Mail Routing Guide For Cutover Migration Between Tenants
Ensure zero email loss during domain migration between Microsoft 365 tenants with Cloudiway's Mail Routing solution.
Introduction
When migrating between Microsoft 365 tenants, one of the most critical challenges is moving your domain name from the source tenant to the target tenant. During this transition, your domain will not exist in either tenant, which means emails sent to your domain would bounce.
Cloudiway's Mail Routing solution is a short-term service designed specifically for this scenario. It ensures that all incoming emails are routed to the correct mailboxes during the domain transition, preventing any email loss.
When to Use Mail Routing
- Migrating between two Microsoft 365 tenants
- Moving domain names from source to target tenant
- Cutover migrations where domain detachment is required
- Any scenario where DNS propagation delays could cause email loss
Complete Tenant to Tenant Solution
Mail routing works seamlessly with our full Microsoft 365 tenant migration solution including mailbox, OneDrive, and Teams migration.
View Solution PageWhy Mail Routing?
Moving domain names between Microsoft 365 tenants can take up to 48 hours. Without mail routing, any emails sent to those domains during this period would receive non-delivery reports (NDRs).
The Domain Migration Challenge
During a cutover migration between Microsoft 365 tenants, you must:
- Detach the domain from the source tenant
- Wait for the domain to be fully released (can take hours)
- Attach the domain to the target tenant
- Configure the domain on the target tenant
During steps 2-4, your domain doesn't exist in any tenant. Emails sent during this window would bounce. Mail routing eliminates this risk by acting as an intermediary.
How It Works
Cloudiway's Mail Routing platform acts as a smart relay that holds and delivers emails during the domain transition period.
MX Records Point to Cloudiway
Before detaching your domain, you update your MX records to point to Cloudiway's mail routing servers.
Emails Received by Cloudiway
All incoming emails are received by Cloudiway's servers. The platform knows the mapping between source and target addresses.
Emails Delivered to Target
Cloudiway routes each email to the correct target mailbox based on your migration mapping. Email headers are preserved.
Domain Migration Completed
Once your domain is attached to the target tenant, you update MX records to point directly to Microsoft 365.
Prerequisites
Before setting up mail routing for your cutover migration, ensure you have the following:
DNS Management Access
You need access to modify MX records and TTL settings in your DNS provider.
Cloudiway Migration Project
An active Cloudiway migration project with user mapping configured.
Microsoft 365 Admin Access
Global Admin access to both source and target Microsoft 365 tenants.
5 Business Days Lead Time
Contact Cloudiway Services at least 5 business days before your planned cutover.
Step 1: Prepare DNS Settings
The first step is to reduce the TTL (Time To Live) of your MX records. This ensures faster DNS propagation when you switch to the mail routing servers.
Understanding TTL
TTL determines how long DNS records are cached by DNS servers worldwide. A high TTL (like 3600 seconds = 1 hour) means changes take longer to propagate. For migrations, you want the lowest TTL possible.
Recommended TTL Settings
| TTL Value | Duration | Recommendation |
|---|---|---|
| 300 | 5 minutes | Ideal if available |
| 900 | 15 minutes | Recommended |
| 1800 | 30 minutes | Acceptable |
| 3600+ | 1 hour+ | Too high - reduce before cutover |
Procedure
- Log in to your DNS provider's management console
- Navigate to your domain's DNS records
- Find the MX records for your domain
- Reduce the TTL value to the minimum allowed (typically 300-900 seconds)
- Save the changes
- Wait at least 24-48 hours before proceeding to allow the new TTL to propagate
Step 2: Contact Cloudiway Services
Mail routing requires coordination with Cloudiway's services team. This service is not self-service.
What to Provide
- Planned cutover date and time: When you intend to start the domain migration
- Domain list: All domains that need mail routing
- User mapping: Your migration project with source-to-target email mapping
- Contact information: Technical contacts available during the cutover
Timeline
5 Business Days Before
Contact Cloudiway Services to request mail routing setup.
3 Business Days Before
Cloudiway configures the mail routing with your user mapping.
1 Business Day Before
Test the mail routing configuration. Verify routing works as expected.
Cutover Day
Execute the cutover with mail routing active.
Step 3: Configure MX Records
When you're ready to begin the cutover, update your MX records to point to Cloudiway's mail routing servers.
MX Record Configuration
Cloudiway will provide you with the specific MX record values during the setup phase. Typically, you will:
Update MX Records
Replace your existing Microsoft 365 MX records with the Cloudiway mail routing server address provided by the services team.
Wait for Propagation
Wait for DNS propagation. With a low TTL, this should complete within 15-30 minutes for most DNS servers.
Verify Mail Flow
Send test emails to verify that mail is being received and routed correctly through Cloudiway.
Step 4: Domain Migration
With mail routing active, you can now safely perform the domain migration between tenants.
Migration Sequence
Run Final Delta Pass
Perform a final delta migration to sync the latest emails from source to target.
Remove Domain from Objects
Run scripts to remove the domain from all user objects, groups, and distribution lists in the source tenant.
Detach Domain from Source
Remove the domain from the source Microsoft 365 tenant. This may take several hours to fully release.
Add Domain to Target
Add and verify the domain on the target Microsoft 365 tenant.
Update User Email Addresses
Update all user mailboxes, groups, and distribution lists with the migrated domain addresses.
Step 5: Decommission Mail Routing
Once your domain is fully operational on the target tenant, you should stop using the mail routing service.
Decommissioning Checklist
- Domain is verified and active on the target tenant
- All user mailboxes have the correct primary email addresses
- All groups and distribution lists are updated
- Test emails are being received directly on the target tenant
Procedure
- Update MX records to point to the target Microsoft 365 tenant
- Wait for DNS propagation (15-30 minutes with low TTL)
- Verify emails are being delivered directly to Microsoft 365
- Notify Cloudiway Services to deactivate mail routing
- Optionally, restore your TTL to a standard value (3600 seconds)
Forwarding vs Mail Routing
Understanding the difference between mail forwarding and mail routing is crucial for choosing the right solution.
Comparison Table
| Feature | Mail Forwarding | Mail Routing |
|---|---|---|
| Headers Modified | Yes | No |
| SPF Validation | Can fail | Preserved |
| DKIM Validation | Can fail | Preserved |
| Spam Risk | Higher | Lower |
| Original Sender Visible | Depends | Yes |
| Migration Use Case | Not recommended | Recommended |
Mail routing is the preferred solution for migrations because it acts as a transparent proxy, preserving the original email integrity. This ensures that emails don't get incorrectly flagged as spam due to failed SPF or DKIM checks.
Troubleshooting
Common issues and solutions when using Cloudiway Mail Routing:
MX records not propagating
DNS propagation can take time depending on your TTL settings. Use tools like nslookup or dig to verify MX records from different DNS servers. If you reduced TTL recently, you may need to wait for the old TTL duration to expire first.
Emails not being delivered to target
Verify that the user mapping in your migration project is correct. The target email address must be accessible. Check that the target mailbox has a valid license and is not in a disabled state.
Domain won't detach from source tenant
The domain must be removed from all objects in the tenant including users, groups, distribution lists, and shared mailboxes. Use PowerShell scripts to identify and remove the domain from all objects. Some objects may have the domain as their primary address which must be changed first.
Emails being marked as spam after migration
Ensure you've updated SPF, DKIM, and DMARC records for your domain on the target tenant. The DNS records should reflect the new Microsoft 365 tenant's configuration.
Cannot verify domain on target tenant
The domain must be fully released from the source tenant before it can be added to the target. This can take several hours. If you still have issues, check that there are no lingering references to the domain in Azure AD.
Get a free migration quote in minutes — entirely self-service.