DocsGetting started
Before you begin
The access, values and twenty minutes you need before opening your admin console.
Updated August 29, 2026
Who does this
One person, once. Setup is performed entirely in your mail platform's admin console and your DNS provider. You need:
| Platform | Role required |
|---|---|
| Microsoft 365 | Exchange Administrator (or Global Administrator) in the tenant |
| Google Workspace | Super Admin in the Workspace organization |
| DNS | Whoever can add a TXT record for your sending domain |
Nothing is installed on user devices, and no user sees a prompt.
What you need from RubySig
Your connection values are issued when your organization is approved on RubySig. Sign in to the portal and open Setup to find:
- Your relay address — a hostname of the form
<tenant>.smtp.rubysig.comthat is unique to your organization. It appears on two screens in the Microsoft guide and one in the Google guide. - Your DKIM record — the TXT record to publish for your domain, and whether RubySig can see it yet.
Everything else in the guides — the relay's IP address, the header name the loop guard checks, port numbers — is the same for every customer and is listed under Connection values.
Tip: Keep the portal's Setup page open in a second tab while you work. The values are copy-paste, and a single stray character (a trailing full stop after the hostname, for instance) is the most common reason a wizard refuses to continue.
Prerequisites
- Your sending domain is already verified in your tenant and shows as Healthy (Microsoft 365: Settings → Domains) or Verified (Google: Account → Domains). Almost every organization that already sends mail from the domain meets this.
- Users who should receive a signature exist in your directory with the fields the signature uses — display name, title, phone. RubySig reads these; it does not invent them.
- One external mailbox you control (a personal Gmail is fine), to send a test message to at the end.
How long it takes
About twenty minutes for the console work, plus DNS propagation for the DKIM record — usually minutes, occasionally up to an hour. You can do the console steps before the DNS record resolves; the two are independent.
What does not change
- MX records — untouched. RubySig never handles inbound mail.
- Existing connectors and rules — the RubySig connectors are additive. Mail that the transport rule does not match flows exactly as before.
- Deliverability — the final hop is still your platform, from its own IP addresses.
Ready? Start with Microsoft 365 or Google Workspace.