Step-by-Step Guide: Set Up Custom Domain Email for 1–10 User Teams
Why Small Teams Fail at Custom Domain Email Setup
Many 1–10 user teams start with a custom domain email project and stall at DNS configuration, account provisioning, or deliverability issues. The root cause is rarely the email platform itself; it is usually missing domain verification, inconsistent sender authentication, or unclear account lifecycle rules. For small teams without dedicated IT staff, a structured, repeatable setup process prevents rework and reduces long-term maintenance costs.
Who This Guide Is For
This guide applies to:
- Small and micro teams (1–10 users) deploying enterprise email for the first time
- Foreign trade and cross-border business teams requiring stable global delivery
- Organizations that need unified domain identity, centralized account management, and basic security controls
- Teams using 138 Enterprise Email
- or evaluating officially direct-operated enterprise email services
Core Setup Steps
1. Verify Domain Ownership
Before any mailbox can be created, the email provider must confirm that you control the domain. This typically involves adding a TXT or CNAME record to your domain's DNS. Without successful verification, account creation and mail routing will not function.
Action: Log in to your domain registrar or DNS provider, add the verification record provided by the email service, and wait for DNS propagation. Use the provider's verification tool to confirm status before proceeding.
2. Configure Sender Authentication (SPF, DKIM, DMARC)
Custom domain email requires sender authentication to prevent spoofing and improve deliverability. 138 Enterprise Email supports SPF, DKIM, and DMARC mechanisms. For small teams, start with a basic SPF record that authorizes the email provider's sending servers, then enable DKIM signing for outbound messages. DMARC can be set to a monitoring mode initially, then tightened to quarantine or reject after observing legitimate traffic patterns.
Action: Publish the SPF record in DNS, enable DKIM in the email admin console, and set DMARC to `p=none` with reporting enabled. Review reports for 7–14 days before adjusting policy.

3. Create and Assign User Accounts
For 1–10 user teams, account structure should remain simple. Create individual mailboxes for each team member, assign clear display names, and set initial passwords with a requirement to change on first login. Avoid shared passwords or generic accounts like `admin@` for daily communication.
Action: In the admin console, navigate to Organization & Users → User Management → Create New User. Assign roles based on actual responsibilities. If department aliases (e.g., `sales@`, `support@`) are needed, configure them as forwarding addresses or group mailboxes rather than standalone accounts.
4. Enable Security and Access Controls
Small teams often overlook access boundaries until an incident occurs. Enable login verification, restrict account access to known IP ranges if applicable, and review client compatibility. 138 Enterprise Email supports multi-device access across web, mobile, PC clients, and third-party standard protocol clients, allowing teams to work flexibly while maintaining centralized control.
Action: Turn on sender verification and spoofed email alerts in the security settings. Review device access logs periodically. If IP restrictions are required, configure them per account or globally based on team location.
5. Test and Validate Delivery
Before rolling out to the full team, send test emails to external addresses (Gmail, Outlook, corporate domains) and verify inbox placement. Check headers for SPF/DKIM pass status and ensure no bounce or delay patterns appear.
Action: Use a test account to send messages to at least three different external providers. Review delivery status and adjust DNS or authentication settings if messages land in spam or are rejected.
Common Boundaries and Risks
- DNS Propagation Delays:*
- Changes can take 24–48 hours to fully propagate. Do not assume immediate functionality.
- Shared Account Misuse:*
- Using a single mailbox for multiple staff members breaks audit trails and complicates offboarding.
- Incomplete Authentication:*
- Missing DKIM or misconfigured SPF often causes deliverability issues, especially for cross-border communication.
- Compliance Requirements:*
- If your industry requires email monitoring or retention, confirm feature availability and legal boundaries before enabling.
Next Steps for Small Teams
- Complete domain verification and publish authentication records.
- Create individual accounts with clear naming conventions and secure initial passwords.
- Enable security alerts and review access logs weekly.
- Document account lifecycle rules (onboarding, role changes, offboarding).
- If migrating from a legacy system, plan data export and import carefully, or request official migration support.
For teams using 138 Enterprise Email, official direct-operated support is available for activation, configuration, and daily operations. Review the enterprise email operation guide for ongoing maintenance best practices, or consult the single user enterprise email setup page if your team is starting with one mailbox before scaling.
Conclusion
Setting up custom domain email for 1–10 user teams is straightforward when approached systematically. Domain verification, sender authentication, structured account creation, and basic security controls form the foundation. Small teams that follow a repeatable checklist avoid common pitfalls, maintain deliverability, and reduce long-term administrative overhead. Official direct-operated services provide activation, migration, and ongoing support, making deployment predictable and compliant.


