# Email setup

How you set up email depends on where you are starting from. Find your situation below and follow that section. You choose for each address, so one domain can mix them. For example, support can live in Intray while a founder's own address stays with Google.

Email setup needs no code. Anyone who can sign in to your DNS provider, and to your mail provider if you have one, can do it.

## Where are you starting from?

<CardGroup cols={1}>
  <Card
    title="We have a new domain, or nobody reads email on it yet"
    href="#new-domain-host-it-in-intray"
  >
    Intray becomes the mail server for the domain. You add DNS records, create
    addresses such as support and info, and mail starts arriving. You do not
    need a mailbox anywhere else.
  </Card>
  <Card
    title="Our team already uses Google, Microsoft, or another provider"
    href="#existing-provider-share-an-address-with-intray"
  >
    Keep your provider. For each address the team should share, such as support,
    you tell your provider to send a copy of new mail to Intray. Everyone's
    personal mailbox stays where it is.
  </Card>
  <Card
    title="We have one mailbox we want to bring in, with its old email"
    href="#existing-mailbox-connect-it-with-its-history"
  >
    Intray signs in to that mailbox and imports the folders you choose, then
    keeps reading new mail from it. Nothing changes at your DNS provider.
  </Card>
</CardGroup>

|                              | New domain                                | Existing provider                          | Existing mailbox                                   |
| ---------------------------- | ----------------------------------------- | ------------------------------------------ | -------------------------------------------------- |
| What you do                  | Host the domain in Intray                 | Forward the shared addresses to Intray     | Connect the mailbox to Intray                      |
| Where mail arrives first     | Intray                                    | Your provider, which sends Intray a copy   | Your provider, and Intray reads it from there      |
| Old email                    | Not imported                              | Not imported                               | Imported from the folders you choose               |
| Replies are sent             | From Intray                               | From Intray                                | Through your own mail server, after you turn it on |
| Changes at your DNS provider | Inbound mail (MX), DKIM, SPF, return path | DKIM, SPF, return path. MX stays unchanged | None                                               |

## New domain: host it in Intray

<Steps>
  <Step title="Add the domain">
    Open Settings and press **Add domain**. Enter a domain you own.
  </Step>
  <Step title="Add the DNS records">
    In the DNS dialog choose **Host mail in Intray**. Intray generates the
    record values. Copy each one to your DNS provider. If the dialog shows a
    **Set up automatically with** button for your DNS provider, press it and
    approve the records there.
  </Step>
  <Step title="Wait for Verified">
    Each row shows Verified once Intray sees the record. The page updates
    without a refresh. **Recheck** asks again. A domain that has not verified
    after 72 hours shows as stalled.
  </Step>
  <Step title="Add addresses">
    Press **Add address**. Intray suggests info, press, privacy, and support. An
    address needs no DNS of its own.
  </Step>
</Steps>

| Record            | What it does                           | Required    |
| ----------------- | -------------------------------------- | ----------- |
| Inbound mail (MX) | Delivers mail for the domain to Intray | To host     |
| DKIM              | Signs the mail you send                | Yes         |
| SPF               | Allows Intray to send for the domain   | Yes         |
| Return path       | Routes bounces back to Intray          | Yes         |
| DMARC             | `_dmarc` TXT `v=DMARC1; p=none;`       | Recommended |

<Warning title="The MX record moves all mail">
  Once you add the inbound mail record, mail for every address on the domain
  stops arriving at your current provider. If anyone still reads mail there,
  forward instead.
</Warning>

## Existing provider: share an address with Intray

Your provider keeps receiving all mail for the domain. For each address the team should share, you add a rule at your provider that sends a copy of new mail to a private Intray address. That rule is called forwarding. Your MX records stay as they are, and nobody else's mailbox changes.

<Steps>
  <Step title="Verify the domain for sending">
    Add the domain and choose **Keep current provider** in the DNS dialog. Add
    the sending records only. They do not change where your mail arrives.
  </Step>
  <Step title="Generate a forwarding address">
    Open the address, choose **Forward from current provider**, and press
    **Generate forwarding address**. Intray creates a private address for this
    one address.
  </Step>
  <Step title="Add a forwarding rule at your provider">
    Forward your address to the forwarding address. Choose the option that keeps
    a copy in the original mailbox. Do not change your MX records.
  </Step>
  <Step title="Test forwarding">
    Press **Test forwarding**. Intray sends a test to your address and marks the
    forwarding address Verified when your provider forwards it back. Until then
    Intray rejects all other mail to the forwarding address.
  </Step>
</Steps>

<Note title="What forwarding does not do">
  Forwarding delivers new incoming mail only. It does not sync mail history,
  read state, or mail you send from your current provider.
</Note>

To rotate a forwarding address, press **Generate new address**, update the rule at your provider, test the new address, then revoke the old one. Intray refuses mail sent to a revoked address.

## Existing mailbox: connect it with its history

Intray reads a mailbox you already have over IMAP. DNS and MX stay as they are, and mail keeps arriving where it does today.

<Steps>
  <Step title="Enter the mailbox details">
    In Settings, under Connected mailboxes, press **Connect mailbox**. Enter the
    email address, IMAP server, port, encryption, username, and password. Use an
    app password where your provider offers one.
  </Step>
  <Step title="Your browser seals the password">
    The password is encrypted in your browser before it leaves the page.
    Intray's servers receive ciphertext only.
  </Step>
  <Step title="Choose folders and start the import">
    Pick the folders to import, then press **Start importing**. Import never
    starts on its own.
  </Step>
  <Step title="Turn on sending, if you want it">
    Sending is separate and off by default. Under Address access, press **Send
    code** and enter the code that arrives in the mailbox. Save your SMTP
    details under Sending server (SMTP). Then press **Turn on sending**. Saving
    SMTP details alone does not enable sending.
  </Step>
</Steps>

| Encryption | Usual port |
| ---------- | ---------- |
| SSL/TLS    | 993        |
| STARTTLS   | 143        |

## Steps for your mail provider

Find your provider from your MX records, or ask whoever pays for your email.

<ProviderTabs>
  <Provider name="Google Workspace">
    **Best path: forward, set by an admin.** An admin routing rule sends no
    verification message and works for group addresses such as support.

    <Steps>
      <Step>
        In the Google Admin console open Apps, Google Workspace, Gmail, then
        **Routing**. Find **Email forwarding using recipient address map**.
      </Step>
      <Step>
        Map your address to the Intray forwarding address. Tick **Also route
        to original destination** so the mailbox keeps its copy.
      </Step>
      <Step>
        Save, then press **Test forwarding** in Intray. Google can take a few
        minutes to apply a rule.
      </Step>
    </Steps>

    To connect the mailbox instead, use IMAP server `imap.gmail.com`, port 993, SSL/TLS. For sending, use `smtp.gmail.com`, port 465. The password is an app password, which needs 2-Step Verification. Google does not offer app passwords on accounts that use security keys only or Advanced Protection.

  </Provider>
  <Provider name="Gmail">
    **Best path: connect the mailbox.** Gmail sends a verification message to
    the forwarding address and forwards nothing until someone clicks the link
    in it. Intray rejects mail to a forwarding address that has not passed its
    own test, so that message never arrives.

    Use IMAP server `imap.gmail.com`, port 993, SSL/TLS. For sending, use `smtp.gmail.com`, port 465. The password is an app password from your Google Account, which needs 2-Step Verification. IMAP is always on in Gmail, so there is nothing to enable.

  </Provider>
  <Provider name="Microsoft 365">
    **Only path: forward.** Microsoft disabled password sign-in for IMAP in
    every tenant, app passwords included. Connect a mailbox does not work with
    Microsoft 365.

    <Steps>
      <Step>
        In the Exchange admin center open Recipients, Mailboxes, pick the
        mailbox, then **Manage email forwarding**. Enter the Intray forwarding
        address and choose **Deliver message to both forwarding address and
        mailbox**. For a shared address with no mailbox, use Mail flow, Rules.
      </Step>
      <Step>
        Microsoft blocks forwarding to outside addresses by default. A blocked
        forward bounces with code 5.7.520. At security.microsoft.com open Email
        and collaboration, Policies and rules, Threat policies, Anti-spam. In
        the outbound policy set **Automatic forwarding rules** to **On -
        Forwarding is enabled**. A custom policy can limit this to the one
        mailbox.
      </Step>
      <Step>Press **Test forwarding** in Intray.</Step>
    </Steps>

  </Provider>
  <Provider name="Fastmail">
    **Either path works.** Forward for new mail only. Connect the mailbox when
    you want history.

    <Steps>
      <Step>
        In Fastmail open Settings, **Filters and Rules**, then create a rule.
        Match your address, then choose **Send a copy to** and enter the
        Intray forwarding address. Fastmail keeps the original. Mail that
        Fastmail files as spam is not forwarded.
      </Step>
      <Step>Press **Test forwarding** in Intray.</Step>
    </Steps>

    To connect the mailbox instead, use IMAP server `imap.fastmail.com`, port 993, SSL/TLS. For sending, use `smtp.fastmail.com`, port 465. Create an app password under Settings, Privacy and Security, Connected apps and API tokens. Your login password does not work over IMAP.

  </Provider>
  <Provider name="iCloud">
    **Either path works.** To forward, open icloud.com/mail, Settings, **Mail
    Forwarding**, and enter the Intray forwarding address. Leave "Delete
    messages after forwarding" off.

    To connect the mailbox instead, use IMAP server `imap.mail.me.com`, port 993, SSL/TLS. For sending, use `smtp.mail.me.com`, port 587, STARTTLS. The IMAP username is the part of your address before the @ sign. The SMTP username is the full address. The password is an app-specific password from your Apple Account page.

  </Provider>
  <Provider name="Other">
    Any provider with forwarding rules or IMAP works. Look for "forwarding",
    "redirect", or "mail rules" in its settings, and choose the option that
    keeps a copy. For IMAP, search the provider's help for "IMAP settings" and
    "app password".

    If a provider sends a confirmation to the forwarding address before it forwards, connect the mailbox instead. Zoho Mail does this. Use IMAP there: `imappro.zoho.com`, port 993, on paid organization accounts, after you turn IMAP on in Zoho webmail.

    Proton Mail also asks the forwarding address to accept a request, and it offers IMAP only through its Bridge app. Neither path works with Proton today.

  </Provider>
</ProviderTabs>

## Steps for your DNS provider

If Intray shows a **Set up automatically with** button for your DNS provider, press it. You approve once at your DNS provider, the records are added for you, and Intray verifies them on its own. The button appears only when your provider supports it.

Otherwise add the records by hand. The two mistakes below cause most failed verifications.

- **The name field.** Most DNS providers add your domain to the name for you. Enter the name without your domain. If verification fails, look up the record and check for a doubled domain.
- **A second SPF record.** A name can hold one SPF record. If one already exists at the same name, add Intray's `include` to it. Do not create a second record.

Intray checks DNS from its side, so Verified means the record is public. Some providers take longer to publish a change.
