How MxGuard Smarthost works and how to authenticate
Your mail server hands outbound mail to smtp.mxguard.uk over an authenticated, encrypted connection (port 587 with STARTTLS). MxGuard scans it lightly, optionally DKIM-signs it, rate-limits it, and relays it out over the same reputable UK and EU IPs used for scanned inbound mail. Configuration takes about five minutes; after that your server sends exactly as it always has, with MxGuard sitting transparently in the middle.
Two ways to authenticate:
- SMTP authentication (SASL) — recommended. A unique username and password per domain. It works from any IP, can be rotated freely, and constrains the sender domain so no one can spoof others.
- IP allowlist. Give us your static sending IP(s) and we trust the source with no credentials. This is the simplest config for fixed-IP datacentre servers, but it requires stable, non-dynamic IPs.

0 comments
Sign in with your TDesk account to comment.