Sophos Email: choose an architecture and plan onboarding
This decision guide separates Mailflow and Gateway, assigns ownership and walks through the pilot, cutover, validation and operations.
These guides cover architecture and onboarding, licensing, directory, mailbox and domain management, Gateway and Microsoft 365 Mailflow, and safe policies against spam, spoofing, malware, and dangerous URLs.
The articles follow the Sophos Email operational lifecycle: architecture and licensing, domains and mailboxes, mail flow, protection policies, quarantine and investigation, encryption, and automation.
Choose Mailflow or Gateway, check regions and licences, plan onboarding, and migrate existing Mail Protection.
This decision guide separates Mailflow and Gateway, assigns ownership and walks through the pilot, cutover, validation and operations.
This checklist assigns ownership, evidence and escalation for a Sophos Central data-region choice that can't be changed after submission.
This guide explains editions, add-ons, license consumption, reconciliation and the safe handling of trial and subscription end dates.
A staged migration runbook for MTA and transparent proxy deployments, with explicit feature gaps, loop prevention and acceptance gates.
Manage domains, DKIM, and SMTP routing, maintain mailboxes, synchronise directories, and remove domains safely.
This guide moves from domain verification through DNS and DKIM to BATV, SMTP routing, testing and a controlled way back.
This runbook disconnects Mailflow, removes the domain from both possible inventories, and proves the replacement mail path.
This guide covers the lifecycle of manually managed user mailboxes, distribution lists and public folders in Sophos Central.
This guide covers authorization, filters, synchronization, additional domains, troubleshooting, and irreversible cleanup of a Google Directory source.
Set up and troubleshoot Sophos Gateway and Microsoft 365 Mailflow for Microsoft 365, Exchange, Google Workspace, and Zoho Mail.
This guide covers the Gateway decision, domain verification, controlled cutover, validation, troubleshooting and offboarding.
This guide covers Microsoft 365 Gateway connectors, a safe MX cutover, and validation in Message Trace and Sophos Message History.
This guide connects on-premises Exchange to Sophos Gateway with restricted receive and send connectors while avoiding open relay and competing routes.
This guide connects Google Workspace to Sophos Gateway in both directions and provides a safe change, validation, and troubleshooting strategy.
This runbook covers Zoho routes, live Sophos Gateway values, a controlled cutover and validation in both directions.
This guide takes administrators from tenant permissions through Mailflow activation to testing, Gateway migration, and clean removal.
This runbook isolates Sophos Mailflow faults with Quick Test, Message Trace, and header analysis and provides safe repair and rollback paths.
Control spam, spoofing, malware, dangerous URLs, DLP, DMARC, outbound threats, and account compromise.
This guide explains scope, policy order, special handling for distribution lists and shared mailboxes, and safe testing and rollback.
This guide covers spam actions, NRD and New Sender Protection, outbound disclaimers, the delay queue and safe handling of false positives.
A controlled workflow for narrowly scoped inbound exceptions, list precedence, SPF/DKIM/DMARC, CSV imports, and regular cleanup.
This practical workflow connects VIP management, policy actions, Aggressive Mode, smart banners, validation, and safe troubleshooting.
This guide explains inbound sender authentication, processing order, safe actions, Smart Banners and validation in Message History.
This administrator workflow connects policy scope and rule order with safe actions, Message History checks, troubleshooting, and rollback.
A safe administrator workflow for page text, logos, tightly scoped URL Allow List entries, validation, and troubleshooting.
This guide shows how to plan and prioritise Data Control rules, verify them with realistic positive and negative tests, and safely resolve …
Practical guide to DNS delegation, staged DMARC policies, sender analysis, validation, troubleshooting and the reporting-migration boundary.
This administrator workflow separates provider setup, automatic remediation, and on-demand clawback and covers acceptance testing, quarantine, …
This incident runbook connects recipient configuration with triage, documented containment measures, validation, recovery, rollback, and escalation.
This admin guide connects current thresholds with the request workflow, status checks, reset windows, and the distinction between legitimate bulk mail …
Operate quarantines, trace messages, process user reports, and investigate incidents with monitoring and Threat Analysis.
A controlled setup and acceptance workflow for Gateway and M365 Mailflow domains, with a clear boundary around Microsoft-owned quarantine.
A controlled administrator workflow for quarantine types, details, Intelix inspection, release, deletion, evidence, and escalation.
A controlled workflow for scheduling, portal access, release and delete permissions, recipient mapping, validation, and troubleshooting.
A practical runbook for search, status and category analysis, recipient events, authentication, eligible remediation, evidence, and escalation.
An operational workflow for dataset selection, filters, drill-down, scheduling, export, validation, and correct handling of pending verdicts.
A controlled workflow for Microsoft 365 deployment, client and network diagnosis, cache and token cleanup, and a verifiable reporting test.
The Marketplace integration sends Sophos Email events to Sophos for analysis and is accepted through tile health and a representative data record.
Deploy TLS, Secure Message, S/MIME, portal encryption, and the Outlook add-in safely.
Decision guide and runbook for policy scope, TLS versions, certificate verification, Push and Portal Encryption, validation, troubleshooting and …
An evidence-led administrator workflow for prerequisites, certificate matching, inbound and outbound testing, and the secure certificate lifecycle.
This workflow joins the Sophos Central configuration to supported Microsoft deployment and a verifiable acceptance test.
A practical workflow for the branding request, recipient experience, administration, acceptance testing, rollback, and troubleshooting.
Automate API access, tenant routing, mailboxes, quarantine, Clawback, and S/MIME in a controlled way.
This entry point connects shared Central API access to a harmless read test and clear version, pagination, throttling, and write-operation boundaries.
This workflow protects the Client Secret and token, validates the Who-am-I identity, and couples every Email request to the correct tenant ID and data …
A safe mailbox lifecycle covering search, pagination, CRUD, aliases, delegates, distribution-list owners and bulk-sender requests.
A controlled API workflow for search, pagination, preview, URLs, attachments, downloads, strip/reattach, bulk actions, and error handling.
A tenant-scoped API workflow for search, preview, attachments, download jobs, release, deletion, state validation, and partial failures.
This runbook covers single and multiple clawback with x-sophos-email-id, tenant-scoped requests, status polling, partial failures, throttling, and …
A safe lifecycle runbook with exact API paths, payloads, validation, and safeguards for the destructive S/MIME reset.