When configuring a new domain for Proofpoint Essentials, all of a customer's domains must be both verified and have the relay enabled so that they can send and receive email.
Allow time for the change to propagate. A domain is not usable the moment you enable it. Changes propagate across the Proofpoint platform on the hour and on the half hour, so depending on when you save, the wait is anywhere from a few seconds to thirty minutes.
Adding domains to Proofpoint
Log into the Proofpoint portal that matches your tenant's region.
If you are adding a domain for a customer rather than your own account, navigate to Customer Management → Customers and click on them in the list. Once you are logged in, navigate to Account Management → Domains.
To add a new domain to Proofpoint, click the New Domain button:

Set the domain type to Relay. The primary delivery destination is where Proofpoint hands filtered inbound mail on to, so for a Google Workspace domain this is the customer's Google MX host, normally ASPMX.L.GOOGLE.COM. Enter the host name only, with no priority value.
If additional Google MX records are published at a lower priority, these can be added to Proofpoint as failover delivery destinations.

Before setting up an existing domain, click the three dots on the right side of the screen, then click Edit Domain:

Ensure that the domain type is set to Relay and that the correct delivery destination is filled in.
Prepare Google Workspace routing
On the Account Management → Domains page, click on Manage Hosted Services:

Turn on the option for Google Apps, then click Save.

Verify and enable domains
For each domain on the Account Management → Domains page, click the Verify Domain button:

This will display a TXT record that needs to be added to the domain's DNS zone. Once this TXT record is published, click on Verify Now.

Once this is complete, click Enable Relay next to the domain on the Account Management → Domains page.
Enable outbound relaying
Outbound mail will not leave through Proofpoint unless outbound relaying is switched on for the account. Setting it here rather than at cutover gives it time to propagate before it is needed.
- In the customer's Proofpoint account, go to Account Management → Features.
- Check Enable Outbound Relaying.
- Click Save.
This is confirmed again as a pre-flight check in Step 6.
Proceed to next step: Step 2: Update SPF Record
Deploying Proofpoint? We Can Help
We support Proofpoint deployments end-to-end from configuration and migration to optimization, ensuring a smooth rollout with minimal disruption.
Speak to an expertWas this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article