Skip to content

Email Security: document internal domains and the Additional internal domains setting - #457

Merged
maximelb merged 3 commits into
masterfrom
feat/mailsec-internal-domains
Sep 29, 2026
Merged

maximelb merged 3 commits into
masterfrom
feat/mailsec-internal-domains

Conversation

@maximelb

Copy link
Copy Markdown
Contributor

Adds an Internal Domains page to the Email Security docs.

  • Explains message direction (internal / inbound / outbound) and why it matters.
  • Explains how your organization's domains are detected: protected mailbox domains, alias and send-as domains from Microsoft 365 SMTP proxy addresses and Google Workspace aliases, and the domain of the mailbox that received the message. No extra permissions are needed.
  • Covers the safety rules:
    • shared mailbox providers are never internal;
    • test-google-a.com routing aliases are ignored;
    • your tenant's own *.onmicrosoft.com domain is kept;
    • mail that fails authentication for one of your domains stays inbound.
  • Documents the new Additional internal domains setting (scope.internal_domains): when you need it, how it's validated, and YAML/JSON examples. A warning explains that scope.domains limits mailbox coverage and must not be used to mark a domain internal.
  • Explains where to see the effective list (Settings → connection card → Internal domains) and what each source label means.

Also links the page from the setup wizard field table (getting-started) and the connection record reference (providers), and adds it to the nav.

mkdocs build --strict and markdownlint-cli2 pass.

🤖 Generated with Claude Code

maximelb and others added 2 commits September 28, 2026 22:18
Add an Internal Domains page covering how message direction is decided,
how organization domains are detected from mailbox and alias addresses,
the safety rules (shared providers, routing aliases, failed authentication),
the Additional internal domains setting (scope.internal_domains), and where
to see the effective list. Link it from the connection record reference
and the setup wizard field table.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… list is shown

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
lcbill
lcbill previously approved these changes Sep 28, 2026
… primary addresses included

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@maximelb
maximelb merged commit c22c6a4 into master Sep 29, 2026
7 checks passed
@maximelb
maximelb deleted the feat/mailsec-internal-domains branch September 29, 2026 00:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants