Skip to content
Avanet

Safely remove and offboard a Sophos Email domain

Do not remove a domain from Sophos Fusion (formerly Sophos Central) until its replacement mail path works and no rule, connector, directory synchronization, or policy depends on the Sophos path. Always check both inventories: M365 Mailflow Domains and Gateway Domains. This procedure offboards Sophos Email; it does not administer Sophos Firewall Mail Protection.

Quick path: record the starting state and owners, test the replacement path in both directions, disconnect an active Mailflow connection, delete the domain from M365 Mailflow Domains, then inspect Gateway Domains and delete an entry there only after the routing and DNS cutover. Finally check delivery, Microsoft Message Trace, Sophos Message History, reports, and quarantine.

Establish scope and inventory

For every domain, record the deployment mode; all protected domains, mailboxes, aliases, and groups; the mailbox synchronization source; policy, encryption, quarantine, and reporting owners; MX and other routing dependencies; and the cutover and rollback contacts for Sophos Fusion, the mail platform, DNS, and incident management. Record abort criteria and the last known working state.

In Sophos Fusion, open Global Settings > Products and Services > Email > M365 Mailflow Domains and record the domain and connection status. Then open Gateway Domains from the same area. Absence from one list does not prove absence from the other.

Clear dependencies before deletion

For Mailflow, identify the domain-specific transport rules and connectors in Exchange Admin Center. For Gateway, check MX targets, inbound and outbound relays, firewall allowances, and final delivery hosts. Assign every object to a domain and owner; never delete suspected remnants blindly.

Check synchronized mailboxes and groups, policies, encryption workflows, quarantine cases, scheduled reports, and investigations. Change synchronized objects at their source directory. Complete export and retention duties before deletion; do not assume historical data remains available in the same way afterwards.

Define an external inbound and outbound test with sender, recipient, UTC time, and Message-ID. The alternative route must be ready before deletion. Stop if ownership, the target route, or rollback is unclear.

Approve cutover and rollback

The approved plan must state the maintenance window, order, expected interruption, DNS TTL, success criteria, and rollback deadline. Keep the Sophos Fusion, mail-platform, DNS, and incident contacts available.

Immediately before cutover, deliver one inbound and one outbound message through the active Sophos path. Confirm delivery and the expected record in Message History and the provider trace. This is the baseline. Apply routing or DNS changes using the approved provider procedure and prove the replacement path before irreversible deletion.

Remove the domain in a safe order

  1. Open Global Settings > Products and Services > Email > M365 Mailflow Domains and find the domain.
  2. If its Mailflow connection is active, use the disconnect action offered there. Then independently verify in Microsoft 365 that no domain route still depends on Sophos; do not treat an interface status as proof. Do not resolve unclear leftovers by indiscriminate deletion.
  3. Delete the domain from M365 Mailflow Domains only after this independent routing check.
  4. Open Global Settings > Products and Services > Email > Gateway Domains and find the same domain.
  5. If present, reconfirm that MX, inbound and outbound routing, and final delivery use the approved non-Sophos path. Then delete it from Gateway Domains.
  6. Repeat for every alias or additional domain in scope, recording time, operator, and result.

Email landing pages are navigation only. Do not infer deployment mode or successful removal from a tile or landing page.

Verify offboarding

The change is complete only when:

  • the domain is absent from both M365 Mailflow Domains and Gateway Domains;
  • controlled inbound and outbound messages reach their recipients over the replacement route;
  • provider traces and headers show no remaining Sophos connector, relay, or loop;
  • the new tests produce no new processing record in Sophos Message History;
  • policy and mailbox inventories show no unintended scope for the removed domain;
  • required historical reports and quarantine cases were reviewed or retained as planned;
  • monitoring and service owners know the new expected state.

Absence from Message History alone does not prove delivery; recipient delivery, provider trace, and headers do. Conversely, a new Sophos record after cutover indicates a remaining route.

Abort, roll back, and escalate

If the replacement route fails, stop before the next deletion and restore the documented last working route. Test both directions again. If the domain was already deleted, do not improvise connectors: rebuild the approved deployment mode. For Mailflow, use Set up Sophos Email Mailflow for Microsoft 365 as the controlled recovery procedure.

If Mailflow objects remain, ownership is unclear, or tests conflict with status, follow Sophos Email Mailflow troubleshooting. Escalate with the domain, UTC times, Message-IDs, headers, traces, before-and-after inventory, and actions taken. Route provider setup, licensing, and directory errors to their dedicated procedures rather than performing risky ad hoc cleanup.