Ready to migrate?
User Guide

Mail Routing Guide For Cutover Migration Between Tenants

Ensure zero email loss during domain migration between Microsoft 365 tenants with Cloudiway's Mail Routing solution.

10 min read Updated: 2025-01-27 Microsoft 365 Tenant to Tenant

Introduction

When migrating between Microsoft 365 tenants, one of the most critical challenges is moving your domain name from the source tenant to the target tenant. During this transition, your domain will not exist in either tenant, which means emails sent to your domain would bounce.

Cloudiway's Mail Routing solution is a short-term service designed specifically for this scenario. It ensures that all incoming emails are routed to the correct mailboxes during the domain transition, preventing any email loss.

Additional Service: Mail routing is not included by default and has an additional cost. The setup and testing must be completed prior to your cutover date.

When to Use Mail Routing

  • Migrating between two Microsoft 365 tenants
  • Moving domain names from source to target tenant
  • Cutover migrations where domain detachment is required
  • Any scenario where DNS propagation delays could cause email loss

Complete Tenant to Tenant Solution

Mail routing works seamlessly with our full Microsoft 365 tenant migration solution including mailbox, OneDrive, and Teams migration.

View Solution Page

Why Mail Routing?

Moving domain names between Microsoft 365 tenants can take up to 48 hours. Without mail routing, any emails sent to those domains during this period would receive non-delivery reports (NDRs).

Zero Email Loss
Headers Preserved
Minimal Downtime
SPF/DKIM Compatible

The Domain Migration Challenge

During a cutover migration between Microsoft 365 tenants, you must:

  1. Detach the domain from the source tenant
  2. Wait for the domain to be fully released (can take hours)
  3. Attach the domain to the target tenant
  4. Configure the domain on the target tenant

During steps 2-4, your domain doesn't exist in any tenant. Emails sent during this window would bounce. Mail routing eliminates this risk by acting as an intermediary.

How It Works

Cloudiway's Mail Routing platform acts as a smart relay that holds and delivers emails during the domain transition period.

1

MX Records Point to Cloudiway

Before detaching your domain, you update your MX records to point to Cloudiway's mail routing servers.

2

Emails Received by Cloudiway

All incoming emails are received by Cloudiway's servers. The platform knows the mapping between source and target addresses.

3

Emails Delivered to Target

Cloudiway routes each email to the correct target mailbox based on your migration mapping. Email headers are preserved.

4

Domain Migration Completed

Once your domain is attached to the target tenant, you update MX records to point directly to Microsoft 365.

Transparent Routing: Unlike mail forwarding, mail routing does not modify email headers. This ensures SPF and DKIM validation continues to work correctly and emails don't get flagged as spam.

Prerequisites

Before setting up mail routing for your cutover migration, ensure you have the following:

DNS Management Access

You need access to modify MX records and TTL settings in your DNS provider.

Cloudiway Migration Project

An active Cloudiway migration project with user mapping configured.

Microsoft 365 Admin Access

Global Admin access to both source and target Microsoft 365 tenants.

5 Business Days Lead Time

Contact Cloudiway Services at least 5 business days before your planned cutover.

Step 1: Prepare DNS Settings

The first step is to reduce the TTL (Time To Live) of your MX records. This ensures faster DNS propagation when you switch to the mail routing servers.

Understanding TTL

TTL determines how long DNS records are cached by DNS servers worldwide. A high TTL (like 3600 seconds = 1 hour) means changes take longer to propagate. For migrations, you want the lowest TTL possible.

Recommended TTL Settings

TTL Value Duration Recommendation
300 5 minutes Ideal if available
900 15 minutes Recommended
1800 30 minutes Acceptable
3600+ 1 hour+ Too high - reduce before cutover

Procedure

  1. Log in to your DNS provider's management console
  2. Navigate to your domain's DNS records
  3. Find the MX records for your domain
  4. Reduce the TTL value to the minimum allowed (typically 300-900 seconds)
  5. Save the changes
  6. Wait at least 24-48 hours before proceeding to allow the new TTL to propagate
Important: Reduce the TTL well in advance of your cutover. If you change the TTL at the same time as the MX records, some servers may still have the old records cached for the old TTL duration.

Step 2: Contact Cloudiway Services

Mail routing requires coordination with Cloudiway's services team. This service is not self-service.

What to Provide

  • Planned cutover date and time: When you intend to start the domain migration
  • Domain list: All domains that need mail routing
  • User mapping: Your migration project with source-to-target email mapping
  • Contact information: Technical contacts available during the cutover

Timeline

T-5

5 Business Days Before

Contact Cloudiway Services to request mail routing setup.

T-3

3 Business Days Before

Cloudiway configures the mail routing with your user mapping.

T-1

1 Business Day Before

Test the mail routing configuration. Verify routing works as expected.

T-0

Cutover Day

Execute the cutover with mail routing active.

Support During Cutover: Cloudiway Services will be available during your scheduled cutover window to monitor the mail routing and address any issues.

Step 3: Configure MX Records

When you're ready to begin the cutover, update your MX records to point to Cloudiway's mail routing servers.

MX Record Configuration

Cloudiway will provide you with the specific MX record values during the setup phase. Typically, you will:

1

Update MX Records

Replace your existing Microsoft 365 MX records with the Cloudiway mail routing server address provided by the services team.

2

Wait for Propagation

Wait for DNS propagation. With a low TTL, this should complete within 15-30 minutes for most DNS servers.

3

Verify Mail Flow

Send test emails to verify that mail is being received and routed correctly through Cloudiway.

Mail Routing Active: Once MX records are propagated and verified, you can safely proceed with detaching the domain from the source tenant.

Step 4: Domain Migration

With mail routing active, you can now safely perform the domain migration between tenants.

Migration Sequence

1

Run Final Delta Pass

Perform a final delta migration to sync the latest emails from source to target.

2

Remove Domain from Objects

Run scripts to remove the domain from all user objects, groups, and distribution lists in the source tenant.

3

Detach Domain from Source

Remove the domain from the source Microsoft 365 tenant. This may take several hours to fully release.

4

Add Domain to Target

Add and verify the domain on the target Microsoft 365 tenant.

5

Update User Email Addresses

Update all user mailboxes, groups, and distribution lists with the migrated domain addresses.

Continuous Email Delivery: During this entire process, emails sent to your domain continue to be received by Cloudiway and routed to the correct target mailboxes. Users experience no interruption.

Step 5: Decommission Mail Routing

Once your domain is fully operational on the target tenant, you should stop using the mail routing service.

Decommissioning Checklist

  • Domain is verified and active on the target tenant
  • All user mailboxes have the correct primary email addresses
  • All groups and distribution lists are updated
  • Test emails are being received directly on the target tenant

Procedure

  1. Update MX records to point to the target Microsoft 365 tenant
  2. Wait for DNS propagation (15-30 minutes with low TTL)
  3. Verify emails are being delivered directly to Microsoft 365
  4. Notify Cloudiway Services to deactivate mail routing
  5. Optionally, restore your TTL to a standard value (3600 seconds)
Don't Forget: Mail routing is a paid service. Make sure to notify Cloudiway to stop the service once you've completed the migration to avoid unnecessary charges.

Forwarding vs Mail Routing

Understanding the difference between mail forwarding and mail routing is crucial for choosing the right solution.

Comparison Table

Feature Mail Forwarding Mail Routing
Headers Modified Yes No
SPF Validation Can fail Preserved
DKIM Validation Can fail Preserved
Spam Risk Higher Lower
Original Sender Visible Depends Yes
Migration Use Case Not recommended Recommended

Mail routing is the preferred solution for migrations because it acts as a transparent proxy, preserving the original email integrity. This ensures that emails don't get incorrectly flagged as spam due to failed SPF or DKIM checks.

Troubleshooting

Common issues and solutions when using Cloudiway Mail Routing:

MX records not propagating

DNS propagation can take time depending on your TTL settings. Use tools like nslookup or dig to verify MX records from different DNS servers. If you reduced TTL recently, you may need to wait for the old TTL duration to expire first.

Emails not being delivered to target

Verify that the user mapping in your migration project is correct. The target email address must be accessible. Check that the target mailbox has a valid license and is not in a disabled state.

Domain won't detach from source tenant

The domain must be removed from all objects in the tenant including users, groups, distribution lists, and shared mailboxes. Use PowerShell scripts to identify and remove the domain from all objects. Some objects may have the domain as their primary address which must be changed first.

Emails being marked as spam after migration

Ensure you've updated SPF, DKIM, and DMARC records for your domain on the target tenant. The DNS records should reflect the new Microsoft 365 tenant's configuration.

Cannot verify domain on target tenant

The domain must be fully released from the source tenant before it can be added to the target. This can take several hours. If you still have issues, check that there are no lingering references to the domain in Azure AD.

Ready to Plan Your Migration?

Get a free migration quote in minutes — entirely self-service.