We’re primarily a managed host, but we also get the occasional self-serve customer who just wants to buy a plan, get a mailbox, and be off to the races, without us hand-fixing a DNS record every time their outbound doesn’t deliver.
We’re trying to figure out the cleanest outbound setup on a multi-tenant Enhance mail server, and we keep going back and forth.
One option is sending directly from the Enhance mail node with its native per-domain DKIM/SPF/DMARC. For anyone doing this at scale: is Enhance’s auto-managed authentication (when the domain’s DNS is on Enhance) enough for solid inbox placement on its own? If so, a self-serve client’s mail could just work with zero manual DNS on our end. But then there's the IP getting banned issues.
The other option is an external smart host (Cloudflare Email Sending, Resend, SES, and so on). That gets us warmed sending IPs, but every one requires per-sending-domain verification (DKIM/SPF records added per client), and Cloudflare even requires the client’s whole DNS zone to be on Cloudflare. That’s exactly the manual, ask-us-what’s-wrong friction we’re trying to avoid for self-serve users.
So for those running multi-tenant Enhance mail at any scale: what actually works? Does Enhance auto-configure each domain’s DKIM/SPF/DMARC when the zone is on Enhance DNS, so outbound just works for a hands-off customer? Or does everyone end up relaying, and if so, how do you keep the per-domain sender auth from becoming manual work? Who do you prefer as a smart host provider if so?
Thanks!