Setup guide

Set up inbound filtering without changing how your team reads email.

SpamVest sits in front of your existing mailbox provider. Confirm where clean mail should be delivered, update your MX records, and verify that filtering is active.

Preparation

Have these details ready before you start.

DNS access

You need access to the DNS zone for the domain you want to protect, usually where the domain, DNS, or hosting is managed.

Current mail destination

Know where accepted mail should continue after filtering, such as Microsoft 365, Google Workspace, cPanel, or another mailbox provider.

A quiet testing window

DNS changes can take time to propagate, so make the change when someone can watch status and confirm mail flow.

Setup steps

Move mail through SpamVest in the right order.

Follow this order: configure the protected domain and clean-mail destination first, then update DNS.

SpamVest provides the MX records and setup guidance, but DNS changes must be made by the domain owner, DNS administrator, or hosting provider with access to the domain's DNS zone.

Create the trial and add your domain

Enter the domain you want SpamVest to protect. The setup flow will prepare inbound filtering for that domain.

Confirm the clean-mail destination

SpamVest needs to know where accepted messages should be delivered after filtering. This keeps your existing inboxes in place.

Replace your domain's MX records

Before changing MX records, confirm your clean-mail destination. Then remove old MX entries and add the MX records shown in SpamVest so senders cannot bypass filtering.

Verify filtering

After DNS has propagated, check the SpamVest status and confirm that inbound mail is passing through the filtering layer.

MX records

Use the records shown in your SpamVest setup.

SpamVest provides redundant MX records for inbound filtering. Some DNS panels also require a trailing dot after the hostname; follow your DNS provider's format.

Before changing MX records, confirm your clean-mail destination. After changing MX records, remove old MX entries so senders cannot bypass filtering.

Type Priority Value
MX 10 Shown in SpamVest setup
MX 20 Shown in SpamVest setup
MX 30 Shown in SpamVest setup
Important: DNS changes can take time to propagate. A pending status does not always mean the setup is wrong, but old MX records or backup routes can allow unfiltered delivery.

Verification

What each setup status means.

Filtering active

MX records are pointing to SpamVest and inbound mail is flowing through the filter.

Pending

DNS may still be propagating, or the new records are not visible everywhere yet.

Needs attention

The destination may be incorrect, required MX records may be missing, or old MX records may still exist.

Troubleshooting

Common setup issues to check first.

Remove previous Microsoft 365, Google Workspace, cPanel, or hosting MX records once SpamVest is ready. Leaving old records in place can allow unfiltered delivery.

MX changes are not always visible immediately. The previous records can continue to be used for a while depending on DNS cache and TTL values.

Check that the clean-mail destination is correct and accepts mail from the filtering service. This is where SpamVest forwards accepted messages after filtering.

Some DNS providers require a trailing dot after hostnames and some do not. If a value is rejected, follow the exact format your DNS provider expects.