Email using Microsoft Graph API instead of Mailgun
Currently Gorelo is sending emails using Mailgun. Ok, nothing is wrong with this, but it means that emails are being sent outside of our ecosystem, which among other things, pulls it out of our security remit.
If we are monitoring our help mailbox for anomolous emails outbound at strange hours, we cannot do this now. If we want to set some mail flow rules that say between 7pm and 7am don’t allow emails to send to anyone other that [whitelisted domains]…. we cannot set such rules. if we want to monitor the outgoing flow of tickets by polling the graph API and making sure that ticket emails are actually firing off as expected, we cannot do this now.
On top of this, Mailgun is another third party that we have to whitelist with DKIM and SPF to allow to send. Again it’s not bad what is happening, but I feel it is unecessary and doesn’t need to happen. I come from a system where we just signed the PSA into MSFT Graph, and all emails were done through the graph API, keeping the security posture (conditional accesss etc.) all within our MSFT environment, including the aforementioned observability.
I hope I make sense, surprisingly English is my first language, and I still suck at it.
Log in to comment and vote
Comments1
Brown Oak
Does not let me modify content but to clarify, by unecessary I mean an unecessary function for Gorelo which can be offloaded to Microsoft. Then again, I just realised that perhaps it is incorrect to assume everyone is using MSFT for emails, and so probably there will always need to exist the Mailgun capability, I did not consider it. In anycase for me personally, I would feel a lot more comfortable being “in control of my destiny” if you will, by having that complete control over my email security and flow.
I like being able to run ‘s’ policies in my DMARC, I like running an ‘-’ in my SPF, a hardened posture that I like and cannot do all of it now because I need to allow subdomains to DKIM sign as my root and things like this.
For me it feels irresponsible for me to be just throwing emails into someone else’s system and praying they get delivered, I know we can look at email logs in settings, but if an NDR comes through or something how can we see it?
I hope it is not viewed as criticism, I’m not criticising because a lot of providers do exactly this same setup, I want to reiterate there is nothing ‘bad’ or ‘wrong’ with the Mailgun setup, I just would prefer more control, it feels like I’m having that control taken away from me if that makes sense, because I lost that capability when I switched to Gorelo I guess, so I have that “you never know what you’ve got till it’s gone” thing going on, I mourn the loss of my email observability & control, RIP.