Overview
TenantCore organizes your outbound infrastructure around a simple operating model:The TenantCore resource model
Tenant
A tenant is a Microsoft 365 environment connected to TenantCore. TenantCore uses the technical term tenant inside the application because that is the Microsoft 365 resource being managed. A connected tenant is the parent resource for its domains, mailboxes, sending limits, status/readiness data, and related automation. For the current bring-your-own-tenant experience, you must already own or administer the Microsoft 365 tenant you connect.Domain
A domain is a sending domain you already own and add to a connected tenant. TenantCore does not register or create domains for you. Once a domain is added, TenantCore can help you configure and monitor the Microsoft 365 DNS records required for sending, including:- MX
- SPF
- DMARC
- DKIM
Mailbox
A mailbox is a sending identity created under one of your TenantCore domains. Each domain can contain up to 3 mailboxes, and each tenant can contain up to 12 domains, for up to 36 mailboxes per tenant. TenantCore can manage the mailbox lifecycle, including:- creation
- deletion
- password reset and protected credential access
- MFA setup
- sending limits
- Outlook access
- sending-tool connection status
- operational and reputation status
Sending connection
A sending connection links a TenantCore mailbox to a supported sending tool. TenantCore keeps the connection associated with the mailbox so you can see its state, retry an interrupted connection, disconnect it, and manage the connection without treating the sending provider as a separate source of truth. Where a provider gives TenantCore the required access, TenantCore automates the connection workflow directly.The normal infrastructure workflow
Most TenantCore setups follow the same sequence:Connect your Microsoft 365 tenant
TenantCore starts with a Microsoft 365 tenant that you are authorized to administer. The connection flow uses Microsoft authorization rather than asking you to manually paste Microsoft administrator credentials into TenantCore. After consent is completed, TenantCore adds the tenant to your account and loads the resource and permission data needed for supported operations. A tenant must be connected to your TenantCore account before TenantCore can manage its domains or mailboxes.Add your domains
After the tenant is connected, add the domains you want to use for outbound mail. TenantCore treats each domain as a resource inside the connected tenant. That relationship matters because DNS setup, DKIM, mailbox creation, and API automation are all scoped through TenantCore ownership. A domain cannot be managed through TenantCore simply because someone knows its name. It must already belong to a tenant connected to the authenticated TenantCore account.Configure DNS
TenantCore supports two DNS setup paths.Automatic DNS
On supported plans and providers, TenantCore can configure the required DNS records for you. Current direct-provider paths include:- Porkbun
- Cloudflare
- Namecheap
Manual DNS
TenantCore can also show the exact records that need to be added at your DNS provider. After you publish them, TenantCore rechecks the domain and updates its readiness state. Manual DNS remains useful for unsupported providers or situations where provider API access is unavailable.Create mailboxes
Once the domain is ready for mailbox creation, create your mailboxes from TenantCore. TenantCore creates the mailbox in the connected Microsoft 365 tenant and keeps its TenantCore resource linked to the correct tenant and domain. Mailbox credentials and security state remain part of the mailbox workflow so you do not need to maintain a separate spreadsheet of identities and setup status.Secure and access mailboxes
Depending on how you use a mailbox, you may also want to configure:- password access or reset
- TenantCore-guided MFA
- mailbox sending limits
- Outlook access through a licensed Outlook sign-in account
Connect sending tools
Supported sending tools can be connected from TenantCore after the mailbox exists. TenantCore keeps the sending-tool connection associated with the mailbox so you can see whether it is Connected, Connecting, Needs attention, or Not connected. If a browser popup is closed or a connection is interrupted, the mailbox does not remain permanently locked. You can retry the connection. Providers that do not expose the access TenantCore needs may still require a manual connection workflow.Monitor what happens after setup
TenantCore continues monitoring and updating the infrastructure after setup is complete. Depending on the capability and plan, TenantCore can monitor or surface:- tenant service status and access
- DNS and authentication state
- mailbox sending usage
- sending IP or location changes
- sending-tool connection status
- bounce and spam-related reputation signals
- alerts and proactive notifications
- operational history in Reports
Tenant slots
A tenant slot is TenantCore capacity to connect and manage a Microsoft 365 tenant. A slot is not an included Microsoft 365 tenant. Base, Plus, and Complete each include 3 tenant slots for customer-supplied Microsoft 365 tenants. Additional tenant slots are available separately. Your plan also determines which automation, reporting, integration, and API capabilities are available.Bring-your-own-tenant is the current customer workflow
The current public TenantCore experience is built around bring your own tenant (BYOT). That means:- you provide the Microsoft 365 tenant
- you remain responsible for having authority to administer it
- you add domains you already own
- TenantCore automates and manages supported operations inside those connected resources