All guides

Business IT Support

Business email setup: plan Microsoft 365 or Google Workspace without breaking mail

A business mailbox depends on four ownership layers: the domain registrar, authoritative DNS, the Microsoft 365 or Google Workspace tenant, and the people who control billing, administrator roles, MFA, and recovery. Map those layers and every mail-dependent workflow before changing MX. A successful sign-in or copied inbox does not prove that aliases, calendars, scanners, website forms, authentication, and recovery will work after cutover.

Business email setup troubleshooting guide

Guide updated

Start with simple checks. Get expert help when the fix needs more.

Common symptoms

  • The business uses personal or ISP email and wants addresses on its own domain without losing control of the domain.
  • Microsoft 365 or Google Workspace exists, but billing ownership, administrator roles, recovery contacts, licenses, mailboxes, aliases, or shared addresses are unclear.
  • A move from another provider must preserve the mail, calendars, contacts, shared workflows, devices, and addresses people actually use.
  • Messages fail, land in spam, or appear spoofed after an MX, SPF, DKIM, DMARC, forwarding, website, CRM, scanner, or bulk-sender change.
  • Outlook, Gmail, phones, calendars, shared mailboxes, or delegated access behave differently for different users after setup.
  • A new employee, departing employee, domain change, rebrand, merger, or provider cancellation needs a controlled handoff rather than an improvised account change.

Quick checks

  • Confirm the legal or authorized business owner, registrar account, DNS host, current mail provider, target tenant, billing owner, and at least one working recovery path. Do not begin a cutover when one vendor or former worker controls an unknown layer.
  • Inventory every user mailbox, shared mailbox, alias, group, forwarding address, calendar, contact set, archive, phone, Outlook profile, scanner, printer, website form, CRM, invoicing tool, newsletter service, and application that sends as the domain.
  • Export or record the approved current DNS zone and mail settings, including MX, Autodiscover or provider discovery records, SPF, DKIM selectors, DMARC, verification records, and any legitimate third-party senders. Keep tenant IDs, DNS exports, addresses, and screenshots in the private job record.
  • Decide what each address actually needs. A licensed user mailbox, shared mailbox, alias, distribution group, and external forward have different ownership, sign-in, retention, and delivery behavior; do not replace one with another by guesswork.
  • Provision and license the intended target users and mailboxes before directing new mail to the target. Microsoft specifically warns that an MX change directs all new domain mail to Microsoft 365 while old mail remains at the previous host unless it is migrated.
  • Pilot the migration and document what the chosen vendor tool excludes. Depending on the source and method, rules, signatures, permissions, categories, local archives, delegated access, calendars, contacts, and autocomplete data may need separate work.
  • Treat SPF, DKIM, and DMARC as a sender inventory and verification project, not three copied DNS strings. Keep one valid SPF record, enable and verify DKIM for the active provider, then roll out DMARC gradually while reviewing reports and accounting for every authorized sender.
  • Use named administrator accounts, appropriate least-privilege roles, MFA, owner-controlled recovery, and documented emergency access appropriate to the platform. The technician should not become the permanent sole owner or retain a customer's password or recovery code.
  • Choose a cutover window, lower DNS TTL only when the responsible provider's plan calls for it, define the last synchronization, keep the previous service active, and write the rollback condition. Test external-to-internal, internal-to-external, replies, aliases, shared addresses, calendars, mobile devices, and approved application senders.
  • Do not delete the old tenant, cancel the old provider, remove the old administrator, purge mail, change the primary domain, remove and rebuild every Outlook profile, or enforce a DMARC reject policy until the owner has accepted the test results, retention needs, recovery path, and rollback boundary.

When to call

  • A small business needs its first professional domain email, Microsoft 365 or Google Workspace tenant, users, shared addresses, devices, or documented owner handoff.
  • A migration, domain change, rebrand, new or departing employee, or multi-device rollout needs an inventory, pilot, cutover window, test plan, and rollback decision.
  • Mail delivery depends on several vendors or senders, or MX, SPF, DKIM, DMARC, forwarding, aliases, scanners, website forms, and application mail no longer agree.
  • Use the email provider, registrar, DNS host, application vendor, or an authorized specialist when tenant recovery, domain ownership, compliance, retention, legal hold, bulk-mail reputation, hybrid Exchange, or an unsupported migration owns the next step.
  • Move immediately to the business-email-compromise response path when you find unauthorized forwarding, unfamiliar rules or administrators, unexpected MFA or recovery changes, fraudulent mail, exposed customer data, or money in motion.

How Tech Genie helps

Solve the problem and make it easier next time.

Tech Genie identifies the cause, handles the agreed work, and explains what changed and what to do next.

Build a private ownership and dependency map for the domain, DNS, tenant, billing, administrators, users, addresses, devices, and approved services that send or receive mail.
Separate a one-device Outlook or Gmail setup from a domain cutover, mailbox migration, sender-authentication project, account-security incident, or vendor-controlled recovery.
Plan and execute approved reversible changes in stages, with owner-controlled credentials and MFA, a pilot, non-sensitive test messages, evidence of delivery, and a written rollback point.
Provide a service summary showing who owns each system, what migrated, what did not, which records and workflows were verified, what remains active temporarily, and the next scheduled review.

FAQ

Quick answers before booking.

Should I choose Microsoft 365 or Google Workspace?

Choose around the business's real workflow, not a generic winner. Microsoft 365 often fits organizations centered on Outlook, Exchange, Office, shared mailboxes, and Microsoft administration; Google Workspace often fits browser-first Gmail, Calendar, Drive, and Google administration. Licenses, existing data, devices, shared workflows, compliance needs, and the person who will administer the system matter more than a feature checklist.

What happens when the MX record changes?

MX records tell other mail systems where to deliver new messages for the domain. Changing MX does not move old mail, calendars, contacts, rules, signatures, or local archives. Target mailboxes should exist first, the old provider should remain available during validation, and the business needs a tested rollback path.

Do I need SPF, DKIM, and DMARC?

They work together to authenticate legitimate senders and tell receiving systems how to handle mail that fails alignment. First inventory every service that sends as the domain, keep one correct SPF record, enable and verify DKIM, then introduce DMARC gradually and review reports before stronger enforcement. A copied record that omits a scanner, website, CRM, or newsletter tool can disrupt legitimate mail.

Will an email migration move everything?

Do not assume it will. Coverage depends on the source, destination, and migration method. Messages may move while rules, signatures, calendar permissions, delegated access, categories, local archives, autocomplete data, or some contacts do not. Run a pilot, compare counts and representative folders, and document every excluded workflow before cutover.

Should I share my email password or MFA code with a technician?

No. Do not send passwords, MFA codes, recovery codes, private email contents, attachments, DNS exports, tenant identifiers, or customer records through a booking form, text, or AI chat. The authorized owner signs in and handles MFA directly. Any ongoing administrator access should be a named, least-privilege role the business can review and revoke.

Keep troubleshooting

Tech Genie is not a licensed contractor. Construction-related work is limited to casual, minor, or inconsequential projects totaling less than $1,000 for labor, materials, and all other items, requiring no building permit, and performed without employees or paid helpers.