Setup steps, Amertrans Logistics

The exact order, who does each step, and what we check before moving on. You = Amertrans IT / Machaela. Us = Max. We never need your logins.

One setting decides whether the whole plan works, check it first. HubSpot and EmailPond both connect to mailboxes through a Microsoft sign-in (no passwords, no SMTP). If your tenant blocks users from consenting to third-party apps, an admin grants consent once for each app and everything else proceeds.

Microsoft Entra admin center → Identity → Applications → Enterprise apps → Consent and permissions → User consent settings

If it reads "Do not allow user consent", Jeff approves HubSpot and EmailPond when the first connection prompt appears, or grants admin consent up front.

Part 1 · Domains and mailboxes Same steps for all 4 domains. About 45 minutes with IT on a screenshare.

  1. YouBuy the 3 new domains on GoDaddy. amertrans-logistics.com is already yours.
    amertranslogisticsinc.com   amertranslogisticsgroup.com   amertranslogisticsusa.com
  2. YouAdd each domain to Microsoft 365. Microsoft 365 admin center → Settings → Domains → Add domain
    GoDaddy is a Domain Connect registrar: the wizard opens a GoDaddy sign-in, writes the verification record, then on "Add DNS records" writes MX, autodiscover and SPF for you. Tick Exchange only.
  3. YouTurn on DKIM for each domain and publish the two records. security.microsoft.com → Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM
    Select the domain, the portal shows two CNAMEs (selector1 and selector2). Copy the exact targets it shows into GoDaddy DNS, wait for them to resolve, then flip the domain to Enabled.
  4. YouAdd the DMARC record in GoDaddy DNS. Type TXT, host _dmarc, value:
    v=DMARC1; p=none; pct=100; rua=mailto:dmarc@amertranslogistics.com
  5. YouCreate 4 mailboxes per domain, 16 total, named after the reps. Microsoft 365 admin center → Users → Active users → Add a user
    Pick the new domain in the Domains dropdown so it is the primary address. Assign an Exchange Online or Business Basic license to each. Real licensed mailboxes, not shared mailboxes (HubSpot cannot connect a shared mailbox).
  6. UsVerify every domain from the outside. DNS lookups on MX, SPF, both DKIM selectors and DMARC for all 4 domains, then one test send and reply per domain.

What the records look like, per domain

RecordHostValueWho writes it
MX@<token>.mail.protection.outlook.com (shown in the wizard)Wizard
CNAMEautodiscoverautodiscover.outlook.comWizard
TXT (SPF)@v=spf1 include:spf.protection.outlook.com -allWizard
CNAME (DKIM)selector1._domainkeytarget shown in the Defender portalIT, by hand
CNAME (DKIM)selector2._domainkeytarget shown in the Defender portalIT, by hand
TXT (DMARC)_dmarcv=DMARC1; p=none; pct=100; rua=mailto:...IT, by hand

One SPF record per domain, never two. DKIM targets differ per domain and per tenant, always copy from the portal rather than typing them.

Route 1 · The 4 rep mailboxes on amertrans-logistics.com Sending from HubSpot. Zero new HubSpot seats.

  1. YouEach rep signs into the new mailbox once at office.com, sets the password and registers MFA if your tenant asks for it.
  2. YouEach rep connects the new mailbox in HubSpot. HubSpot → Settings → General → Email → Connect email account → Office 365
    Microsoft sign-in with the new mailbox, click Allow. This adds a second connected inbox to their existing HubSpot user. No new user, no new seat.
  3. YouMake the new address the default for outgoing emails. In any email compose window, open the From dropdown, pick the new address, click "Set as default". Sequences also let you pick the From address when enrolling contacts.
  4. UsTest with each rep. Send a one-to-one email from a contact record, reply to it from outside, confirm the reply shows on the contact timeline and in the new mailbox.
  5. YouOptional: replies also in the rep's main inbox. Exchange admin center → Recipients → Mailboxes → mailbox → Email forwarding → Manage email forwarding
    Forward to the rep's existing address, tick "Deliver message to both forwarding address and mailbox". Note: the tenant's outbound spam policy setting "Automatic forwarding rules" must be On for this to work, the default blocks it.
  6. UsWarm-up first, real sends after 14 days. These 4 mailboxes go into EmailPond with the rest (Route 2, step 3).

Route 2 · The 12 cold-email mailboxes on the 3 new domains Nobody logs into these day to day. They never touch HubSpot.

  1. YouCreate the EmailPond account at emailpond.com, Starter plan ($49/mo, up to 20 inboxes), company card, in your name.
  2. UsConfigure the workspace on the screenshare: one workspace for Amertrans, tags per domain, warm-up settings.
  3. YouConnect all 16 mailboxes (12 cold + 4 rep). Each connection is a Microsoft sign-in for that mailbox, click Allow. Same consent rule as HubSpot, see the box at the top. No passwords stored, no SMTP.
  4. UsStart and monitor the warm-up. EmailPond ramps each inbox from a couple of emails a day upward. We watch the reputation scores and tell you when each domain is ready.
  5. UsCold domains on standby at about 5 weeks. Microsoft mailboxes on brand-new domains take longer to warm than Google ones, so we hold them a full 30 days before any cold send.
  6. UsFinal check and written summary: every domain, every mailbox, every record, what was set up and where.

Who does what, in one table

StepYouUs
DomainsBuy the 3 on GoDaddyNamed them, verify DNS
Microsoft 365Add domains, DKIM, DMARC, 16 mailboxes, licensesExact records and naming list, live on the session, verify from outside
HubSpotEach rep connects the new mailbox, 2 minutesWalk them through it, test sends, confirm replies land
EmailPondCreate the account, connect the mailboxesConfigure, run and monitor the warm-up
Final checkNothingVerify everything, written summary

Timeline

Day 1Domains bought. Session with IT: domains added, DKIM and DMARC in, 16 mailboxes created, EmailPond account created and mailboxes connected, warm-up on.
Day 2DNS verified, reps connect HubSpot, test sends checked.
Week 3Reps start sending from the new domain.
Week 5Cold domains fully warm and on standby. Final checks, written summary.

Max Pidvalnyi, email infrastructure and outbound, Bottle Rocket Growth. Paths and record formats checked against Microsoft, HubSpot and EmailPond documentation on September 10, 2026.