Business Role Addresses

How to set up legal@ and keep delivery evidence

Route legal@ cleanly. Do not call a hop store a legal hold. Counsel keeps the archive.

MailerZ editorial · Secuno LLC17 min read

Legal email delivery routing is a named legal@ alias into a counsel or founder store you can defend, plus evidence of hops this layer actually saw. Create the name before you print it on a policy page. Exclusive MX. Probe from another mailbox. MailerZ delivery recovery is 14 days on Free and 90 days on paid — hops, not Vault, not legal hold, not HIPAA, not SOC 2. If counsel needs eDiscovery, buy eDiscovery. Header From stays. Envelope SRS only. Confirm /pricing. Do not fan-out legal@ to the whole company.

legal@ to counsel store
One dest you can defend.

Quick answer for legal email delivery routing

Create legal@ as a named alias to counsel’s mailbox. Exclusive MX. Probe with a unique subject. Keep hop history for the published window. Keep the real archive in counsel’s store or a hold product. That is legal email delivery routing.

Guide: print after probe. Setup: one dest, maybe a dated second copy. Best practice: do not invent compliance badges.

A leftover miss has no history. Cut leftovers first.

Send-as as legal@ is rare and paid. Most legal@ is receive-only.

MailerZ Free is one domain, ten aliases, one seat, a 14-day store, send-as Off, SMTP Off, API Off, and unrouted mail held or rejected only. Solo is $40 per year only, with send-as, SMTP, and API On. Starter is $8 monthly or $80 yearly. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm numbers on MailerZ pricing. Limits are not an inbox-placement promise. Hop rows and recoverable copies live in Mail Box for the published window. Field maps: MailerZ documentation. Counsel still owns legal hold. MailerZ is hop evidence, not a vault.

Google’s own Send mail as steps live in Google Gmail Help — Send mail from a different address. Workspace as a product is described on Google Workspace — product overview. Transport still follows IETF RFC 5321 — Simple Mail Transfer Protocol.

legal email delivery routing guide: the real decision

Printed legal@ before the alias existed.

Called 14-day store a hold.

Fan-out to five founders.

Criteria: named alias, exclusive MX, unique probe, honest evidence window.

Evidence versus archive
ThingMailerZCounsel
Hop codesHistory / recoveryNot a substitute
Message bodyForwarded intactTheir mailbox / hold
14 / 90 daysThis layer’s hopsNot eDiscovery
HIPAA / SOC 2NoBuy if the matter needs it

Prove inbound from another mailbox before you print hello@ on a homepage.

Start free — one domain

Technical mail flow for legal email delivery routing

Public legal@ → named map → counsel store. Header From stays the sender.

History records hops this layer accepted. Leftover MX never appears.

Outbound as legal@ is hop five if you enable it. Most teams should not.

Self-send is not evidence you can show a third party.

MailerZ is inbound MX plus authenticated SMTP from Secuno LLC. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME are never rewritten. Not Google Workspace, not IMAP or POP, not an open relay. Unauthorized send is SMTP 550 / 550 5.7.1. Leftover MX is a hard stop. Self-send from Gmail to the same Gmail account can hide routing errors. Not SOC 2, not ISO 27001, not HIPAA.

Hop store versus legal hold
90 days is not Vault.

legal email delivery routing setup

Ask counsel where the archive lives. Then create the alias. Then print.

  1. Name counsel’s destination mailbox.
  2. Create legal@ (and privacy@ or dpo@ if you print them).
  3. Exclusive MX. Delete leftovers.
  4. Probe from another mailbox. Save subject, history, Message-ID.
  5. Confirm Header From intact.
  6. Leave send-as off unless counsel must reply as legal@.
  7. Export or retain in the store counsel named. Do not rely on 14 or 90 days.
  8. When counsel changes firms, remap dest. Do not share the old password.

Failure modes and proof

Printed first.

Hop store as hold.

Invented HIPAA.

Five dests.

Leftover MX, empty history, “we never got it.”

Leftover MX is the usual ghost. Check a public lookup before you blame Gmail.

Open leftover MX troubleshooting

MailerZ workflow and product boundary

Related: aliases and catch-all, use cases, send and reply, pricing. Security page for the questionnaire.

Delivery recovery is hops. Related troubleshooting if leftovers ate the notice.

Related pages: aliases and catch-all, use cases, send and reply, and pricing.

Unique subject as evidence
Probe before you print the policy URL.

legal email delivery routing best practice

legal@ is one alias. A hold product is a different invoice. Solo or Business buys a longer hop window, not Vault. Confirm pricing. Do not sell 90 days as legal hold to a customer.

Competitor blogs may talk logs. Cite nofollow. Do not invent their retention.

MailerZ Free is one domain, ten aliases, one seat, a 14-day store, send-as Off, SMTP Off, API Off, and unrouted mail held or rejected only. Solo is $40 per year only, with send-as, SMTP, and API On. Starter is $8 monthly or $80 yearly. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm numbers on MailerZ pricing. Limits are not an inbox-placement promise. Hop rows and recoverable copies live in Mail Box for the published window. Field maps: MailerZ documentation. Counsel still owns legal hold. MailerZ is hop evidence, not a vault.

Field notes you can reuse

security@ / vulnerability reports is a sibling article.

privacy@ may be required on a policy page — create it if you print it.

Agencies: per-client legal@, per-client counsel dest.

Quarterly leftover review is how notices vanish.

Do not put privileged files in a ticket with SMTP secrets.

Two-founders copy is not a hold.

The incident postmortem template is ops. This is the role.

DPA and subprocessors pages exist. Link humans there. Do not invent processors.

Deeper field notes for legal email delivery routing

Evidence you can swear to, and evidence you cannot

Legal email delivery routing has two piles. Pile one: hops this layer accepted — timestamps, destination SMTP replies, a unique subject you sent as a probe. MailerZ can show that for fourteen days on Free and ninety on paid. Pile two: the message body in counsel’s mailbox, a hold product, or an export counsel named. MailerZ is not pile two. Calling pile one a legal hold is how you lose a credibility argument. Not Vault. Not HIPAA. Not SOC 2. Not eDiscovery.

If leftover MX ate the notice, pile one is empty. There is nothing to recover. That is why exclusive MX is a legal-ops issue, not only an IT issue. Public lookup. Delete leftovers. Then create legal@. Then probe. Then print the address on the policy page.

Who owns legal@

One counsel dest you can name in a sentence. A dated second dest if the founder must see a copy. Not five partners. Not catch-all. Not the agency shared inbox. When counsel changes firms, remap. Do not forward-from-old-counsel-Gmail as a forever plan. The alias stays. The dest changes.

privacy@, dpo@, and legal@ are different printed strings if your policy names them. Create what you print. Hold the rest. security@ for vulnerability reports is a sibling runbook — do not merge it into legal@ unless counsel said so.

What to save when you probe

Unique subject, UTC timestamp, sending mailbox (not the dest), public MX screenshot or text, MailerZ history row, destination Message-ID, Header From intact. That is a probe packet. Self-send is not a packet you can show a third party. After a dest or MX change, send a new subject. Do not reuse the old one as if it were new evidence.

Do not mail SMTP passwords with the packet. Do not put privileged attachments in the same ticket as credentials.

Send-as as legal@ is usually wrong

Most legal@ is receive-only. If counsel must reply as legal@, that is paid send-as, one secret, rotate on firm change. Free 550 is honest. Do not put legal@ SMTP in a marketing plugin. Do not use legal@ as the site’s contact form From.

Retention honesty on sales calls

You may say: we store delivery hops for fourteen or ninety days depending on plan. You may not say: we are your legal hold. You may not say: SOC 2. You may point at /security, /privacy, /terms, /data-processing, and /subprocessors. Confirm those pages. Do not invent processors.

Competitor blogs may claim logs. Nofollow. Quote them if you must. Do not copy their retention onto this product.

Agency and multi-brand

Per-client legal@, per-client counsel dest, per-client leftover cut. A validated zone A does not prove zone B. Nameserver templates that restore Google MX are how a client’s privacy notice becomes a hole. Quarterly leftover review is counsel-adjacent ops.

When you need a real hold product

Litigation hold, regulated mailbox, or counsel said so. Buy that product. Map legal@ there if that is the dest. MailerZ can still be the hop if exclusive MX points here and the dest is the hold mailbox. Or the hold product owns MX — then delete MailerZ leftovers. One inbound owner. The hop store is still not the hold.

A complete worked story

The notice that never had a hop

A privacy notice listed legal@yourdomain. The alias did not exist. Google leftover MX still answered. Counsel said they never got the letter. MailerZ history was empty because hop one never ran. They created legal@, cut leftovers, probed with a unique subject, and kept counsel’s mailbox as the archive. The next notice had a history row. The first one never would.

Operator brief

A longer operator brief for legal email delivery routing

Teams that bookmark How to Set Up legal@ and Keep Delivery Evidence usually arrive after a missed invoice, a form that never notified anyone, or a migration that looked clean in one resolver. The useful brief is still boring. Name the store. Name the printed local-parts. Name the nameservers that actually answer. Publish one MailerZ MX set. Delete leftover hosts. Probe from a mailbox that is not the destination. Only then talk about legal email delivery routing as a send-as, catch-all, or comparison problem.

MailerZ remains inbound MX plus authenticated SMTP around Gmail or Outlook. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME stay intact. It is Mail Box portal webmail, not IMAP, not POP, and not an open relay. Unauthorized send is 550 / 550 5.7.1. Free cannot finish send-as: SMTP and API stay off. Solo is $40 per year when the domain From must travel. Starter is $8 or $80. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm the live pricing page. Those numbers are ceilings, not an inbox-placement service-level agreement.

If leftover Google, Microsoft, Cloudflare routing, or registrar MX is still public, stop widening legal email delivery routing. The map you built never saw that copy. Priority numbers are an order, not load balancing. A higher preference host is idle while a leftover host still accepts mail. Save the old MX set before you delete anything. Check more than one public view because TTL lies.

Catch-all forward is not a safety feature for how to set up legal and keep delivery evidence. Hold unknowns on everyday production. Review the store. Promote a leftover only when a real person used it. Paid forward belongs to a dated cutover. Fan-out of unknowns into two inboxes trains two spam buttons. Plus addressing on Gmail is not a custom-domain unknown policy. MailerZ will not strip plus tags on your domain the way Gmail does on @gmail.com.

Send-as is a second hop. Creating an inbound alias does not approve outbound. Catch-all does not mint a From. Copy the dashboard host, port, and TLS pair together. Set From to an identity you created. Do not paste a Gmail password into a CMS, a cron file, or a ticket. Do not mail SMTP secrets to support. Send a 550 line, a timestamp, and a Message-ID. Rotate if a secret already leaked.

Self-send from Gmail to the same Gmail account can short-circuit. That green result is why people swear legal email delivery routing works while customers vanish. Use a second provider. Put a unique subject on the probe so delivery history is searchable. If Header From was rewritten by some other forwarder, authentication stories get noisier. MailerZ does not rewrite Header From on inbound.

Agencies should keep legal email delivery routing per client zone. Separate SMTP credentials. Do not pour every client into one catch-all because the spreadsheet got long. Agency plan capacity exists so you can hold more domains and aliases. It does not replace a named list. Offboard means delete MX you own, revoke SMTP, and stop forwarding leftovers into the agency inbox.

Legal and security questions have published answers on the security, privacy, terms, DPA, and subprocessors pages. MailerZ is not SOC 2, not ISO 27001, and not HIPAA. The 14-day Free store, the 90-day Solo–Agency store, and the 180-day Unlimited store are recovery windows for hops this layer saw. They are not an archive and not legal hold. If counsel wants eDiscovery, buy eDiscovery.

Comparisons only help after the hop is honest. Cloudflare Email Routing is inbound routing. A privacy-mask product hides a destination on a provider domain. A suite hosts mailboxes, Calendar, and admin. Proton-class mailboxes encrypt a store. MailerZ is the delivery layer when you already have Gmail or Outlook and you need a domain route you can prove. Cite the other product’s documentation. Do not invent feature parity.

When How to Set Up legal@ and Keep Delivery Evidence is closed, the next physical action is a lookup and a probe, not another tab. Start free on one domain you can break. Sign in if the zone already lives here. Review quarterly, or sooner after a nameserver move, a plugin swap, or a staff departure. That is how legal email delivery routing stays a runbook instead of an incident.

A second worked pass for legal email delivery routing: write the last change on a sticky note before you open the dashboard. Nameserver move, leftover MX, new form plugin, contractor laptop, or a registrar forwarding toggle are the usual five. MailerZ history only shows hops that reached this layer. If the sticky note says leftover MX, you do not have a legal email delivery routing mystery. You have a split. Delete the leftover. Wait for TTL. Probe again.

A third worked pass: print the public list. If you cannot print it, you are not ready for production unknowns and you are not ready for a bigger alias ceiling. Unlimited aliases as marketing will not save a missing list. Three named aliases on Free are enough to stop printing a personal Gmail on a homepage. Grow the list when a real person used a leftover, not when a harvest guessed admin@.

Policy-page strings you must create before publish

Legal email delivery routing includes every address the policy names: legal@, privacy@, dpo@, sometimes counsel@yourdomain. If the page lists them, the map must list them. Publishing first and creating later is how the first GDPR-style notice has no hop. Probe each printed name. Save the packet. Then ship the page. Internal links to /security, /privacy, /terms, /data-processing, and /subprocessors should match what those pages actually say. Do not invent a DPO if you do not have one.

A contact form that mails legal@ as the From is a send-as problem, not a routing win. Forms should send to legal@ as the destination, from a mailbox or a paid SMTP identity you intended. Free 550 on a “contact legal” form is a plan miss. Split the ticket from leftover MX.

What to give counsel on day one

Here is the dest mailbox. Here is last probe subject and history. Here is the public MX text. Here is how long we keep hop records on this plan. Here is what we will not call this: legal hold, HIPAA, SOC 2. Here is who remaps if you change firms. Here is /contact for operational mail that is not a notice. If counsel wants a hold product, they name it. We will point MX or the dest at whatever they named — one inbound owner, never both.

If counsel wants everything in a suite mailbox, that can be the dest while MailerZ owns MX, or the suite can own MX. Write the sentence. Dual MX is not a compromise that protects notices. It is how notices vanish.

Abuse of legal@

Once printed, legal@ gets spam and sometimes threats. Hold extras. Do not catch-all. If the name is abused, you can disable it and print a dated replacement — after counsel agrees, because the old string is on PDFs. That is a policy change, not a silent dashboard click. Delivery history of abuse is still hops, not a police report.

Competitor blogs may tell you to “just forward legal@.” Nofollow. The missing half is exclusive MX, a probe packet, and honesty about the store. RFC 5321 does not create a hold. Google’s Workspace page does not make MailerZ into Vault.

FAQ

What is the safest way to handle legal email delivery routing?
Create legal@ as a named alias to counsel’s existing mailbox. Exclusive MX. Probe from another mailbox and keep hop history. The 14-day or 90-day store is hops this layer saw, not legal hold. Buy a hold product if counsel needs one. Do not invent HIPAA or SOC 2.
Does this require a new mailbox?
No. MailerZ is Mail Box portal webmail (Inbox, Sent, New email). It is not IMAP or POP. Gmail or Outlook remains the store unless you separately buy a hosted mailbox product.
Will it work with Gmail or Outlook?
Yes for inbound when the destination is a verified mailbox. Branded replies need paid send-as plus Gmail Send mail as or a manual Outlook SMTP identity. Free has no send-as.
What DNS records are involved?
A verification TXT, one MailerZ MX set on the authoritative nameservers, leftover host MX removed, and SPF, DKIM, and DMARC if you also send as the domain.
What should I test before production?
Send a uniquely titled message from an unrelated provider into each named alias. Confirm Header From and delivery history. Do not email yourself from the same Gmail account.

Key takeaways

  • Named legal@.
  • Counsel dest.
  • Exclusive MX.
  • Probe as evidence.
  • Hops ≠ hold.
  • No HIPAA claim.
  • Print after prove.
  • Remap on counsel change.

Conclusion and next action

Set up legal@ so notices have a hop you can show. Keep delivery evidence for the published window. Keep the archive where counsel said. MailerZ will not become Vault. Cut leftovers. Probe. Then print the address.

Start free. Sign in if legal@ is already on a policy page and history is empty.

Name legal@ on purpose

Start free, create legal@, prove history and the destination, then print the address.

Do not call the hop store a hold.

Review quarterly, or sooner if Gmail, Workspace, or MailerZ scope changes. Author: MailerZ editorial, Secuno LLC.