Mail Server Configuration
Follow the simple, step-by-step instructions to configure your corporate email server to work with StayPrivate. The whole setup process should take little more than 5 minutes and will not disrupt your current email service in any way.
Please note that for your mail server to work with StayPrivate, you must have already signed up your domain to the StayPrivate service.
1. Update DNS Records
The first step is to update your DNS records to allow StayPrivate to forward emails on behalf of your company. It is very important to do this before configuring your server below, otherwise some emails may not be delivered.
Firstly, log into your DNS administration console and find the current SPF record - this is a TXT record and normally starts with 'v=spf1'. Add the text: include:spmail.com before the trailing ~all.
OR, if you do not have an SPF record, add a new TXT record with the following content: v=spf1 a mx include:spmail.com ~all
Secondly, add support for DKIM by adding a CNAME record for stayprivate._domainkey with the value stayprivate._domainkey.spmail.com.
2. Google Mail Server Access
You require administrator access to your Google mail server in order to configure it to work with StayPrivate:
Log into the Google Admin console at: https://admin.google.com
Select 'Apps'.
Select 'Google Workspace' and from the list, click on 'Gmail'.
If you do not have administrator access to your email server, please send the following link to your IT administrator and ask them to complete the setup: https://stayprivate.com/server-configuration/?config=google
3. Configure Host
First, add StayPrivate as a host:
Click on 'Hosts'.
Click on 'ADD ROUTE' to add a new mail route.
Enter the name: StayPrivate
In the 'Enter host name or IP' field, enter sendsecure.stayprivate.com and in the numeric field next to it, enter the port number: 587
Click 'Save'.
4. Outbound Email
The next step is to add a rule so that the email server can identify which emails to send via the StayPrivate host.
Go back to the Gmail settings page by clicking on 'Settings for Gmail' near the top.
Scroll down to near the bottom and click on 'Compliance'. Then scroll down to 'Content compliance' and click 'CONFIGURE'.
Under 'Content compliance', enter the text: Identify messages to send via StayPrivate
Under '1. Email messages to affect', select 'Outbound'.
Under '2. Add expressions that describe...', select 'If ALL of the following match the message'. Then click on 'ADD'.
Click on 'Simple content match' and select 'Advanced content match'. Then under 'Location', select 'Full Headers'.
Under 'Match type', select 'Not contains text'.
Under 'Content', enter the text: x-stayprivate-processed: true
Click 'SAVE'.
In '3. If the above expressions match, do the following', select 'Modify the message', then under 'Route', check the box next to 'Change the route'.
Click on 'Normal routing' and select 'StayPrivate'.
Then under 'Spam', check the box next to 'Bypass the spam filter for this message'.
Click on 'SAVE' bottom right.
5. Inbound Email
The next step is to configure your email server to accept and relay emails sent by StayPrivate:
Go back to the Gmail settings page by clicking on 'Settings for Gmail' near the top.
Scroll down to the bottom and click on 'Routing'. Under 'Routing' scroll down and under 'SMTP relay service', click 'CONFIGURE'.
Under 'SMTP relay service', enter the text Receive from StayPrivate.
Under '2. Authentication', select 'Only accept mail from the specified IP addresses'. Then click 'ADD'.
Under 'Description', enter the text StayPrivate and under 'Enter IP address/range', enter the text: 18.130.40.2
Click 'SAVE'.
Under '3. Encryption', select 'Require TLS encryption'.
Click on 'SAVE' bottom right.
6. Secure Replies
To ensure that direct replies from secure corporate domains are included in StayPrivate, incoming secure replies are identified and blind copied to server@stayprivatemail.com. This is achieved by adding a further compliance rule:
Go to the Gmail settings page by clicking on 'Settings for Gmail' near the top.
Scroll down to near the bottom and select 'Compliance'. Under 'Content compliance', click 'ADD ANOTHER RULE'.
Under 'Content compliance', enter: Send secure replies to StayPrivate
Under '1. Email messages to affect', select 'Inbound'.
Under '2. Add expressions that...', select 'ADD'.
Click on 'Simple content match' and select 'Advanced content match'. Then under 'Location', select 'Body'.
Under 'Content', enter #stayprivate-secure-reply then click 'SAVE'.
In '3. If the above expressions match, do the following', under 'Route', select 'Modify message'.
Under 'Also deliver to', check the box next to 'Add more recipients' then select 'ADD'.
Under 'Recipient address:', enter: server@stayprivatemail.com
Select 'SAVE'.
Finally, click on 'SAVE' bottom right. This is important - otherwise your changes may be lost.
That is it! StayPrivate will start working immediately.
7. Deleting StayPrivate from Your Mail Server
If you do wish to delete StayPrivate, return to the 'Settings for Gmail' page, scroll down to near the bottom and click on 'Compliance'. Then scroll down to 'Content compliance' and delete the rules 'Identify messages to send via StayPrivate' and 'Send secure replies to StayPrivate'.
Again, in the 'Settings for Gmail' page, scroll down to the bottom and click on 'Routing'. Scroll down to 'SMTP relay service' and delete the service 'Receive from StayPrivate'.
Finally, near the top of the 'Settings for Gmail' page, click on 'Hosts' and delete 'StayPrivate'.
Summary
The above instructions detail the necessary steps to establish and manage your corporate email server’s integration with StayPrivate. Please follow the steps carefully to ensure successful setup.