Barracuda Email Gateway Defense setup
Barracuda Email Gateway Defense: inbound mail bypasses the gateway
Your domain's public MX records may not match the Barracuda routes assigned to your account.
The visible symptom is:
Inbound mail bypasses Barracuda Email Gateway Defense or stops after the MX change.
Fix the mail route
- Add and verify the domain in Barracuda Email Gateway Defense.
- Confirm the destination mail server in Barracuda can receive mail.
- Copy the MX hostnames and priorities assigned to your Barracuda account.
- Publish that complete MX set at the domain’s DNS provider.
- Remove old MX routes only after the Barracuda route is ready.
- Check public MX results, then send a new message from an external account.
Why partial changes fail
Barracuda says all MX records must point to its service. A leftover direct-delivery MX can bypass filtering. A Barracuda MX published before the domain and destination are ready can stop delivery.
What the check proves
A public check can show the current MX hosts, priorities, conflicts, and DNS visibility. It cannot prove that Barracuda knows the domain or can reach the final mailbox.
Frequently asked questions
Why does mail bypass Barracuda Email Gateway Defense?
A non-Barracuda MX record can give senders a direct path around the gateway. The domain can also fail if its Barracuda destination server is not ready.
Should I copy a DNS value from another company?
No. Use the value shown for your own tenant, region, and mail route. Preserve every other service that still sends or receives mail.
Related email diagnostics
Primary sources: Barracuda: Configure MX records to direct mail to Email Gateway Defense.