DocsGetting started

What RubySig does

Signatures are applied in transit, on every message, from every device — with nothing installed and your mail platform still doing the delivering.

Updated August 29, 2026

RubySig is a stamping relay. Your mail platform hands each outbound message to RubySig for a fraction of a second; RubySig appends the sender's signature, signs the message for your domain, and hands it straight back. Your platform then delivers it exactly as it would have anyway.

The path a message takes

  1. A user sends mail — from Outlook, the web, a phone, a shared mailbox. No add-in, no plugin, no per-device setup.
  2. Your platform routes it to RubySig — via a connector (Microsoft 365) or a routing rule (Google Workspace) that applies only to mail leaving your organization.
  3. RubySig stamps and signs it — the sender is looked up in your directory, their signature is rendered and appended, and the message is DKIM-signed for your domain.
  4. RubySig hands it back — to your own platform, which delivers it from its own IP addresses and reputation.

Note: Because the final hop is still your platform, nothing about your deliverability changes. Recipients see mail from Microsoft or Google, as before — now with a signature that passes SPF, DKIM and DMARC.

What RubySig never does

  • It does not receive your inbound mail. Your MX records are untouched. RubySig only ever sees messages your platform explicitly routes to it, and only outbound ones.
  • It does not deliver to the internet. Every message goes back to your platform. RubySig has no sending reputation of its own to manage — or to damage.
  • It does not keep mail. A message is stamped in memory and handed on within seconds. Nothing is written to disk.
  • It does not log addresses. The relay logs the domain a message belongs to so operators can act, never the sender or recipient address. This is a commitment in the Data Processing Agreement, not a setting.

What you need to set up

For Microsoft 365, three things in the Exchange admin center — an outbound connector, an inbound connector, and one transport rule — plus one DNS TXT record for DKIM. The Microsoft 365 guide walks through every screen with screenshots.

For Google Workspace, the same shape with Google's names: a mail route, a content compliance rule, and the SMTP relay service. See the Google Workspace guide.

Either way, Before you begin lists what to have ready.