Mimecast Cloud Gateway setup

Mimecast: inbound mail bypasses the gateway

The domain's MX set may contain the wrong Mimecast region, unequal priorities, or an old direct-delivery route.

Problem description

The visible symptom is:

Inbound mail bypasses Mimecast or stops after the MX change.

Check the sending domain

Fix the mail route

  1. Validate the domain in the Mimecast setup application.
  2. Copy both inbound MX hostnames shown for your region.
  3. Publish both at the same priority. Mimecast recommends priority 10.
  4. Remove non-Mimecast MX records only after the Mimecast delivery route is ready.
  5. Return to Mimecast and validate the MX change.
  6. Send a new external message and confirm it appears in Mimecast tracking.

Common causes

The records belong to another region, only one host was added, priorities differ, an old MX still accepts direct mail, or cached DNS still shows the previous route.

What the check proves

MailFixIt can show the public MX set and mixed routes. It cannot confirm the destination server or a Mimecast account setting.

Frequently asked questions

Should both Mimecast MX records use the same priority?

Yes. Mimecast recommends equal priority for its two regional inbound hosts so both can provide load distribution and redundancy.

Does a correct DNS record prove the gateway is using it?

No. The gateway must also enable the matching route, signing profile, or policy. Confirm the result in a new message header.

Related email diagnostics

Primary sources: Mimecast: update and validate MX records.