Set up SpamExperts incoming filtering and configure MX records

Reading time approx.: 9 minutes

With SpamExperts Incoming Filtering incoming emails are first routed through the SpamExperts filter infrastructure and checked there before accepted messages are forwarded to your actual mail server.

For this messaging path to work, two things in particular must be set up correctly: In SpamExperts, the correct Destination mail server be on file and the MX records of your domain must point to SpamExperts.

Important: Faulty MX records or an incorrect destination can impair the reception of your emails. Therefore, do not change these settings on a whim and make a note of the previous configuration before making any DNS changes.

How does SpamExperts Incoming Filtering work? #

Without upstream filtering, incoming messages are sent directly to the mail server responsible for your domain.

With SpamExperts, the message path is simplified as follows:

Sender
   ↓
SpamExperts
   ↓
Message check
   ↓
Destination
   ↓
Your mail server
   ↓
Mailbox

The MX records ensure that external mail servers use SpamExperts as the responsible system for incoming messages of your domain.

After processing, SpamExperts routes accepted messages to the one configured in SpamExperts Destination continue.

What you should check before the transition #

Before changing the MX records of your domain, the SpamExperts service for the domain in question should already be set up.

To do this, open your SpamExperts service via the CURIAWEB customer center and check that you are managing the correct domain.

We explain how to open the Control Panel under Login to the SpamExperts Dashboard via the CURIAWEB Customer Center.

Also check your domain's current DNS configuration and make a note of the existing MX records. This will make it easier to revert if an unexpected problem occurs during the transition.

1. Check destination in SpamExperts #

Before the MX records are switched to SpamExperts, you should first check where SpamExperts should forward accepted messages.

Open in the SpamExperts Control Panel the section for Incoming Filtering and there the administration of Destinations.

The destination refers to the actual target mail server behind SpamExperts.

Simplified:

SpamExperts
     ↓
Destination
     ↓
your mail server

Depending on the email infrastructure, a hostname of the mail server, for example, can be used as the destination.

A schematic example would be:

mail.example.ch

However, the destination that actually needs to be entered depends on your email infrastructure. Therefore, do not use any example value from this guide.

Attention: The destination must not simply be set to one of the SpamExperts MX hostnames. It must point to the actual mail server to which SpamExperts should forward your filtered messages.

Why the destination should be checked before the MX records #

As soon as the MX records point to SpamExperts, external mail servers can deliver their messages to SpamExperts.

If there is no correct destination available at this time, SpamExperts cannot properly forward the accepted messages to your actual mail server.

Therefore, the logical order is:

Domain present in SpamExperts
          ↓
Check destination
          ↓
Change MX records
          ↓
Wait for DNS update
          ↓
Test delivery

2. Change the MX records of the domain #

After the destination has been checked, the MX records of your domain must be switched to SpamExperts.

The MX records are located in the DNS zone of your domain. Where you manage them depends on which DNS provider or nameservers are used for your domain.

The following global MX records are used for SpamExperts Hosted Cloud:

PriorityHostname / Destination
10mx.spamexperts.com
20fallbackmx.spamexperts.eu
30lastmx.spamexperts.net

The lowest number has the highest priority for MX records. Therefore, mx.spamexperts.com with priority 10 used first.

3. Remove old MX records #

During a complete transition to SpamExperts Incoming Filtering, the previous MX records should be removed so that only the designated SpamExperts MX servers are published for incoming email traffic.

This is not only important for a unique delivery route.

If, for example, the direct hostname of your actual mail server also remains as an MX record, senders can attempt to deliver messages directly there and thereby bypass SpamExperts.

Important: Do not simply add the SpamExperts MX records in addition to the previous MX records. For a complete SpamExperts configuration, the old MX records must be removed so that incoming email traffic runs reliably through the filter.

Why are there three SpamExperts MX servers? #

Multiple MX records provide redundancy for receiving incoming emails.

Priorities determine the order in which sending mail servers should use the published MX targets.

PrioritySpamExperts-MX
10mx.spamexperts.com
20fallbackmx.spamexperts.eu
30lastmx.spamexperts.net

Therefore, all three entries belong to the intended global SpamExperts configuration.

4. Save DNS changes #

Save the modified MX records with your DNS provider.

Then check carefully again:

  • whether all three SpamExperts MX records are present
  • whether the hostnames are spelled correctly
  • whether the priorities 10, 20 and 30 voices
  • whether old MX records are no longer published

Even a typo in a DNS record can affect email delivery.

5. Wait for DNS update #

A change in MX records is not necessarily used immediately by all DNS resolvers worldwide.

How long old DNS information is still cached depends in particular on the previous TTL value and the DNS caches involved.

During this transition phase, it can therefore happen that some sending mail servers are already using the new SpamExperts MX records, while others are temporarily still working with cached DNS information.

Practical Tip: Do not judge a DNS change as failed just a few minutes after making it. Instead, check the publicly visible MX records and then the SpamExperts Log Search.

6. Check public MX records #

After the DNS change, you should check which MX records are publicly returned for your domain.

The expected result is:

10  mx.spamexperts.com
20  fallbackmx.spamexperts.eu
30  lastmx.spamexperts.net

If old MX records are still being displayed, you should first check whether they have actually been removed from the active DNS zone.

Send test email #

As soon as the new MX records are visible, send a test message from an external email account to an address on your protected domain.

For this, use an external sender if possible, rather than just two mailboxes within the same domain or the same mail server.

Make a note:

  • Sender address
  • Recipient address
  • approximate shipping time

You will then need this information for verification in SpamExperts.

8. Check message in Log Search #

Then open the Log Search in the SpamExperts Control Panel and looking for your test message.

If the message appears there, it has been processed by SpamExperts.

Log search is therefore one of the most important tools for checking a new incoming configuration.

We explain how to target and examine messages there at SpamExperts Log Search: Trace E-Mail History.

The message does not appear in the Log Search #

If a test message has arrived in the mailbox but does not appear in the SpamExperts Log Search, you should check which delivery route the message actually took.

Possible causes include, for example:

  • The MX record change is not yet effective everywhere
  • old MX records are still published
  • the actual mail server was addressed directly

In this case, check the publicly visible MX records again.

SpamExperts sees the message, but it does not arrive in the mailbox #

If the message appears in the Log Search, but SpamExperts cannot successfully deliver it to your mail server, the problem is likely behind the acceptance by SpamExperts.

Then check in particular:

  • the configured destination
  • whether the destination mail server is reachable
  • whether the destination mail server accepts the message
  • whether a temporary or permanent SMTP error message is displayed

In case of temporary delivery issues, SpamExperts can hold messages in a delivery queue and make further delivery attempts.

What is the incoming delivery queue? #

If SpamExperts cannot deliver an accepted message to the destination due to a temporary issue, the message can be temporarily stored in the Incoming Delivery Queue remain.

This can occur, for example, if the destination mail server is temporarily unreachable or returns a temporary SMTP error message.

Therefore, a message in the queue does not automatically mean that it has been lost.

For such problems, the destination and subsequently the availability or response of the target mail server should be checked first.

Prevent direct delivery bypassing the spam filter #

Even if the public MX records point exclusively to SpamExperts, the actual destination mail server can still technically be directly accessible from the Internet.

If its hostname or IP address is known, senders might try to deliver messages directly to this server and thereby bypass the upstream spam filter.

If your mail server infrastructure supports this, it should therefore be checked whether incoming SMTP connections to the target mail server can be restricted to the official SpamExperts delivery systems.

Attention: Firewall or mail server rules must not be set up using a copied list of old IP addresses from somewhere. Use exclusively the delivery IP ranges currently published by SpamExperts or the values specified by your provider. Incorrect restriction can completely block legitimate email delivery.

Keep old MX records as a fallback? #

No, the previous mail server should not simply remain as an additional MX record with a lower priority.

This would publish an alternative direct delivery path through which SpamExperts can be bypassed.

The redundancy for the public acceptance of messages is already provided by the intended SpamExperts MX records.

Destination and MX record are not the same #

These two settings are often confused.

SettingTask
MX recordTell the internet that incoming emails should first be sent to SpamExperts.
DestinationTells SpamExperts to which actual mail server accepted messages should be forwarded.

The complete path is therefore:

Sender
   ↓
DNS / MX
   ↓
SpamExperts
   ↓
Destination
   ↓
Mail server
   ↓
Mailbox

Common setup errors #

Old MX records were not removed #

This allows a direct delivery path to the previous mail server to continue to exist. As a result, messages can bypass SpamExperts.

Wrong destination #

SpamExperts can accept messages, but cannot forward them to the correct mail server.

MX and Destination were mixed up #

The SpamExperts MX hostnames are intended for the public DNS configuration. The destination, on the other hand, describes your actual target mail server.

MX priorities were misunderstood #

For MX records, it means lower numerical value means higher priority.

DNS change is evaluated too early #

Cached DNS information can cause the transition not to be visible everywhere at the same time.

Multiple settings were changed at the same time #

If MX records, destination, firewall, and other mail server settings are changed at the same time, misconfigurations are significantly more difficult to isolate afterwards.

Practical Tip: Work in a controlled manner during a mail server migration. Change one component, check the result, and document the change before adjusting the next area.

What is changing in the email program? #

For the Incoming Filtering normally you don't have to change any settings in Outlook, Apple Mail, Thunderbird, or another e-mail program.

Your email program continues to connect to your previous mail server.

SpamExperts works prior to that at the level of incoming server-to-server delivery.

The change therefore primarily affects:

DNS / MX
+
SpamExperts
+
Destination mail server

and not the IMAP or POP3 connection of your e-mail program.

Incoming Filtering is not Outgoing Filtering #

The MX records described here concern incoming emails.

You do not automatically configure outgoing shipping via SpamExperts.

For outgoing filtering, the outbound message path is set up separately.

You can find the corresponding instructions at Set up SpamExperts Outgoing Filtering.

Check quarantine after activation #

After a new SpamExperts setup, you should regularly check the log search and spam quarantine during the first few days.

This is how you can quickly tell if legitimate messages are unexpectedly classified or withheld.

We explain how to work with withheld messages under Using Spam Quarantine in SpamExperts.

Do not set filters to be more aggressive immediately #

After the setup, you should not tighten the filter settings as a precaution.

The default configuration initially provides a sensible starting point. If a specific message is misclassified, first investigate the concrete case using Log Search.

We cover how the filter settings work under Configure SpamExperts filter settings correctly.

Post-conversion checklist #

A correctly configured incoming filtering should meet the following points:

  • The correct domain is set up in SpamExperts.
  • The correct destination is saved.
  • The three designated SpamExperts MX records have been published.
  • Old public MX records have been removed.
  • An external test email appears in the SpamExperts Log Search.
  • The accepted test message is forwarded to the destination mail server.
  • The message then reaches the expected mailbox.

Summary #

For SpamExperts Incoming Filtering, incoming emails must first be routed through the SpamExperts infrastructure. This is done via the MX records of your domain.

The recommended global SpamExperts MX records are:

10  mx.spamexperts.com
20  fallbackmx.spamexperts.eu
30  lastmx.spamexperts.net

Equally important is the correct Destination. It determines to which actual mail server SpamExperts forwards accepted messages.

After the switch, you should check the publicly visible MX records, send an external test message, and verify its processing in the log search.

If SpamExperts sees the message, but it does not arrive at the destination mail server, investigate the destination and the displayed delivery status. If the message does not appear in SpamExperts at all, check the actual MX and delivery path first instead.

Last updated August 28, 2026
Was this article helpful?
Cookie Consent with Real Cookie Banner