Hosting Multiple Email Domains on One Mail Server

Guides › Hosting Multiple Email Domains on One Mail Server · 2 min read 6 sections
1

One server, many domains: what actually has to be separate

Running several domains on one mail server is normal — a company with two brand names, a group with subsidiary domains, or an MSP hosting several small clients on shared infrastructure. The software side (a single SMTP/IMAP service handling multiple "virtual domains") is the easy part of most modern mail servers.

The part that actually needs planning is everything domains do not automatically share: DNS records, sending reputation, and who can see whose mailboxes.

2

DNS: MX, SPF and DKIM per domain

Every domain needs its own MX record pointing at the server, and its own SPF and DKIM records — these are per-domain by design and cannot be shared between domains even if they point at the same IP. A common mistake is configuring SPF/DKIM correctly for the first domain added and forgetting it for every domain added afterwards, which quietly hurts deliverability for those domains only.

If you have not set these up for each domain yet, see setting up DMARC, SPF and DKIM and repeat the process per domain.

3

Mailbox and user separation

Decide up front whether domains represent genuinely separate organisations (an MSP hosting unrelated clients) or one organisation with multiple brand domains (the same staff, multiple public-facing addresses):

  • Separate organisations. Users, admin access, and quotas should be domain-scoped so one client cannot see or administer another's mailboxes. Check this explicitly during setup — it is not always the default behaviour.
  • Same organisation, multiple domains. Users can often have addresses on more than one domain and share mailboxes; the main risk is accidentally sending externally from the wrong brand's address.
4

Reputation: one bad domain can affect the others

Authentication is per-domain, but the sending IP address is shared across every domain on the server. If one domain's mail gets flagged as spam, generates a lot of complaints, or gets a mailbox compromised and starts sending spam, receiving networks that weight IP-level reputation can start filtering mail from every domain on that server — not just the offending one.

This matters most for MSPs hosting unrelated clients: a compromised account belonging to one client can degrade delivery for every other client sharing the same outbound IP. Monitoring outbound volume per domain, not just per server, catches this early.

5

When to split into separate servers instead

Most small-business multi-domain setups are fine sharing one server and IP. Consider separate outbound IPs (or separate servers entirely) when:

  • Domains send meaningfully different volume or type of mail (a low-volume corporate domain versus a high-volume transactional or marketing domain) — mixing them puts the quiet domain's reputation at the mercy of the busy one's.
  • One domain belongs to a client whose compliance requirements (data residency, access isolation) genuinely require separation, not just labelling.
  • You are already seeing reputation problems traced back to one domain affecting delivery for the others.
6

How Hexamail Can Help

Hexamail Server supports multiple virtual domains with per-domain user separation, so unrelated organisations can share one installation without one seeing the other's mailboxes. Combined with Hexamail Guard's per-account outbound visibility, a reputation issue on one domain is easier to spot and isolate before it drags down delivery for every domain on the server.