Build the setup around business ownership
Use business-controlled contact details, billing, and recovery information throughout this guide. Keep a record of the domain registrar, Cloudflare account, Microsoft or Google tenant, administrator accounts, renewal dates, and support contact. DNS changes can interrupt websites and email. Before changing nameservers or mail records, copy the existing DNS zone and identify every service already using the domain. If the domain is already live and you are unsure, stop and get help.
Step 1: Buy a .nz or .co.nz domain
Choose a short, easy-to-spell name that matches the business. For a New Zealand audience, .nz or .co.nz is a strong default. InternetNZ operates the .nz registry, but domains are purchased through authorised registrars.
- Search for the .nz and .co.nz versions of your preferred name
- Choose an authorised registrar with clear renewal and account-recovery processes
- Register the domain to the business or its lawful owner—not a web designer or staff member
- Use a business-controlled recovery email and enable MFA at the registrar
- Record the registrar, account owner, renewal date, and billing method
Step 2: Pick Microsoft 365 or Google Workspace
Choose Microsoft 365 if your team expects Outlook, Teams, and desktop Office applications. Choose Google Workspace if browser-first Gmail, Drive, Docs, and Meet fit better. Both can provide business email on your domain. Allow roughly $20–30 NZD per user per month for a common small-business plan, but check current vendor pricing and whether desktop applications, storage, security controls, tax, or a commitment term changes the total. Create the first tenant with business-controlled recovery and billing details.
Step 3: Connect Cloudflare, then your workplace platform
Add the domain to Cloudflare and review the imported records before changing nameservers at the registrar. Once Cloudflare reports the zone as active, add the domain in Microsoft 365 or Google Workspace and copy the exact verification and mail records supplied by that platform into Cloudflare DNS. MX and TXT records are DNS-only. Mail-related CNAME records should also remain DNS-only unless the provider explicitly says otherwise. A wrong or missing record can interrupt delivery.
- Export or copy every existing DNS record before making changes
- Onboard the domain in Cloudflare and check the imported DNS records
- Replace the registrar nameservers with the two nameservers Cloudflare assigns
- Wait for Cloudflare to confirm the zone is active
- Add and verify the custom domain in Microsoft 365 or Google Workspace
- Publish the exact MX, TXT, and CNAME records shown by the chosen provider
- Test incoming and outgoing mail before removing any old service
Cloudflare full DNS setup · Microsoft 365 domain records · Google Workspace domain verification
Step 4: Set up MFA
Require multi-factor authentication for every user and administrator. Prefer an authenticator app, passkey, or security key over SMS where the platform and team support it. Enrol people before enforcing the policy so nobody is unexpectedly locked out.
- Protect the registrar, Cloudflare, Microsoft or Google, and password manager
- Use separate named administrator accounts where practical
- Give each person their own MFA method—do not share one-time codes
- Store recovery codes securely and test the recovery process
- Remove old phones and methods when staff or devices change
Step 5: Set up a business password manager
Choose a password manager designed for organisations, with user administration, access controls, audit information, and MFA. Create separate user vaults and shared collections rather than passing credentials around in email or chat.
- Choose a product that supports your devices and a business admin console
- Create a strong, unique master password
- Turn on MFA for the password manager
- Import or add business logins and replace reused passwords
- Define who can access shared credentials and who can recover the account
Step 6: Save recovery details and create a backup admin
Create a second administrator account that is not used for normal email or browsing. Protect it with its own strong password and MFA method. Securely store account ownership, recovery codes, support details, and the path for regaining registrar, Cloudflare, and workplace access. Do not keep the only recovery route inside the same mailbox it is meant to recover. At least two trusted people should understand where the handover record is and how to use it.
Step 7: Create your email accounts
Give each person a named account so access and MFA can be managed individually. Use shared mailboxes, groups, or aliases for role addresses such as accounts@ or info@ instead of sharing one person's password.
- Create a named account for each person who signs in
- Use the business domain as the primary email address
- Create role addresses as shared mailboxes, groups, or aliases
- Give only the required people access to each shared address
- Send and receive test messages internally and externally
- Document how accounts are added, changed, and removed
Step 8: Configure SPF, DKIM, and DMARC
List every legitimate sender first: Microsoft or Google, your website, accounting or CRM tools, newsletters, and SMTP2GO. Then follow each provider's current setup instructions. SPF identifies permitted sending infrastructure, DKIM signs mail, and DMARC tells receivers how to handle messages that fail aligned authentication. Publish only one SPF record. Enable DKIM for every service that supports it. Start DMARC with reporting where appropriate, review legitimate traffic, then move toward quarantine or reject without blocking valid business mail.
- Inventory every service that sends using your domain
- Publish one SPF record that reflects the active senders
- Enable and verify DKIM in Microsoft, Google, and other sending services
- Create a monitored DMARC reporting address
- Publish an initial DMARC policy and review the reports
- Tighten the policy after every legitimate sender passes alignment
- Run the Tier1 public email-domain check and record the result
Prevent your email from being spoofed · Check your public email-domain records
Step 9: Set up SMTP2GO for a scanner or website
Use SMTP2GO for devices and applications that need to send messages but cannot use your normal staff sign-in safely. Verify your sender domain, create a dedicated SMTP user for the device or application, and use the server and encrypted port shown in SMTP2GO's current instructions. SMTP2GO's sender-domain verification uses provider-supplied CNAME records to handle aligned SPF and DKIM. Do not create a second SPF record or copy another customer's records. Store SMTP credentials in the device or server configuration—not website source code.
- Create a business-owned SMTP2GO account and enable MFA
- Add the domain under Verified Senders and publish the supplied CNAME records
- Create a separate SMTP user for each device or application where practical
- Configure mail.smtp2go.com with an encrypted supported port
- Use a clear sender address such as scanner@ or website@
- Send test messages to internal and external recipients
- Record the owner, credential location, and how to revoke access
SMTP2GO verified sender domains · SMTP2GO server and port settings
Finish with a handover you can actually use
Record the domain and renewal, DNS provider, workplace tenant, licence count, administrator accounts, MFA and recovery process, mailbox list, legitimate senders, and support contact. Review it whenever a person, device, website, or sending service changes. If you would rather have Tier1 set up and support the environment, licences and support start from $65 + GST per month. Final scope and GST treatment are confirmed in your quote.
Sources and further reading
- Authorised .nz registrars — InternetNZ
- Set up a primary DNS zone — Cloudflare
- Troubleshooting email DNS records — Cloudflare
- DNS records for a Microsoft 365 domain — Microsoft
- Verify a Google Workspace domain — Google
- Set up Google Workspace MX records — Google
- Deploy 2-Step Verification — Google
- Use a password manager in your business — Own Your Online
- Prevent your email from being spoofed — Own Your Online
- Set up a verified sender domain — SMTP2GO
- SMTP settings — SMTP2GO
Frequently asked questions
Can I move an existing domain to Cloudflare without moving the registrar?
Yes. DNS hosting and domain registration are separate. You can usually keep the domain with the current registrar and point its authoritative nameservers to Cloudflare after copying and checking the full DNS zone.
Should staff share one email account to save money?
No for normal sign-in. Named accounts provide individual MFA, access history, and clean offboarding. Use a shared mailbox, group, or alias for a role address that several people need to monitor.
Should I publish DMARC reject immediately?
Only when you know every legitimate sender is authenticating and aligned. Starting with monitored reporting can reveal forgotten senders before you move toward quarantine or reject.
Should I add SMTP2GO to my existing SPF record?
Follow SMTP2GO's current verified-domain instructions. Its normal sender-domain setup uses CNAME records for aligned SPF and DKIM and says an existing SPF record does not need to be changed. Never publish a second SPF record.
Can Tier1 do all of this for us?
Yes. Tier1 can help select and supply licences, configure the domain and accounts, establish security and recovery controls, and provide ongoing support. Entry-level licences and support start from $65 + GST per month, subject to scope and a formal quote.