Ready to migrate?
User Guide

Mail Forwarders User Guide

Configure mail forwarders for staged migrations to ensure seamless email delivery during coexistence periods.

12 min read Updated: 2025-01-27 Migration Tools

Introduction

Cloudiway's Forwarder feature enables seamless email delivery during staged migrations between cloud tenants. When migrating large organizations in batches over several weeks, forwarders ensure that users continue to receive their emails regardless of whether they've been migrated or not.

During a staged migration, some users will be on the source platform while others have already moved to the target. Forwarders create a bridge between these two environments, routing emails to the correct mailbox based on the user's migration status.

Supported Migration Scenarios

  • Microsoft 365 to Microsoft 365 (tenant-to-tenant)
  • Google Workspace to Microsoft 365
  • Microsoft 365 to Google Workspace
  • Google Workspace to Google Workspace
  • Exchange On-Premises to Microsoft 365

Complete Migration Solutions

Forwarders work seamlessly with our complete migration solutions including Free/Busy coexistence and GAL synchronization.

View Migration Solutions

When to Use Forwarders

Forwarders are designed for specific migration scenarios. Understanding when to use them will help you plan your migration effectively.

Use Forwarders When:

Staged Migration
Multiple Batches
Multi-Week Projects
Coexistence Required

Do NOT Use Forwarders When:

  • Big Bang / Cutover Migration: If all users are migrated at once over a weekend, forwarders add unnecessary complexity
  • Short Migration Window: For migrations completed in a few days, forwarders may not be needed
  • Domain Transfer Only: Use Mail Routing instead for the 24-48 hour domain transfer window
Rule of Thumb: If your migration will span more than one week with users being cut over in batches, you should consider using forwarders.

How Forwarders Work

Forwarders manage email flow during the coexistence period by directing emails to the correct mailbox based on the user's migration status.

Before Cutover (User Not Yet Migrated)

1

Target Mailbox Created

The user's mailbox is provisioned and licensed in the target tenant with a technical domain address.

2

Forward to Source Enabled

A forwarder is configured on the target mailbox to redirect any incoming mail back to the source mailbox.

3

User Works in Source

The user continues to work normally in their source mailbox. Any mail accidentally sent to the target is forwarded back.

After Cutover (User Migrated)

1

Forwarder Flipped

The forwarder is removed from the target and added to the source mailbox, now forwarding to the target.

2

User Works in Target

The user now works in the target mailbox. Any mail still arriving at the source is forwarded to the target.

3

No Email Loss

Regardless of where emails are sent, they always reach the user's active mailbox.

Mail Flow Diagram

Before Cutover:

External Sender → Source Mailbox ([email protected]) ✓

External Sender → Target Mailbox ([email protected]) → Forwarded → Source ✓

After Cutover:

External Sender → Target Mailbox ([email protected]) ✓

External Sender → Source Mailbox (old address) → Forwarded → Target ✓

Prerequisites

Before configuring forwarders, ensure the following requirements are met:

Target Mailboxes Provisioned

User mailboxes must be created in the target tenant before setting up forwarders.

Licenses Assigned

Target mailboxes must have valid licenses (Exchange Online, Google Workspace, etc.).

Technical Domain Configured

If migrating the primary domain, a technical intermediate domain must be set up.

Admin Access

Global Admin or Exchange Admin access to both source and target tenants.

Timing Consideration: You can provision mailboxes at the start of the project for all users, or just before each batch is migrated. Provisioning early allows you to test forwarders before the actual migration.

Configure Forwarders

Cloudiway provides an automated way to configure forwarders through the migration platform.

Enable Forwarders in Cloudiway

1

Access Project Settings

Navigate to your migration project in the Cloudiway platform and open the project settings.

2

Enable Forwarder Settings

Set Forwarder Settings to Enable to access the configuration options.

3

Configure Alias Options

For same-domain migrations, enable alias creation to allow Cloudiway to create the necessary aliases in both source and target mailboxes automatically.

4

Enable Target-to-Source Forwarding

Enable this option to ensure that target mailboxes receive a forwarder back to the source mailbox initially. This is the recommended setting.

Alias Conflicts: When enabling automatic alias creation, ensure there are no existing alias conflicts in your tenants that could cause issues.

Forwarder Options

Option Description Recommendation
Create Aliases Automatically creates email aliases in both tenants Enable for same-domain migrations
Target to Source Forward Creates forwarder from target back to source initially Enable (recommended)
Keep Local Copy Keeps a copy in the forwarding mailbox Disable (prevents duplicates)

Domain Configuration

If you're migrating your primary domain to the target tenant, you'll need to use a technical intermediate domain during the coexistence period.

What is a Technical Domain?

A technical domain is a temporary email domain used for the target mailboxes during coexistence. Since a domain can only exist in one tenant at a time, you cannot use your primary domain on the target until it's been removed from the source.

Technical Domain Options

Option Example Pros/Cons
Built-in Tenant Domain tenant.onmicrosoft.com Free, always available. May look unprofessional.
Purchased Domain company-migration.com More professional. Requires purchase and DNS setup.

Cross-Platform Domain Registration

When migrating between Google Workspace and Microsoft 365, you need to register the target technical domain in the source tenant to prove ownership.

For Google Workspace to Microsoft 365:

  1. In Google Admin Console, go to Account > Domains
  2. Add the Microsoft 365 technical domain (e.g., tenant.onmicrosoft.com) as a user alias domain
  3. Add the TXT record provided by Google to your DNS (or Microsoft 365 admin center for onmicrosoft.com domains)
  4. Verify the domain ownership

For Microsoft 365 to Google Workspace:

  1. In Microsoft 365 Admin Center, go to Settings > Domains
  2. Add the Google Workspace technical domain
  3. Add the TXT record provided by Microsoft to your DNS
  4. Verify the domain ownership
onmicrosoft.com Verification: If using the onmicrosoft.com domain as the target technical domain, you can add the Google TXT verification record directly in the Microsoft 365 admin center under the domain's DNS settings.

Cutover Process

When a user or batch of users is ready to switch to the target platform, you need to "flip" the forwarders.

Cutover Steps

1

Complete Data Migration

Ensure the user's mailbox data has been fully migrated to the target, including a final delta pass to capture recent emails.

2

Flip the Forwarder

In Cloudiway, select the user(s) and use the cutover action to flip the forwarder direction. This removes the target-to-source forwarder and creates a source-to-target forwarder.

3

Update User Configuration

Update the user's email client (Outlook, mobile devices) to connect to the target mailbox.

4

Verify Mail Flow

Send test emails to verify that the user is receiving mail in the target mailbox.

Post-Cutover Cleanup

After all users have been migrated and the domain has been transferred to the target tenant:

  • Remove forwarders from the source tenant
  • Disable or delete source mailboxes (after retention period)
  • Update MX records to point to the target tenant
  • Remove the technical domain aliases if no longer needed
Best Practice: Keep the source forwarders active for at least 30 days after cutover to catch any stragglers or automated systems still sending to old addresses.

Forwarders vs Mail Routing

Cloudiway offers two solutions for managing mail flow during migrations. Understanding when to use each is important.

Comparison Table

Feature Forwarders Mail Routing
Duration Weeks to months 24-48 hours max
Use Case Staged migration coexistence Domain transfer cutover
Headers Modified Yes (forwarded) No (transparent)
MX Change Required No Yes
Per-User Control Yes No (all or nothing)
Additional Cost Included in migration Separate service fee

When to Use Both

In many large migrations, you'll use both solutions:

  1. Forwarders during staged migration: Use forwarders throughout the multi-week migration period as users are migrated in batches
  2. Mail Routing for domain transfer: At the end, use mail routing for the 24-48 hour window when you transfer the primary domain to the target tenant

Exchange On-Premises Forwarders

When migrating from Exchange On-Premises to Microsoft 365, you may need to create forwarders manually or via PowerShell.

PowerShell Method

Use the Exchange Management Shell to create forwarders for users migrated to Microsoft 365:

Step 1: Create Mail Contact

New-MailContact -ExternalEmailAddress 'SMTP:[email protected]' -Name 'user_forward'

Step 2: Hide from Address Book

Set-MailContact user_forward -HiddenFromAddressListsEnabled $true

Step 3: Enable Forwarding

Set-Mailbox user -ForwardingSmtpAddress [email protected]
Critical Warning: Do NOT check "Deliver Message to Both Forwarding Address and Mailbox" in the Exchange Admin Center. This would create duplicate emails when running delta migrations.

Exchange Admin Center Method

  1. Open Exchange Admin Center
  2. Navigate to Recipients > Mailboxes
  3. Select the mailbox and click Edit
  4. Go to Mailbox Features tab
  5. Under Mail Flow, click View details
  6. Enable forwarding and specify the target address
  7. Ensure "Deliver message to both forwarding address and mailbox" is unchecked

Troubleshooting

Common issues and solutions when working with forwarders:

Emails are being duplicated

This usually occurs when "Deliver to both forwarding address and mailbox" is enabled. Check both the source and target mailbox forwarding settings and ensure this option is disabled. Also verify that you don't have multiple forwarders creating a loop.

Forwarder not working - emails bounce

Verify that the target mailbox exists and has a valid license. Check that the forwarding address is correct and that there are no transport rules blocking the forwarding. Also ensure external forwarding is allowed in your tenant's security settings.

Cannot create alias - conflict error

An alias with the same address already exists in the tenant. Search for the conflicting object (mailbox, group, contact) and remove or rename the alias before creating the new one.

Forwarded emails marked as spam

When emails are forwarded, the SPF check may fail because the sending server doesn't match the original sender's SPF record. Consider using transport rules to bypass spam filtering for forwarded mail, or use Mail Routing instead for the final cutover.

External forwarding is blocked

Microsoft 365 may block external forwarding by default for security. Check the anti-spam outbound policy in the Security & Compliance Center and add exceptions for your migration scenario if needed.

Technical domain not verified

For cross-platform migrations, ensure you've added the TXT verification record to your DNS. For onmicrosoft.com domains, add the record in the Microsoft 365 admin center. DNS propagation can take up to 48 hours.

Ready to Start Your Migration?

Get a free migration quote in minutes — entirely self-service.