clients. Split if the retainer cares.

Field notes

The architecture diagram that omits leftover delete is a poster. The checklist that includes morning re-query is operations.

Clients speak brand, not zone ID. The sheet needs both columns.

Website builders republish. Architecture includes that enemy.

Caps are architecture. Shame about caps is how second vendors appear.

One shared Slack for all HOLD is a leak. Per-zone or named-alias only.

If you cannot name the deputy, you do not have an architecture. You have a hero.

Start free on a lab, not on the tenth client.

Handoff memo

Sheet location, workspace URL, plan, cap math, per-zone NS, last probe dates, leftover products, deputies, inverse offboard rule.

Forbidden: roster catch-all, dual MX, Free for a fleet, php folklore ports on send-as.

Lab loop: add a disposable zone, cut, probe, delete leftovers, remove the zone.

Acceptance criteria

Every production zone exclusive and probed. Caps fit. No shared catch-all. Sheet complete. Morning re-query exists.

Send-as only where paid and listed. Leftover products disabled.

A stranger can run one zone from the memo.

Operations review of the roster

Walk the sheet monthly. Every zone needs exclusive listings, a last probe date, and an old-seat owner. Multi-domain email forwarding without dates is a poster.

HOLD review per zone or per named alias. A shared Slack for all brands is a leak with architecture branding.

Cap math versus live domain and alias counts. Upgrade before the next wave. Do not open a second vendor.

Morning re-query sample: pick three zones that had website saves. Builders republish.

Offboard list for the quarter. Inverse cut dates written. Do not remain published after you drop the retainer.

Send-as identities listed. Free cannot cover a fleet. Confirm /pricing.

Workspace split if metadata join matters. Capacity is not tenancy.

Two-brand listings are incidents, not propagation. Delete the other name.

IDN and punycode zones copied from the dashboard, not hand-rolled.

Deputy can add a disposable lab zone and complete the checklist without a call.

Quarterly review

Re-score caps. Re-probe a sample of public aliases. Re-read leftover products on registrars that sell email.

Diff the sheet against MailerZ domain list. Orphans go or get documented.

Rehearse inverse offboard on a lab.

Security questionnaires still say no on badges.

Franchise or merger waves scheduled as waves, not as one dual-publish weekend.

Write no-drift or name the drift.

Start-free lab still exists so juniors do not practice on hospitals.

Closing notes

Architecture is exclusive MX per zone, named maps, and a checklist with dates. It is not one catch-all and not dual MX.

Free is one domain. Fleet plans are capacity. Confirm /pricing. Probe every public alias.

Start free on a lab, then scale the roster. Leftover MX on any zone still pages you.

Field depth on rosters

A roster without close dates is how leftover seats outlive retainers. Multi-domain email forwarding includes the cancel column. Capacity does not.

Brand names and zone names differ. Clients page you with brands. The sheet needs both or the junior will edit the wrong NS.

Website teams ship pages that include email toggles. Architecture that ignores them will republish MX on launch night.

Mergers want one weekend. Physics wants waves. Each wave has exclusive cut, probes, and a drain clock. Dual-publish is not a wave strategy.

Franchises want city domains to inherit parent hello@. That is a map, not a catch-all. Typos at a city zone should HOLD, not land in HQ Slack.

IDN zones punish hand typing. Dashboard copy only.

Parked for-sale zones still receive if MX says so. Decide whether that is on purpose.

A second forwarder for overflow, if published, is leftover MX. Overflow belongs in send-as vendors, not a second inbound MX.

People and deputies

Who owns the sheet, who can change TXT per zone, who reviews HOLD, who quotes caps, who runs inverse offboard.

Two agencies on one client must name one exclusive MX owner. The runbook cannot survive split-brain.

A hire who has not completed the lab zone is not ready for a hospital client.

Finance must see cap math before a wave. Surprise Agency upgrades mid-cut are avoidable.

Support macros must not promise inboxing or badges.

Proof packet

Sheet complete, caps fit, every production zone exclusive and sampled probes, HOLD policy, leftover products off, inverse dates, deputy lab loop.

Send-as listed or forbidden per zone.

No shared catch-all. No dual MX. No Free fleet.

Appendix

Appendix: the sheet needs brand, zone, NS host, exclusive date, last probe, HOLD policy, send-as, old-seat owner, offboard date.

Appendix: a missing brand column is how juniors edit the wrong panel when a client says the shop name, not the zone.

Appendix: shared HOLD Slack is a confidentiality bug. Per-zone or named-alias only.

Appendix: Free cannot hold a fleet. Confirm /pricing before the tenth zone.

Appendix: a second inbound vendor published is leftover MX. Overflow is a send-as vendor, not a second MX.

Appendix: mergers are waves. Each wave exclusive. PR week is not a dual-publish license.

Appendix: franchises map cities. They do not catch-all cities into HQ.

Appendix: IDN copy from the dashboard only.

Appendix: parked zones still receive if MX says so. Decide.

Appendix: inverse offboard before you drop a retainer. Remaining published is your bounce.

Appendix: workspace split if metadata join matters.

Appendix: website launches trigger morning re-query. Put it on the design checklist.

Appendix: two agencies, one exclusive owner. Split-brain is leftover MX with invoices.

Appendix: badges stay no. Diagrams do not hide that.

Appendix: deputy lab zone monthly. Heroes do not scale.

Appendix: cap math is architecture. Shame about caps is how second vendors appear.

Final pass

Final pass: every production zone exclusive and sampled, caps fit, no shared catch-all, sheet complete, inverse dates, lab loop done.

Send-as listed or forbidden. Leftover products off. Morning sample clean.

Start free on a lab. Then scale. Leftover MX on any zone still pages you.

Extended operator narrative

Draw the roster as a sheet, not a diagram. Brand, zone, NS host, exclusive date, last probe, HOLD policy, send-as, old-seat owner, offboard date. Multi-domain email forwarding fails when the junior hears a shop name and opens the wrong panel because you omitted the brand column. It fails when HOLD for every brand lands in one Slack. It fails when Free is asked to hold ten zones. Confirm /pricing before the wave. Capacity is architecture. Shame about caps is how a second inbound vendor appears and becomes leftover MX.

Each zone is exclusive physics. Public NS name a panel. That panel shows only MailerZ MX after cut. Senders do not see your workspace. They see MX. A leftover on zone B does not repair zone A and still pages you because clients speak brands. Morning re-query after website saves. Disable registrar email products so they cannot republish. Inverse offboard: new exclusive owner before you drop MailerZ MX. Remaining published after you drop a retainer is your bounce.

Waves, not weekends. Mergers and franchises want one ceremony. Physics wants exclusive cuts, probes, and drain clocks per wave. Cities do not inherit parent hello@ through a catch-all. They get maps. IDN copies from the dashboard. Parked zones still receive if MX says so; decide. Workspace split if a retainer forbids metadata join. Two agencies, one exclusive owner. Badges stay no. Deputy completes a disposable lab zone without a call.

Send-as is per identity and per cap. A blast across ten zones hits hourly walls and is the wrong class. Architecture includes the cap and an overflow transactional vendor if needed. That overflow is not a second inbound MX. Inbound leftover MX never raises a send cap. Keep tickets split. Keep hop history IDs under the zone name. Keep the sheet dated. A poster architecture without dates is how leftover seats outlive retainers.

Start free on a lab, not on the tenth client. Prove one exclusive hop, then scale. Review caps quarterly. Sample probes. Re-read leftover products on registrars that sell email. Write no-drift or name the drift. The checklist is the architecture. The hop is MailerZ. The inbox SLA does not exist. The suite is optional and separate. Leftover MX is still a hard stop on every zone you touch.

More operator notes

Print the sheet and walk it with a junior as if they will page you at 2 a.m. If they cannot find the brand-to-zone mapping, the architecture is unfinished. Multi-domain email forwarding is a filing system that happens to use MX. Exclusive hops are the physics. The sheet is the product the client actually bought from an agency.

Schedule HOLD review and morning re-query on the same calendar as launches. Builders republish. Guessed prefixes arrive. A shared Slack for all brands is a leak. Per-zone HOLD or named aliases only. Inverse offboard dates belong on that calendar too. Remaining published after you quit is your bounce.

Cap math before waves. Confirm /pricing. Free is one domain. A second inbound vendor is leftover MX. Send-as overflow is a transactional product, not a second MX. Workspace split if metadata join is forbidden. Two agencies, one exclusive owner. Badges stay no.

Lab a disposable zone monthly. Start free there, not on a hospital. Sample production probes quarterly. Write no-drift or name the drift. Leftover MX on any zone still pages you.

One last note

One last note: if the junior cannot map a brand to a zone at 2 a.m., the architecture is a poster. Multi-domain email forwarding is a sheet with exclusive physics attached. Brand, zone, NS, exclusive date, last probe, HOLD, send-as, old-seat, offboard. Shared Slack HOLD is a leak. Free is one domain. Confirm /pricing before waves.

Each zone: exclusive MX, leftovers deleted, products that republish disabled, morning re-query after launches. Inverse offboard before you quit. Remaining published is your bounce. Two agencies, one exclusive owner. Workspace split if metadata join is forbidden. Badges stay no.

Waves for mergers. Maps for franchises, not catch-alls. IDN from the dashboard. Parked zones are a decision. Send-as overflow is a transactional vendor, not a second inbound MX. Caps are architecture. Shame about caps is how leftovers appear.

Lab a disposable zone monthly. Sample production probes quarterly. Write no-drift or name the drift. Start free on the lab. Scale only after one hop is boring. Leftover MX on any zone still pages you.

MailerZ is the hop, not a suite, not IMAP, not an inbox SLA. The checklist is what you sell. Keep dates on the sheet or you are running a hero, not an architecture.

Last checks

Last check: the sheet has brand, zone, NS, exclusive date, last probe, HOLD, send-as, old-seat, offboard. Multi-domain email forwarding closeout is a complete row per production zone.

Last check: caps fit. No shared catch-all. No second inbound MX. Inverse dates written. Lab zone exists. Junior can map a brand at 2 a.m.

Last check: morning sample after launches. Leftover products off. Badges still no. Confirm /pricing. Start-free lab still clean.

Last check: waves planned for any merger. Franchise maps, not catch-alls. Workspace split if required. Two agencies, one exclusive owner.

Endnote

Endnote: print the nine columns and refuse to cut a zone that is missing a row. Multi-domain email forwarding is exclusive physics plus a sheet a stranger can page from. Caps first. Lab first. Waves not weekends. No shared HOLD Slack. No second inbound MX.

If a client says the shop name, the junior must find the zone without you. If they cannot, finish the sheet before the window. Start free on the lab. Confirm /pricing before the tenth domain. Leftover MX on any zone still pages you.

If you remember one number, remember that Free is one domain. Fleet plans exist. Agency capacity is not tenancy and not dual MX. Write that on the first page of the sheet.

FAQ

What is the safest way to handle multi-domain email forwarding?

Exclusive MX per zone, named aliases, no shared catch-all across brands, plan caps checked, leftover MX deleted, third-mailbox probes per public alias.

Does this require a new mailbox per domain?

No. Destinations can be existing Gmail or Outlook accounts. MailerZ is not IMAP. Tenancy still matters: do not dump every brand into one shared folder without a map.

Will it work with Gmail or Outlook?

Yes as destinations. Self-send is not proof. Probe each zone from a third mailbox.

What DNS records are involved?

Per zone: public NS, exclusive MailerZ MX, verify TXT, leftovers gone. SPF and DKIM per zone that sends.

What should you test?

Two resolvers per zone, unique probes per public alias, HOLD behavior, and a morning re-query after website saves.

Can one catch-all cover every domain?

No. That mixes tenants and turns typos into a confidentiality incident. Named aliases or per-zone HOLD.

Key takeaways

  • One exclusive hop per zone.
  • Named maps. No roster-wide catch-all.
  • Plan caps are architecture. Confirm /pricing.
  • Leftover MX is per zone and still pages you.
  • Probe every public alias.
  • Free is one domain. Fleet plans exist.
  • Envelope SRS. Header From intact.
  • Not IMAP, not SOC 2, not an inbox SLA.

Conclusion and next action

Architect multi-domain email forwarding as exclusive MX per zone, named maps, and a checklist you can run on Sunday. MailerZ is the hop, not a shared inbox, not a suite, not an inbox SLA. Start free, prove one zone, then add the next.

Ready to run more than one zone

Start free on a lab domain, then scale the roster against live limits.

One zone on Free. Fleet plans when the list grows. Sign in if the workspace exists.

Review quarterly, or sooner if provider behavior, pricing, or MailerZ scope changes. Author: MailerZ editorial, Secuno LLC.