Skip to content
English
  • There are no suggestions because the search field is empty.

Mimecast: Allowing Emails Sent by Apxium

If your organisation uses Mimecast, emails sent by Apxium may be blocked by Mimecast's anti-spoofing policy.

Why does this happen?

Apxium sends emails using the nominated sender email address configured for your account. As a result, messages sent by Apxium may appear to originate from your organisation's email domain.

Mimecast's anti-spoofing policies may block these messages because they are being sent on behalf of your domain from infrastructure outside Mimecast.

Apxium uses Amazon Web Services (AWS) to send emails and does not use a dedicated static sending IP address. Therefore, creating a Mimecast bypass rule based on a specific Apxium sending IP address is not recommended.

Recommended Configuration

Where possible, we recommend configuring Mimecast to validate Apxium emails using DKIM rather than relying on the sending IP address.

This allows Mimecast to verify that an email sent on behalf of your domain has been legitimately authorised, without requiring Apxium to send from a fixed IP address.

If DKIM-based validation cannot be used, Mimecast can also be configured with an SPF-based anti-spoofing bypass. In this configuration, your IT administrator can allow messages from the nominated Apxium sender where the message passes the appropriate SPF validation, such as for:

  • amazonses.com
  • spf.apxium.com

For instructions on configuring an SPF bypass in Mimecast, refer to the Mimecast documentation:

https://mimecastsupport.zendesk.com/hc/en-us/articles/34000752076563-Policies-Anti-Spoofing-SPF-Bypass#h_01JAFSDM0951NPV896YNJMZB55

Alternative: Restrict the bypass to specific recipients

If required, your Mimecast administrator may create a more restrictive bypass that applies only to emails:

  • sent from your nominated Apxium sender address or domain; and

  • delivered to specific recipients within your organisation.

For example, you could create a Mimecast group containing only the staff members who need to receive Apxium-generated emails.

This may be useful if you do not want the bypass to apply to all users in your organisation.

Why is this important?

Apxium may need to send system-generated emails to members of your organisation.

For example, staff may receive notifications when a client does not have an email address or when another event requires staff attention. If Mimecast blocks messages sent by Apxium, these notifications may not reach the intended recipients.

If your organisation expects staff to receive emails generated by Apxium, we recommend asking your IT administrator to review the Mimecast configuration.

Enable Custom Mail From Domain

We also recommend enabling Custom Mail From Domain in Apxium.

In your Apxium sandbox, navigate to: Admin > Email Setup

Enabling this feature generates two additional DNS records that need to be added to your domain's DNS configuration.

Once configured, Custom Mail From Domain allows the email infrastructure used by Apxium to send messages with improved authentication and domain alignment. This can improve email deliverability and reduce the likelihood of messages being rejected or classified as spoofed.

Recommended Approach

For the best email deliverability:

  1. Enable Custom Mail From Domain in Admin > Email Setup and configure the generated DNS records.
  2. Configure Mimecast to recognise DKIM-authenticated Apxium emails, where possible.
  3. If DKIM validation cannot be used for the anti-spoofing policy, configure an appropriate SPF bypass.
  4. Where necessary, restrict the bypass to the nominated Apxium sender and the specific staff members who need to receive Apxium emails.

Your IT administrator or email service provider should be able to assist with the required Mimecast and DNS configuration.