Skip to main content
Skip table of contents

Routing Internal Emails in Google Workspace

Failure to complete this step will mean internally sent emails are very likely to be quarantined as impersonation by Mesh. Internal emails should remain within the tenancy in Google, they should not pass through Mesh Gateway.

Create Mail Route

  1. Go to https://admin.google.com

  2. Go to Apps -> Google Workspace -> Gmail.

  3. Scroll down to "Hosts". Click "Add Route"

  4. Give the new route a name such as "Internal Emails Route".

  5. Under "Specify email server", choose "Single Host", and enter "aspmx.l.google.com". Port 25. (If preferable, more hosts can entered using the “alt” options from here: https://support.google.com/a/answer/174125?hl=en).

  6. Important: Uncheck "Perform MX lookup".

  7. Ensure the following boxes are checked:
    a. Require mail to be transmitted via a secure (TLS) connection (Recommended).
    b. Require CA signed certificate (Recommended).
    c. Validate certificate hostname (Recommended).

  8. Click Save.


Apply Routing Rule

  1. Go to Apps -> Google Workspace -> Gmail.

  2. Scroll down to the section labelled “Routing”.

  3. Click “Configure” or “Add Another Rule”.

  4. Give the new route a name like "Internal Emails Route Rule".

  5. Select the checkbox "Internal - Sending".

  6. In section 2, select "Modify message" from dropdown. Choose the checkbox "Change Route" and select the host you set up earlier.

  7. Scroll to the bottom and click "Show options".

  8. Ensure the following boxes are checked:
    a. Users
    b. Groups

  9. Under Section C, select "Only affect specific envelope senders", choose "Pattern Match" from, and enter in your domain/customer domain in the Regexp field in the format "example.com".

  10. Click Save.


Disable SPF/DKIM checks

SPF and DKIM checks are performed by Mesh. Validating a second time after passing through our servers can cause emails to be falsely marked as spam within Gmail.

  1. Go to Apps -> Google Workspace -> Gmail.

  2. Go to "Safety" section.

  3. Select "Spoofing and Authentication".

  4. Uncheck "Protect against any authenticated emails" and "Apply future recommended settings automatically".

  5. Click Save.


You’re all set!

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.