Skip to content
Avanet

Set up Sophos Email Gateway with Zoho Mail

With Zoho Mail, Sophos Email is deployed as the upstream SMTP gateway: inbound messages reach Sophos first and are delivered to Zoho after scanning; outbound messages are sent by Zoho over TLS to the Sophos relay host. The critical values are regional and, in some cases, tenant-specific. Copy them from the current consoles during the change rather than from an old ticket.

Safe sequence: Record the current state, prepare the Sophos domain and Zoho destination, allow delivery from Sophos in Zoho, configure and test the outbound path, then change MX and only at the end restrict Zoho acceptance to the Sophos IP addresses.

Scope: Gateway, not Mailflow

This procedure applies only to Sophos Gateway with Zoho Mail. Manage the domain in Sophos Fusion (formerly Sophos Central) under Products and Services > Email > Gateway Domains. M365 Mailflow Domains, Microsoft connectors and mail flow rules belong to the Microsoft 365 Mailflow architecture and must not be enabled in parallel for this Zoho domain. Mail Protection on a Sophos Firewall is also outside this procedure.

Prerequisites and change data

Before starting, you need:

  • administrative access to Sophos Fusion and the Zoho Mail Admin Console;
  • access to the domain’s authoritative public DNS;
  • a domain configured in Sophos Gateway, with complete recipients and production-ready policies;
  • the regional Zoho MX hostname, checked in the Zoho console under Mail Settings > Tools and Configurations > Configurations > MX;
  • a change window, internal and external test accounts, and owners for Sophos, Zoho and DNS.

Before each change, record the domain, existing MX values with priorities and TTL, existing Zoho routes and restrictions, and the following values copied live from the current tenant:

  • regional Sophos MX records and their priorities;
  • Sophos delivery IP addresses from Configure External Dependencies > Inbound Settings;
  • the Sophos Outbound Relay Host from Configure External Dependencies > Outbound Settings;
  • the regional Zoho MX hostname used as the internal Sophos destination;
  • outbound SMTP CIDR ranges currently published by Zoho.

Sophos documentation currently lists the delivery addresses 18.220.12.142, 18.216.7.10 and 103.246.251.128/26. The values displayed in the current tenant’s Inbound Settings remain authoritative. Zoho IP ranges can change; verify them immediately before the change against current Zoho documentation or SPF records, or with Zoho Support.

Prepare the Sophos domain and inbound destination

  1. In Sophos Fusion, open the Global Settings icon and select Products and Services > Email > Gateway Domains.
  2. If the domain isn’t verified, select Set up email gateway settings, enter the domain, and click Verify Domain Ownership. Publish the domain-specific TXT value shown in the dialog unchanged in public DNS.
  3. After the DNS update takes effect, click Verify in Sophos. If it fails, check the TXT name and value at the authoritative DNS; don’t proceed with a value from another tenant.
  4. For initial setup, select Inbound Only under Direction and Mail Host under Inbound Destination.
  5. Under FQDN, enter the MX hostname confirmed for your own Zoho region, for example mx.zoho.com only if the Zoho console shows that exact value. Set Port to 25 and save.
  6. Under Configure External Dependencies > Inbound Settings, copy the displayed Sophos MX records, priorities and delivery IP addresses into the change record again.

The Sophos FQDN points to Zoho; the public MX will later point to Sophos. Using the same Sophos host or the public domain name in both places can create a loop.

Prepare Zoho for inbound delivery

  1. In the Zoho Mail Admin Console, open Mail Settings > Email Routing > Inbound Gateway.
  2. Add exactly the delivery IP addresses previously copied from Sophos and save.
  3. Leave Reject non-inbound gateway emails disabled initially. Enable it only after MX propagation and a successful inbound test. Otherwise, Zoho can reject legitimate messages that still arrive directly during cutover.

The destination is now ready without changing the public mail path.

Configure the outbound path through Sophos

  1. In Gateway Domains, open the domain and select Edit.
  2. Set Direction to Inbound and Outbound, and under Outbound Gateway select Custom Gateway.
  3. Enter each Zoho outbound SMTP CIDR currently confirmed for the tenant and click Add after each one. The baseline documented by Sophos is:
136.143.182.0/23
136.143.190.0/23
136.143.188.0/24
136.143.184.0/24
135.84.80.0/24
135.84.82.0/24
8.39.54.0/23
204.141.32.0/23
204.141.42.0/23
8.40.222.0/23
65.154.166.0/24
199.67.84.0/24
199.67.86.0/24
169.148.129.0/24
169.148.131.0/24
199.67.88.0/24
169.148.138.0/24
169.148.188.0/24
  1. Save. Don’t add broader networks, especially not 0.0.0.0/0: Custom Gateway controls relay authorization and isn’t a general allowlist.
  2. Under Configure External Dependencies > Outbound Settings, copy the current Outbound Relay Host.
  3. In Zoho, open Mail Settings > Email Routing > Outbound Gateway, paste the copied FQDN into Destination Host, select TLS under Connection type, and save with Update.
  4. Check the Zoho verification email, then send from a Zoho mailbox to a controlled external mailbox.

Cut over MX in a controlled manner

Only after the Sophos domain, recipients, policies, Zoho inbound gateway and outbound test are ready, replace the existing MX records at authoritative DNS with the MX records copied live for your Sophos region, using the displayed priorities. Never use MX values from another region. While TTL and DNS caches expire, monitor both paths and freeze parallel routing changes.

Send from an external account to a normal recipient, an alias and, if business-critical, a group. Once the current authoritative DNS answer points to Sophos, all messages have reached Zoho and are visible in Sophos, you can enable Reject non-inbound gateway emails in Zoho. Don’t enable it sooner.

Validate both directions

Acceptance passes only when a new, uniquely identified inbound and outbound message has been checked as follows:

  1. record final delivery status, sender, recipient, UTC time and Message-ID;
  2. find a scan or processing event in Sophos Fusion under Email Security > Reports > Message History;
  3. in My Products > Email Security > Dashboard, check Inbound Statistics and Inbound Activity Summary, or Outbound Statistics and Outbound Activity Summary;
  4. check the corresponding Zoho trace or delivery evidence;
  5. for inbound mail, also document the authoritative MX answer; for outbound mail, document the Sophos relay host used.

A dashboard counter alone doesn’t prove delivery. Likewise, delivery without an event in Message History doesn’t prove that the message passed through Sophos.

Roll back without creating a loop

Abort conditions include external non-delivery, repeated TLS or relay rejections, missing Sophos events, or a routing loop. Don’t weaken protection policies; roll back in this order:

  1. Disable Reject non-inbound gateway emails in Zoho so that the previous inbound path can be accepted again.
  2. Restore the recorded MX records with their original priorities and verify the DNS result.
  3. Disable the new Outbound Gateway in Zoho or restore the recorded previous setting before removing the Sophos outbound configuration in Central.
  4. Return the Sophos domain to its documented previous state; don’t delete the domain while DNS or Zoho still points to Sophos.
  5. Send one inbound and one outbound control message over the restored path and retain both traces.

Messages can continue to reach the Sophos MX because of DNS caching. Don’t disable Sophos until the recorded TTL has elapsed and queues have been monitored.

Troubleshoot DNS, relay, TLS and loops

  • Domain verification fails: Query the authoritative DNS for the TXT name and domain-specific value; check extra quotes, the wrong zone and live caches, then select Verify again.
  • Inbound mail doesn’t reach Sophos: Check the authoritative MX answer, priorities and propagation. If MX still points to Zoho, direct delivery is expected during the transition.
  • Sophos can’t deliver to Zoho: Compare the regional Zoho MX hostname in FQDN, 25, the Zoho inbound-gateway IP list and the Zoho trace. The host must not resolve back to Sophos.
  • Outbound mail is rejected as relay: Compare the actual Zoho source IP with the currently published CIDRs entered under Custom Gateway. Add a missing range only after confirmation; don’t widen authorization indiscriminately.
  • TLS fails: Check Connection type = TLS in Zoho, the unchanged current Outbound Relay Host, DNS resolution, certificate names and timestamps on both sides. Don’t permanently disable TLS as a workaround.
  • Loop or duplicate processing: Map public MX targets, Sophos FQDN, Zoho Outbound Gateway, forwarding and old gateways together. The inbound route must be Internet → Sophos → Zoho and outbound Zoho → Sophos → Internet. Stop the change and run the rollback immediately if hops repeat.