Cisco Secure Email setup

Cisco Secure Email: inbound mail bypasses the gateway

The public MX route may not point to the Cisco cloud allocation or customer-managed gateway that should receive the domain.

Problem description

The visible symptom is:

Inbound mail bypasses Cisco Secure Email or stops after the MX change.

Check the sending domain

Fix the mail route

  1. Identify the deployment: Cisco cloud gateway or a customer-managed Secure Email Gateway.
  2. Copy the assigned cloud MX hostnames, or confirm the public hostname and IP of each managed gateway.
  3. Verify the domain, listener, recipient validation, firewall, and downstream route before changing DNS.
  4. Publish the complete intended MX set with the required priorities.
  5. Remove an old direct route only after the gateway can deliver mail to the destination.
  6. Check public MX results and send a new external test.

Why copied values fail

Cisco cloud allocations differ. A self-managed appliance has customer-owned hostnames and IP addresses. An MX value copied from another deployment cannot identify your gateway.

What the check proves

A public check can show missing, mixed, or unreachable DNS routes. It cannot see the AsyncOS mail policy or the next hop behind the gateway.

Frequently asked questions

What MX hostname should Cisco Secure Email use?

There is no universal value. Cloud customers use the hostnames assigned to their allocation; appliance customers use DNS names that resolve to their own reachable gateways.

Should I copy a DNS value from another company?

No. Use the value shown for your own tenant, region, and mail route. Preserve every other service that still sends or receives mail.

Related email diagnostics

Primary sources: Cisco Secure Email Gateway configuration documentation.