Email routing explained

How MX-Based Spam Filtering Works

MX-based spam filtering protects a business domain by receiving inbound email before it reaches your current mail provider. Clean mail continues to the inboxes your team already uses.

TLDR

MX-based spam filtering changes where inbound mail goes first. Instead of delivering directly to Microsoft 365, Google Workspace, cPanel, or another mail host, incoming messages go to a filtering layer. The filter blocks or quarantines unwanted mail and forwards clean messages to your existing provider.

What Are MX Records?

MX records are DNS records for email delivery. They tell the internet which mail servers should receive email for your domain.

If your domain is example.com, the MX records for that domain decide where messages for addresses like [email protected], [email protected], and [email protected] should be sent.

Without MX records, other mail systems do not know where to deliver email for your domain.

How MX Filtering Changes Delivery

In a normal setup, your MX records point directly to your mailbox provider.

With MX-based spam filtering, your MX records point to the filtering service first. Incoming mail is checked before it reaches the provider that hosts your inboxes.

The route becomes: incoming email → spam filter → existing email provider → user inbox.

This is useful when your current provider is mostly fine, but too much junk is getting through.

Before changing DNS, review how to prepare and verify an MX record change.

What Stays the Same

MX-based filtering does not mean you are moving your entire email system.

  • Your users keep the same email addresses.
  • Your team keeps using the same inboxes and email apps.
  • Your mailbox provider still hosts the accounts.
  • Your calendars, contacts, and stored mail stay with your provider.
  • Outbound email can continue through your existing provider unless you choose otherwise.

The main change: inbound email reaches the filtering layer before it reaches your current mail host.

What Admins Can Review

A useful inbound filter should not only block mail silently. Admins need a way to understand what happened when a message is delayed, blocked, or quarantined.

Depending on the setup, admins may review quarantined messages, release legitimate mail, search logs, add trusted senders to sender allow lists, block unwanted known senders with sender block lists, and configure advanced filters. See our guide to email quarantine versus spam folders for the operational difference.

In SpamVest, basic controls are available in the dashboard. Deeper per-domain tools are available through antispam cloud.

When to Use MX-Based Filtering

MX-based filtering is a strong fit when spam affects the business domain, not just one person’s mailbox.

  • Multiple inboxes receive unwanted mail.
  • Public addresses like info@ or sales@ attract junk.
  • The existing mail provider works, but its spam filtering is not enough.
  • You want to avoid a full mailbox migration.
  • You want protection before messages reach users.

If only one person receives occasional junk, mailbox rules may be enough. If the whole domain is noisy, domain-level inbound filtering is usually more practical.

Where SpamVest Fits

SpamVest is our MX-based inbound spam filtering service for business domains.

It sits in front of your existing email provider, filters inbound mail, and forwards clean messages to the provider you already use. That means you can keep Microsoft 365, Google Workspace, cPanel email, or another mail host.

SpamVest is priced annually per protected domain, not per user, which keeps the model simple for businesses with shared addresses, aliases, and changing mailbox counts.

Frequently Asked Questions

Do email addresses change?

No. MX-based filtering changes the inbound delivery route for your domain. It does not require new email addresses.

Does this replace my email provider?

No. Your existing provider still hosts your mailboxes. The filter receives inbound mail first and forwards accepted mail onward.

Should old MX records stay in place?

Usually, no. Leaving old provider MX records active can allow senders to bypass filtering. Follow the setup instructions for your domain and remove old routes when the new route is ready.

Is there a quarantine?

Yes. Suspicious messages can be quarantined so admins can review them instead of having every questionable message delivered directly to users.

Are there logs?

Yes. Logs help admins investigate incoming messages and understand whether mail was accepted, blocked, quarantined, or affected by sender allow lists or sender block lists.

Add Filtering Before Mail Reaches Your Inboxes

If your current provider works but spam is getting through, MX-based filtering may be the cleaner fix.

SpamVest protects your business domain while keeping your existing inboxes and email provider in place.

Protect your domain with SpamVest