Step 6: Cut Over Mail Flow to Proofpoint (Google Workspace)

Modified on Tue, Aug 25 at 11:12 AM

Before you change anything

Work through this list first. Each item causes mail loss if it is wrong at the moment the MX records change.

  • In Proofpoint, under Account Management → Features, Enable Outbound Relaying is checked.
  • In Proofpoint, under Account Management → Domains, every active domain shows as verified with the relay enabled.
  • Every mailbox, group and alias from Step 3 is present in Proofpoint.
  • Each domain's SPF record includes the Proofpoint entry for your region, and DNS has updated.
  • Step 5 passed, including the header check.
  • The outbound and internal routing rules in Google are saved, and both use an escaped regexp.

Lower the TTL first

Do this at least a day before the cutover. Set the TTL on the existing MX records to 300 seconds. If something goes wrong you can put the old records back and have mail flowing again in five minutes, instead of waiting out a TTL of several hours while the customer receives nothing.

Change the MX records

Replace the existing MX records with the two Proofpoint records for your region.

US customers

Type: MX   Host/name: @   Value: mx1-us1.ppe-hosted.com   Priority: 0
Type: MX   Host/name: @   Value: mx2-us1.ppe-hosted.com   Priority: 1

EU customers

Type: MX   Host/name: @   Value: mx1-eu1.ppe-hosted.com   Priority: 0
Type: MX   Host/name: @   Value: mx2-eu1.ppe-hosted.com   Priority: 1

Remove the old records

Delete the Google MX records. This is not housekeeping to come back to later.

Filtering is only as good as the records pointing at it. While the Google MX records are still published, any sender that ignores priority, and plenty do, can deliver straight into the mailbox and bypass Proofpoint completely. Targeted mail is more likely to do this than ordinary mail, because it is worth someone's time to look. If the customer wants a fallback for the first day, leave the old records at a higher priority number and set a reminder to remove them. Do not leave them indefinitely.

Verify the change

Wait for the old TTL to expire, then confirm:

  1. Run a public MX lookup for the domain, or dig MX yourdomain.com, and confirm only the two Proofpoint records come back.
  2. Send a message from an external address and confirm it appears in the Proofpoint inbound log and reaches the mailbox.
  3. Open that message, use Show original, and confirm SPF, DKIM and DMARC all pass.
  4. Send a message out to an external address and confirm it leaves through Proofpoint by checking the outbound log.

Lock the inbound gateway down

Once inbound mail has been flowing through Proofpoint cleanly for a day or two, go back to the inbound gateway in the Google Admin console and check Reject all mail not from gateway IPs. Until this is checked, anything that reaches a Google IP directly can still deliver and skip filtering.

Read the gateway IP list back before you check the box. Up to this point a mistyped range causes authentication failures. Once this box is checked, it stops mail. Go through every entry, including any past the first page, against the Connection Details article.

Repeat for every domain

Every active domain on the account needs its own MX change. A domain left on the old records keeps taking mail directly into Google, and because the rest of the estate looks healthy it can sit like that for months.

Deploying Proofpoint? We Can Help

We support Proofpoint deployments end-to-end from configuration and migration to optimization, ensuring a smooth rollout with minimal disruption.

Speak to an expert

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article