Migrations

Email Migration Rollback Plan: Define Failure Before Cutover

If you cannot say what failure looks like, you are not ready to cut. Screenshot first. Exclusive MX. External probe.

MailerZ editorial · Secuno LLC17 min read

Email migration rollback plan work is done before the window, not after the missing invoices. Define failure: empty history after TTL, Header From rewritten, confirm mail absent, or destination 550 on the probe. Rollback is republishing the saved MX set. Dual MX is not rollback. It is how you create a second failure mode.

Abort signals in writing
Name failure.

Quick answer for email migration rollback plan

Failure must be binary enough to abort: probe not in history after agreed TTL, or From rewritten, or send-as 550 if send-as was in scope.

Success is also binary: named aliases received from another mailbox, Header From intact, leftovers gone on two resolvers.

People-as-rollback (“we will think”) fails. The screenshot is the rollback.

Catch-all FORWARD is not a rollback tool. It hides missing names and imports spam.

Authoritative mail transport is still IETF RFC 5321 — Simple Mail Transfer Protocol. migration planner. docs. troubleshooting.

Prove the hop with a received copy before you treat email migration rollback plan as a DNS edit.

Start free — one domain

The real decision

Founders schedule the cut and “see how it goes.” That is hope, not a plan.

Decision: who can abort, in what minute, with what DNS login.

Agencies need a customer-signed abort list or they eat weekend Slack.

Suite migrations need mailbox export abort criteria. This article is the hop cut.

When this path is enough

  • You can staff exclusive MX and named aliases.
  • You will keep Header From intact.
  • You can probe from another mailbox.

When this is the wrong ticket

  • History is empty and leftovers remain.
  • You want an inbox placement SLA.
  • You plan to rewrite visible From.

Technical mail flow

T-minus: inventory, verify, aliases, screenshot. T-zero: exclusive MX. T-plus: probes. T-abort: old MX only.

TTL is part of the definition. Aborting at minute five on a 24h TTL is panic, not science — unless leftovers were never deleted and two products already show.

Self-send is not a success signal.

Send-as can wait for a second window so rollback stays about MX.

Screenshot is rollback
Save the old set.

Step-by-step decision path

  1. Inventory leftovers. Screenshot current MX, SPF, DKIM, NS.
  2. Verify the domain. TXT as the dashboard states.
  3. Create named aliases first. Do not cut MX onto empty maps.
  4. Publish one MX set. Delete Google, Microsoft, registrar leftovers.
  5. Prove from another mailbox. Unique subject. Header From intact.
  6. Only then send-as if paid. Dashboard SPF/DKIM. Outbound probe.
  7. Store the proof packet. MX, hop, headers, plan name.
Dual MX is not rollback
Never mix to “be safe.”

Worked examples

They aborted because history was empty and aspmx remained. Deleted leftover instead of rolling back. Correct — leftover was the abort signal.

They rolled back by adding old MX beside new. Split got worse. True rollback would have removed MailerZ first if they chose old, or removed old if they chose new.

No screenshot. Old host forgotten. They guessed aspmx values. Two hours of folklore.

Abort owner was on a flight. Window slipped. Name two owners.

Success declared on self-send. Stripe missed. Abort criteria had not required an external sender.

If history and public MX disagree, believe MX first.

Open the matching guide

Failure modes and proof

Failures around email migration rollback plan and the proof that isolates them
SymptomLikely causeProof
Empty historyLeftover or cached MXTwo resolvers
Unknowns missingFree HOLDHistory hold
Header From rewrittenWrong hopReceived From
SMTP 550 send-asFree or unauthorized FromHistory line
spf=fail hop twoNaive envelopeReturn-Path
Still spam after clean hopDestination filtersNot an SLA
Self-send cleanShort-circuitOther mailbox
Wrong DNS panelNS ≠ registrar UINS lookup

MailerZ workflow and product boundary

Secuno LLC operates MailerZ. Site: mailerz.net. App: mail.mailerz.net. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME are never rewritten. Not IMAP. Not an open relay.

What MailerZ does

  • Accept MX for verified domains.
  • Rewrite envelope MAIL FROM with SRS on the forward.
  • Leave Header From and MIME intact.
  • Hold unknowns on Free. Optional paid FORWARD.
  • Paid SMTP from approved identities. Dashboard SPF, DKIM, and DMARC instructions.
  • 550 for unauthorized From. Not an open relay.

What MailerZ does not do

  • Guarantee Gmail Primary or any inbox placement rate.
  • Host IMAP, webmail, or Calendar.
  • Send-as on Free.
  • SOC 2, ISO 27001, HIPAA, review counts, or an uptime SLA. Controls: Security and Trust Center.

Plans: pricing. Free $0, 1 domain, 3 aliases, 1 seat, 14-day store, send-as disabled, SMTP and API disabled. Solo $40/year, 3 domains, 15 aliases, 90-day, 1,000 outgoing, 5/hour. Starter $8 or $80, 5/50/5, 2,000, 10/hour. Business $19 or $190, 25/200/25, 4,000, 15/hour. Agency $39 or $390, 100/500/50, 8,000, 25/hour. Unlimited is $99/month or $990/year. Annual Starter, Business, and Agency include two months free versus monthly. Solo is yearly only.

Cost, alternatives, and trade-offs

Approaches to email migration rollback plan
ApproachYou getYou give up
Exclusive MX + named aliasesDebuggable pathYou must delete leftovers
Dual MX backupFeels safeCoin-flip misses
From rewriteCosmetic SPFTrust and DKIM
Suite seatsHosted mailboxPer-user price

Field notes

Put the abort list in /migration-planner notes and in the ticket.

Related: /docs, /troubleshooting, /delivery-recovery.

Store screenshots outside a chat that expires.

If you abort, tell ESPs that cache MX. Some need hours.

Search demand for email migration rollback plan usually arrives as a screenshot, not a sentence. Ask for the received copy, the public MX set, and the plan name before you change a record. Email Migration Rollback Plan: Define Failure Before Cutover is a workflow, not a checkbox.

Write a one-paragraph policy the team can reuse for email migration rollback plan. Name the hop (inbound versus outbound), the proof artifact, and the thing you will not do (dual MX, From rewrite, second SPF record). Put the paragraph in the ticket template.

Change control matters more than a clever record. One person owns DNS for this domain. Adding an include, a selector, or a backup MX requires a ticket. Most regressions in email migration rollback plan are Friday edits without a probe.

Self-send remains invalid for email migration rollback plan. Gmail can short-circuit. Outlook can look local. Use a mailbox on another provider and a unique subject. If the customer refuses, the ticket stays open.

Leftover MX masquerades as every authentication and spam incident. If history is empty, email migration rollback plan is the wrong title until two resolvers agree on one product. Delete aspmx, Microsoft, and registrar MX. Wait TTL.

Free HOLD and missing aliases masquerade as outages. History shows the hold. Create the named local-part or accept that unknowns stay. Catch-all FORWARD is paid, optional, and a spam trade-off — not a debugger for email migration rollback plan.

Paid send-as is a different hop from inbound email migration rollback plan. Free cannot send. Unauthorized From is 550 / 550 5.7.1. Publishing prettier DNS will not authorize a From the product has not approved.

Destination filters still win after a clean hop. Email Migration Rollback Plan: Define Failure Before Cutover does not include an inbox placement SLA, review counts, or a Primary guarantee. Say that once, early, so the customer stops buying a story you cannot ship.

Proof packet for email migration rollback plan: public MX from two resolvers, inbound received copy with Header From, Authentication-Results, outbound received copy if they send, plan name, and the SMTP line if anything refused. That packet ends folklore.

Retention is 14 days on Free and 90 on paid. Export headers while they live. email migration rollback plan arguments without artifacts become myths. The destination inbox is the archive, not the hop store.

Agencies should not blend clients in one email migration rollback plan thread. One domain, one matrix, one MX screenshot. Agency plan limits are 100 domains, 500 aliases, 50 seats, 8,000 outgoing, 25/hour — still not unlimited, still not an SLA.

Security hygiene: no SMTP passwords in the email migration rollback plan ticket, no message bodies in chat, no invented SOC 2. Controls live on the Security and Trust Center. Secrets rotate if they leaked.

Related operations stay on real routes: forwarding, send-as, troubleshooting, tools, delivery recovery, docs, pricing. Do not invent a pillar. If email migration rollback plan is actually leftover MX, say leftover MX.

Refresh cadence is at least quarterly, sooner after a domain transfer, panel change, ESP trial, or dashboard host change. Email Migration Rollback Plan: Define Failure Before Cutover goes stale when the zone changes and the runbook does not.

If two products still share MX after you explained the coin flip, stop adding records. Exclusive MX is a hard stop. email migration rollback plan cannot be correct on a split path.

If Header From is already rewritten, stop tuning SPF for email migration rollback plan. Change the hop. MailerZ will not offer a From-replace control. Honest identity is the product.

If the customer wants a suite, sell the suite as Calendar and a hosted mailbox, not as a magic fix for email migration rollback plan. Workspace and Microsoft 365 are different architectures with their own filters and their own 550s.

Hourly and monthly send-as ceilings (disabled/1,000/2,000/4,000/8,000 outgoing; 5/10/15/25 per hour by plan) produce refuses that look like email migration rollback plan outages. Read counters before you republish DKIM.

Null MX plus a real MX is another lie. Remove the lone-dot refuse if you intend to receive. Empty inbound plus a pretty email migration rollback plan essay is still a refuse-all.

After you change anything, wait TTL, probe from another mailbox, and store the new received source next to the MX screenshot. Email Migration Rollback Plan: Define Failure Before Cutover is done when proof exists, not when the panel is green.

Field story 1 for email migration rollback plan: They aborted because history was empty and aspmx remained. Deleted leftover instead of rolling back. Correct — leftover was the abort signal. Keep that story in the runbook so the next person does not reopen Email Migration Rollback Plan: Define Failure Before Cutover from zero.

Field story 2 for email migration rollback plan: They rolled back by adding old MX beside new. Split got worse. True rollback would have removed MailerZ first if they chose old, or removed old if they chose new. Keep that story in the runbook so the next person does not reopen Email Migration Rollback Plan: Define Failure Before Cutover from zero.

Field story 3 for email migration rollback plan: No screenshot. Old host forgotten. They guessed aspmx values. Two hours of folklore. Keep that story in the runbook so the next person does not reopen Email Migration Rollback Plan: Define Failure Before Cutover from zero.

Field story 4 for email migration rollback plan: Abort owner was on a flight. Window slipped. Name two owners. Keep that story in the runbook so the next person does not reopen Email Migration Rollback Plan: Define Failure Before Cutover from zero.

Field story 5 for email migration rollback plan: Success declared on self-send. Stripe missed. Abort criteria had not required an external sender. Keep that story in the runbook so the next person does not reopen Email Migration Rollback Plan: Define Failure Before Cutover from zero.

For email migration rollback plan, symptom “Empty history” usually means Leftover or cached MX. Isolate it with Two resolvers. Do not stack a second change until that proof exists.

For email migration rollback plan, symptom “Unknowns missing” usually means Free HOLD. Isolate it with History hold. Do not stack a second change until that proof exists.

For email migration rollback plan, symptom “Header From rewritten” usually means Wrong hop. Isolate it with Received From. Do not stack a second change until that proof exists.

For email migration rollback plan, symptom “SMTP 550 send-as” usually means Free or unauthorized From. Isolate it with History line. Do not stack a second change until that proof exists.

For email migration rollback plan, symptom “spf=fail hop two” usually means Naive envelope. Isolate it with Return-Path. Do not stack a second change until that proof exists.

For email migration rollback plan, symptom “Still spam after clean hop” usually means Destination filters. Isolate it with Not an SLA. Do not stack a second change until that proof exists.

For email migration rollback plan, symptom “Self-send clean” usually means Short-circuit. Isolate it with Other mailbox. Do not stack a second change until that proof exists.

For email migration rollback plan, symptom “Wrong DNS panel” usually means NS ≠ registrar UI. Isolate it with NS lookup. Do not stack a second change until that proof exists.

Setup step “Inventory leftovers.” for email migration rollback plan: Screenshot current MX, SPF, DKIM, NS. Skip it and Email Migration Rollback Plan: Define Failure Before Cutover turns into a second ticket next week. Do the step, store the artifact, then continue.

Setup step “Verify the domain.” for email migration rollback plan: TXT as the dashboard states. Skip it and Email Migration Rollback Plan: Define Failure Before Cutover turns into a second ticket next week. Do the step, store the artifact, then continue.

Setup step “Create named aliases first.” for email migration rollback plan: Do not cut MX onto empty maps. Skip it and Email Migration Rollback Plan: Define Failure Before Cutover turns into a second ticket next week. Do the step, store the artifact, then continue.

Setup step “Publish one MX set.” for email migration rollback plan: Delete Google, Microsoft, registrar leftovers. Skip it and Email Migration Rollback Plan: Define Failure Before Cutover turns into a second ticket next week. Do the step, store the artifact, then continue.

Setup step “Prove from another mailbox.” for email migration rollback plan: Unique subject. Header From intact. Skip it and Email Migration Rollback Plan: Define Failure Before Cutover turns into a second ticket next week. Do the step, store the artifact, then continue.

Setup step “Only then send-as if paid.” for email migration rollback plan: Dashboard SPF/DKIM. Outbound probe. Skip it and Email Migration Rollback Plan: Define Failure Before Cutover turns into a second ticket next week. Do the step, store the artifact, then continue.

Setup step “Store the proof packet.” for email migration rollback plan: MX, hop, headers, plan name. Skip it and Email Migration Rollback Plan: Define Failure Before Cutover turns into a second ticket next week. Do the step, store the artifact, then continue.

Trade-off on email migration rollback plan: choosing Exclusive MX + named aliases gets you Debuggable path and gives up You must delete leftovers. Write that exchange on the quote so nobody pretends it is free.

Trade-off on email migration rollback plan: choosing Dual MX backup gets you Feels safe and gives up Coin-flip misses. Write that exchange on the quote so nobody pretends it is free.

Trade-off on email migration rollback plan: choosing From rewrite gets you Cosmetic SPF and gives up Trust and DKIM. Write that exchange on the quote so nobody pretends it is free.

Trade-off on email migration rollback plan: choosing Suite seats gets you Hosted mailbox and gives up Per-user price. Write that exchange on the quote so nobody pretends it is free.

Email Migration Rollback Plan: Define Failure Before Cutover is enough when You can staff exclusive MX and named aliases. If that condition is false, stop implementing email migration rollback plan and reopen the decision.

Email Migration Rollback Plan: Define Failure Before Cutover is enough when You will keep Header From intact. If that condition is false, stop implementing email migration rollback plan and reopen the decision.

Email Migration Rollback Plan: Define Failure Before Cutover is enough when You can probe from another mailbox. If that condition is false, stop implementing email migration rollback plan and reopen the decision.

Email Migration Rollback Plan: Define Failure Before Cutover is the wrong ticket when History is empty and leftovers remain. Name the correct system instead of forcing email migration rollback plan to cover it.

Email Migration Rollback Plan: Define Failure Before Cutover is the wrong ticket when You want an inbox placement SLA. Name the correct system instead of forcing email migration rollback plan to cover it.

Email Migration Rollback Plan: Define Failure Before Cutover is the wrong ticket when You plan to rewrite visible From. Name the correct system instead of forcing email migration rollback plan to cover it.

Write email migration rollback plan in the subject line of the ticket and the layer in the first sentence. If the layer is leftover MX, say leftover MX. If the layer is HOLD, say HOLD. If the layer is a destination 550, paste the text. Email Migration Rollback Plan: Define Failure Before Cutover stays short when the first sentence is honest.

Keep a standing calendar note for email migration rollback plan: monthly external probe, leftover MX lookup, and a glance at send-as counters if you are paid. Five minutes. The outage you avoid is the Friday dual-MX restore.

When two vendors disagree about email migration rollback plan, believe artifacts: two resolvers, one received copy, one history row. Do not believe the prettier admin center. Registrar dots lie. Composer UIs lie. Self-send lies.

Teach the next hire the MailerZ split before they touch email migration rollback plan: envelope may change, Header From must not, Free cannot send, unknowns HOLD, leftover MX is a hard stop, no inbox SLA, no SOC 2 sticker. That speech prevents a class of tickets.

If email migration rollback plan appears in an RFP, answer with published caps and hop evidence. Decline inbox-rate clauses. Decline fake certifications. Point at pricing and the Security and Trust Center. Email Migration Rollback Plan: Define Failure Before Cutover is not a place to invent enterprise theater.

Export while the 14- or 90-day window still has the email migration rollback plan hop. Future-you will not remember the SMTP sentence. The destination mailbox remains the archive. We will not grow the store because a blog asked.

Do not bundle unrelated edits with email migration rollback plan. Rotating SMTP while republishing MX while enabling FORWARD is how you lose the ability to name the failure. One change, one probe, one stored copy.

If you need a suite, buy a suite for Calendar and a hosted mailbox. If you need a hop, buy a hop. Email Migration Rollback Plan: Define Failure Before Cutover does not become Exchange because a quote stacked seats next to aliases.

FAQ

What is the safest way to handle email migration rollback plan?

Write abort signals, save old MX/SPF/DKIM, create aliases, cut exclusive, probe. If an abort signal trips, republish the old set. Do not add the old hosts beside MailerZ.

Does this require a new mailbox?

No. MailerZ is not IMAP and not webmail. Gmail or Outlook stays the store. Buy a suite seat only if you need Calendar and a hosted mailbox, not because this workflow failed.

Will it work with Gmail or Outlook?

Yes as a destination inbox when MX is exclusive and the alias exists. Header From stays the original sender on inbound. Paid send-as is a separate hop. Free has no send-as. Self-send from the same Gmail can hide failures.

What DNS records are involved?

Inbound: verification TXT, one MailerZ MX set, leftover MX removed. Outbound send-as: one SPF TXT, DKIM, and DMARC as the dashboard states. Two MX products split mail. Two SPF records permerror.

What should I test before production?

Prove inbound from another mailbox with a unique subject. Confirm Header From and history. If you send, prove paid SMTP to a third-party mailbox. Wait TTL after DNS deletes. Composer UI is not proof.

Key takeaways

  • Exclusive MX is a hard stop.
  • Header From stays the original sender.
  • SRS is envelope-only.
  • Free holds unknowns and cannot send-as.
  • 550 means read the text.
  • Self-send lies.
  • No inbox SLA.
  • 14- or 90-day store is not an archive.
  • MailerZ is not IMAP.
  • No SOC 2, ISO, or HIPAA claims.

Conclusion and next action

Define failure before cutover or you will invent it under load.

Next action: write three abort signals, save the old MX set, name two people, then schedule the window.

Ready to define failure

Start free, build the map, write the abort list.

Free is enough to rehearse inbound. Paid send-as can be window two.

Review quarterly, or sooner if DNS hosts or dashboard instructions change. Author: MailerZ editorial, Secuno LLC.