Business email on your own domain, set up right.

We set up Microsoft 365 or Google Workspace for South Florida offices, move your old mail across without losing a message, and configure SPF, DKIM and DMARC so your email reaches the inbox and nobody else can send it in your name.

Instead of: [email protected]

Use: [email protected]

People read the part after the @ first. It tells them who they are dealing with before they open the message.

SPF, DKIM and DMARC, explained with one envelope

Every email you send is checked three times before it reaches an inbox. Most owners never think about these checks until invoices land in spam or a scammer sends a fake one in their name. Follow the envelope, one checkpoint at a time.

Why it matters now. Since 2024, Gmail and Yahoo require bulk senders to have all three records in place, and Microsoft set similar rules for Outlook.com in 2025. Smaller senders without them are more likely to be filtered too.

Your domain's records

Your email leaves your domain

You drop a letter in the mailbox with your business on the return address. Anyone can write any return address, and that is exactly the problem.

When you send from [email protected], your provider hands the message to the recipient's mail server. That server has never met you, so it looks up your domain's public DNS records to decide whether to trust the message.

With the records: the receiving server can confirm who you are at every checkpoint that follows.

Without them: the receiving server only has the return address to go on, and return addresses are easy to fake.

SPF: the guest list

SPF is the guest list at the door. It names every service allowed to send email for your domain: your mailbox provider, your website's contact form, your booking or billing software.

Sender Policy Framework is one text record in your domain's DNS. The receiving server compares the server that delivered your message against that list.

With the records: the sending server is on the list, so the message moves on.

Without them: the message arrives as a stranger. A list that forgets one of your tools causes the same trouble, and it is an easy mistake to miss.

DKIM: the wax seal

DKIM is a wax seal pressed with a stamp only your domain owns. If anyone opens the letter and changes a word on the way, the seal no longer matches.

DomainKeys Identified Mail adds a digital signature to every message. Your provider keeps the private key, and the matching public key sits in your DNS so any receiving server can check the seal.

With the records: the seal matches, so the message is untouched and really came from your domain.

Without them: there is no seal. The receiver cannot tell whether the message was changed or who stands behind it.

DMARC: instructions for the post office

DMARC is a note you leave with every post office: if a letter claims to be from us and fails the guest list and the seal, here is what to do with it.

The record sets a policy of none (just report it), quarantine (send it to spam) or reject (refuse it). It also sends you reports, so you can see who is sending email in your name. We start by reading the reports, then tighten the policy once every real sender passes.

With the records: your real email passes and matches your From address. Fakes that use your exact domain get quarantined or refused.

Without them: there are no instructions. Each provider guesses, and a fake invoice with your name on it has a much better chance of getting through.

Where the envelope lands

The receiving server adds up what it saw at each checkpoint, runs its own filters, and decides: inbox or spam folder.

Passing all three is not a promise of the inbox, because content and sending habits still count. It removes the most common technical reason good email gets filtered, and it makes your domain far harder to impersonate.

With the records: the message lands in the inbox with your name on it.

Without them: the message is filtered to spam or rejected, and your customer never sees the appointment reminder.

Microsoft 365 or Google Workspace?

Both are secure, mature business email platforms, and both run on your own domain. The right one depends on how your team already works. This is the same honest comparison we walk through in a consult.

Microsoft 365

A good fit if

  • Your team lives in Word, Excel and Outlook, and trades files with partners who do too.
  • You want the desktop Office apps as well as the web versions.
  • You meet in Teams, or your vendors and clients do.
  • You want laptops and phones managed from the same place as email.

What we set up

Mailboxes, aliases and shared mailboxes, Outlook on every computer and phone, Teams, OneDrive and SharePoint for shared files, and sign-in security policies.

Google Workspace

A good fit if

  • Your team works mostly in the browser and already knows Gmail.
  • You write and edit documents together at the same time.
  • You want a simple admin console with fewer moving parts.
  • You meet in Google Meet and plan around shared calendars.

What we set up

Gmail on your domain, groups and aliases, shared calendars, shared drives for team files, Meet, and sign-in security policies.

Either way. Both work well on iPhone and Android, and both offer a business associate agreement for healthcare use. What causes trouble is a half-and-half office, with some staff on one platform and some on the other. We help you pick one and set it up completely.

Moving your email without losing anything

Think of it as moving offices with mail forwarding in place. Nothing gets thrown out, the old mailbox stays open until the new one is confirmed, and nobody misses a letter on moving day.

Receptionist with a headset working through her inbox at the front desk
  1. Before the move

    • List every mailbox, alias and shared address, including the ones nobody remembers creating.
    • Find every tool that sends email for you: website forms, booking, billing, scanners and copiers.
    • Shorten how long the internet remembers your current mail settings (the DNS TTL), so the switch takes effect quickly.
    • Create the new accounts and copy old mail, contacts and calendars in the background.
  2. Switch day

    • Point your domain's mail records (MX) to the new platform, outside your business hours.
    • Publish SPF, DKIM and DMARC for the new setup.
    • Run a final sync to catch anything that arrived during the switch.
    • Send and receive test messages from outside the company.
  3. The morning after

    • Reconnect phones and laptops, person by person, and check email signatures.
    • Recreate shared mailboxes, forwarding rules and group addresses.
    • Keep the old mailboxes intact until you confirm nothing is missing.
    • Watch the DMARC reports for any sending tool that was missed.

Business email security basics

A business email account is a favorite target, because it can reset passwords, approve payments and send invoices. These settings close the doors scammers actually use.

Attorney writing an email on her laptop in a bright law office

Multi-factor sign-in

A password plus a second proof, like an approval on your phone. A stolen password alone stops being enough, the same way a copied key does not help a burglar who also needs the alarm code. We turn it on for everyone, owner included.

Phishing and spoofing protection

We tune the platform's built-in filtering for suspicious links, attachments and lookalike senders, and DMARC stops anyone from sending as your exact domain. Filters miss things, so we also show your team the warning signs of a fake.

Shared mailboxes, not shared passwords

Addresses like info@ or billing@ become shared mailboxes that several people open with their own sign-in. You can see who replied, and nobody passes a password around the front desk.

Once a shared inbox is organized, an assistant can help sort messages and draft replies. See AI Consulting.

When someone leaves

A former employee's account is where the risk hides. Our offboarding runs in this order:

  1. Block sign-in and sign them out of every device.
  2. Keep their mail and route new messages to a manager.
  3. Remove the account from their personal phone.
  4. Hand over their files and shared calendars.

Offices with sensitive information

Medical, dental and med spa offices need a HIPAA-aware setup: a signed business associate agreement with the provider, encryption for messages that carry patient details, and clear rules for what never goes by email. Law firms need retention and careful sharing of case files.

For laptops, Wi-Fi, backups and the rest of the office, see IT & Security.

Business email questions, answered

Don't see yours? Ask us anything.

Email us your question
How long does it take to set up business email?

Planning starts with a short call, and the switch itself is scheduled outside your business hours. The exact timeline depends on how many mailboxes you have and how much old mail is moving, and you get a written schedule before anything changes.

Will we lose old emails, contacts or calendars?

No. We copy mail, contacts and calendars to the new platform, run a final sync after the switch, and keep the old mailboxes until you confirm everything is there.

Why does our email go to spam?

Usually missing or incomplete SPF, DKIM or DMARC records, or a tool sending in your name that is not on the SPF list. Sometimes it is the content itself. We check the records first, because that is a fix we can confirm from the outside.

Can you guarantee our email never lands in spam?

No, and be careful with anyone who does. Every receiving provider runs its own filters, and content and sending habits matter. What we can do is set up authentication correctly, test it from outside your company and fix what the reports show.

Can someone send email pretending to be our business?

They can try. With DMARC set to quarantine or reject, messages that fake your exact domain get filtered or refused. Lookalike domains with one letter changed are a different trick, which is why staff awareness still matters.

Can we keep using Gmail or Outlook the way we do now?

Yes. Google Workspace uses the Gmail your team already knows, and Microsoft 365 uses Outlook. The difference is that addresses end in your domain and the business, not one person, owns every account.

Is business email safe for patient information?

Only when it is set up for it. We use HIPAA-aware configurations with a signed business associate agreement, encryption for sensitive messages and clear rules for staff, and we tell you what should never go by email.

Let's talk about your business.

Tell us what you need. We'll get back to you soon, in English or Spanish.

We only use your details to reply to you.