Step 5: Test Mail Flow (Google Workspace)

Modified on Tue, Aug 25 at 11:10 AM

Before fully cutting over your inbound mail flow to Proofpoint, it is recommended to run an inbound test to ensure that your mail server is ready to accept messages through Proofpoint. This can be done using one of two methods.

Method 1: Send a test email

This method requires that you have access to an email account that is already relaying through Proofpoint on the same regional stack (US or EU) as the client being set up, which makes it a more suitable approach for partners.

  1. Send a test email from another external email address on Proofpoint to an active mailbox on the new Proofpoint client's domain.
  2. In the new client's Proofpoint account, click Log Search in the top-left corner and run an inbound search for "any" mail.
  3. A successful test should show that the test email appears in the Proofpoint logs and was delivered. The very first email that relays through Proofpoint may show as "queued" if you have just sent it. Wait about 30 seconds and run the log search again if this happens.
  4. Verify on the client's end that they did receive the test email.

Method 2: Telnet test

If you are setting Proofpoint up for your own domain and are not being assisted by our support team, you may verify mail flow yourself using Telnet. These steps assume you are using a Windows PC.

  1. Launch a command prompt window by searching cmd after pressing the Windows key, or by pressing Windows key + R and entering cmd.
  2. In the command prompt, enter the command for your region.

US customers:  telnet mx1-us1.ppe-hosted.com 25
EU customers:  telnet mx1-eu1.ppe-hosted.com 25

  1. If successful, the system should return the message "Welcome to PPE Hosted SMTP Server".
  2. Type in each of the following commands one at a time, pressing Enter after each one. You should receive a response starting with 250 or 354 after each command.

helo x
mail from: <emailaddressnotusingproofpoint@example.com>
rcpt to: <user@yourdomain.com>
data
subject: test
text that you would like to include in the test email.

  1. The message "queued as 7070E40006C" indicates that Proofpoint is now processing this test message.
  2. In the new client's Proofpoint account, click Log Search in the top-left corner and run an inbound search for "any" mail.
  3. A successful test should show that the test email appears in the Proofpoint logs and was delivered. The very first email that relays through Proofpoint may show as "queued" if you have just sent it. Wait about 30 seconds and run the log search again if this happens.
  4. Verify on the client's end that they did receive the test email.

Check the message headers

Delivery on its own does not prove the gateway is configured correctly. While Reject all mail not from gateway IPs is off, mail arrives whether or not the gateway IP list is right, so this test can pass on a broken configuration. The headers are where a wrong gateway entry shows up.
  1. Open the delivered test message in the recipient's Gmail.
  2. Click the three dots at the top right of the message, then Show original.
  3. Check the summary at the top of the page. SPF, DKIM and DMARC should all show PASS.
  4. Check the IP address shown beside SPF. It should be a Proofpoint sending address for your region, and it should fall inside one of the ranges you entered in the inbound gateway in Step 4.
If SPF shows fail or softfail on a Proofpoint address, go back to the gateway IP list. Google treats a range it has not been told about as an ordinary external sender, so it authenticates the message against the Proofpoint IP instead of against the original sender's domain. Everything relayed through that range then fails. Read the saved list back one entry at a time against the Connection Details article, including any pages past the first. A single wrong digit is all it takes, and Google gives no warning when you save it.

Why this matters

If the domain is on a DMARC policy of p=quarantine or p=reject, authentication failures do not arrive in junk with a warning. They are held or discarded, and no bounce reaches the sender. The customer's first symptom is somebody mentioning that a supplier says they have not had a reply.

Proceed to next step: Step 6: Cut Over Mail Flow to Proofpoint

Deploying Proofpoint? We Can Help

We support Proofpoint deployments end-to-end from configuration and migration to optimization, ensuring a smooth rollout with minimal disruption.

Speak to an expert

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article