Documentation Index

Fetch the complete documentation index at: https://docs.trustifi.com/llms.txt

Use this file to discover all available pages before exploring further.

Inbound integration

Prev Next

Overview

Trustifi’s Inbound Shield can be seamlessly integrated into an organization’s email environment to provide protection against threats such as phishing, spoofing, spam, impersonation, and other malicious email activity.

Trustifi supports multiple inbound integration architectures designed to accommodate different email environments, infrastructure capabilities, and deployment goals. The available inbound integration models include Inbound Email Relay, MX Record Change, API Integration, and Journaling Mode.

These architectures vary in mail flow behavior, enforcement level, and configuration requirements, allowing organizations to select the approach that best aligns with their technical constraints and security objectives.

This guide outlines each inbound integration method in detail to help determine which deployment approach best fits your organization.

If you are unsure which inbound integration method is appropriate for your environment, or if you would like additional information about integrating with Trustifi, contact support at [email protected].


Inbound Email relay

With the Inbound Email Relay architecture, Trustifi configures mail flow connectors in the organization’s email environment to route inbound email traffic to Trustifi before it reaches recipient mailboxes.

Trustifi scans and processes incoming messages. Emails that are not quarantined are routed back to the organization’s email server, which then delivers them to the recipient’s mailbox.

Advanced cloud-based email systems such as Microsoft 365 and Google Workspace support custom mail flow rules. These rules can be used to control which inbound traffic is routed to Trustifi and to support limited-scope deployments or proof-of-concept (POC) trials.

Technical Documentation

When This Architecture Should Be Used

  • Organizations using SMTP-based email systems that support mail flow or routing connectors

  • Commonly deployed in Microsoft 365, Exchange Hybrid, and Google Workspace environments

  • Can be deployed inline with an additional inbound security system, such as a Secure Email Gateway (SEG), where email traffic flows through the SEG first and then through Trustifi before reaching the mailbox


MX record change

With the MX Record Change architecture, the domain’s default MX record is updated to point to Trustifi.

This causes all inbound email traffic for the domain to be routed to Trustifi, where messages are scanned and processed before being forwarded to the organization’s email server.

Because MX records apply at the domain level, this architecture does not support conditional routing or limited-scope deployments.

Technical documentation: MX integration guide

When This Architecture Should Be Used

  • Email environments that do not support custom mail flow connectors or rules

  • Commonly used in on-premises email systems

  • Organizations seeking full inbound protection without complex mail flow configuration


API integration

With API Integration, organizations using Microsoft 365 can have inbound emails scanned by Trustifi without making any architectural mail flow changes.

The integration is enabled directly from the Trustifi portal using Microsoft 365 administrator credentials. Administrators then select which mailboxes should be protected.

When an email arrives in a protected mailbox:

  • The message is temporarily moved for scanning by Trustifi

  • After scanning, emails that are not quarantined are returned to the inbox

Technical documentation: API integration guide

When This Architecture Should Be Used

  • Organizations using Microsoft 365

  • Clients who want to avoid mail flow or routing changes

  • Organizations looking to protect a limited number of mailboxes or run a POC before deploying a relay-based integration


Journaling mode

Journaling Mode is based on the inbound relay architecture but does not alter live email flow.

Instead of routing inbound email traffic to Trustifi, the email system sends a copy of inbound messages to Trustifi for scanning and analysis. The original email delivery path remains unchanged.

If threats are detected, organizations using cloud-based email systems such as Microsoft 365 or Google Workspace can locate and remove malicious emails from user mailboxes using Trustifi’s Threat Response tools.

Technical documentation:

Organizations using cloud-based email systems like Office 365 or Google Workspaces can still take actions if threats are found, and find and remove dangerous emails from recipient mailboxes using the Threat Response tool.

When This Architecture Should Be Used

  • Organizations using Microsoft 365, Exchange Hybrid, or Google Workspace

  • Clients who want visibility into inbound threats without quarantining or modifying mail flow

  • Organizations evaluating Trustifi as a proof of concept before enabling full enforcement


Notes and Recommendations

  • Inbound Email Relay provides the strongest real-time protection and enforcement

  • MX Record Change is best suited for environments without advanced mail flow capabilities

  • API Integration is ideal for Microsoft 365 organizations seeking minimal disruption

  • Journaling Mode is well suited for visibility, auditing, or proof-of-concept deployments

  • Multiple inbound integration methods may be evaluated during phased deployment strategies