Skip to main content

Overview

TenantCore organizes your outbound infrastructure around a simple operating model:
You bring the Microsoft 365 tenant and the domains you already own. TenantCore then gives you one place to configure, automate, secure, connect, and monitor the infrastructure built on top of them. This section explains how those pieces fit together before you connect your first tenant.

The TenantCore resource model

Tenant

A tenant is a Microsoft 365 environment connected to TenantCore. TenantCore uses the technical term tenant inside the application because that is the Microsoft 365 resource being managed. A connected tenant is the parent resource for its domains, mailboxes, sending limits, status/readiness data, and related automation. For the current bring-your-own-tenant experience, you must already own or administer the Microsoft 365 tenant you connect.

Domain

A domain is a sending domain you already own and add to a connected tenant. TenantCore does not register or create domains for you. Once a domain is added, TenantCore can help you configure and monitor the Microsoft 365 DNS records required for sending, including:
  • MX
  • SPF
  • DMARC
  • DKIM
Depending on your plan and DNS provider, setup can be automatic or manual.

Mailbox

A mailbox is a sending identity created under one of your TenantCore domains. Each domain can contain up to 3 mailboxes, and each tenant can contain up to 12 domains, for up to 36 mailboxes per tenant. TenantCore can manage the mailbox lifecycle, including:
  • creation
  • deletion
  • password reset and protected credential access
  • MFA setup
  • sending limits
  • Outlook access
  • sending-tool connection status
  • operational and reputation status

Sending connection

A sending connection links a TenantCore mailbox to a supported sending tool. TenantCore keeps the connection associated with the mailbox so you can see its state, retry an interrupted connection, disconnect it, and manage the connection without treating the sending provider as a separate source of truth. Where a provider gives TenantCore the required access, TenantCore automates the connection workflow directly.

The normal infrastructure workflow

Most TenantCore setups follow the same sequence:
You do not need to complete every optional step before creating useful infrastructure, but this sequence keeps the environment organized and reduces avoidable setup issues.

Connect your Microsoft 365 tenant

TenantCore starts with a Microsoft 365 tenant that you are authorized to administer. The connection flow uses Microsoft authorization rather than asking you to manually paste Microsoft administrator credentials into TenantCore. After consent is completed, TenantCore adds the tenant to your account and loads the resource and permission data needed for supported operations. A tenant must be connected to your TenantCore account before TenantCore can manage its domains or mailboxes.

Add your domains

After the tenant is connected, add the domains you want to use for outbound mail. TenantCore treats each domain as a resource inside the connected tenant. That relationship matters because DNS setup, DKIM, mailbox creation, and API automation are all scoped through TenantCore ownership. A domain cannot be managed through TenantCore simply because someone knows its name. It must already belong to a tenant connected to the authenticated TenantCore account.

Configure DNS

TenantCore supports two DNS setup paths.

Automatic DNS

On supported plans and providers, TenantCore can configure the required DNS records for you. Current direct-provider paths include:
  • Porkbun
  • Cloudflare
  • Namecheap
TenantCore plans the required records, applies supported changes, rechecks the domain in the background, handles the DKIM workflow when Microsoft makes it available, and updates the domain state as setup progresses. Automatic DNS availability can depend on provider account requirements. If automatic setup is not available, you can still use manual DNS.

Manual DNS

TenantCore can also show the exact records that need to be added at your DNS provider. After you publish them, TenantCore rechecks the domain and updates its readiness state. Manual DNS remains useful for unsupported providers or situations where provider API access is unavailable.

Create mailboxes

Once the domain is ready for mailbox creation, create your mailboxes from TenantCore. TenantCore creates the mailbox in the connected Microsoft 365 tenant and keeps its TenantCore resource linked to the correct tenant and domain. Mailbox credentials and security state remain part of the mailbox workflow so you do not need to maintain a separate spreadsheet of identities and setup status.

Secure and access mailboxes

Depending on how you use a mailbox, you may also want to configure:
  • password access or reset
  • TenantCore-guided MFA
  • mailbox sending limits
  • Outlook access through a licensed Outlook sign-in account
TenantCore-managed MFA is optional. A mailbox does not need to use TenantCore’s MFA workflow simply to exist or to connect to a sending tool. Native Outlook access is handled through Microsoft mailbox delegation rather than by licensing every individual sending mailbox.

Connect sending tools

Supported sending tools can be connected from TenantCore after the mailbox exists. TenantCore keeps the sending-tool connection associated with the mailbox so you can see whether it is Connected, Connecting, Needs attention, or Not connected. If a browser popup is closed or a connection is interrupted, the mailbox does not remain permanently locked. You can retry the connection. Providers that do not expose the access TenantCore needs may still require a manual connection workflow.

Monitor what happens after setup

TenantCore continues monitoring and updating the infrastructure after setup is complete. Depending on the capability and plan, TenantCore can monitor or surface:
  • tenant service status and access
  • DNS and authentication state
  • mailbox sending usage
  • sending IP or location changes
  • sending-tool connection status
  • bounce and spam-related reputation signals
  • alerts and proactive notifications
  • operational history in Reports
Reports provide the longer-term view of what happened across tenants, domains, and mailboxes.

Tenant slots

A tenant slot is TenantCore capacity to connect and manage a Microsoft 365 tenant. A slot is not an included Microsoft 365 tenant. Base, Plus, and Complete each include 3 tenant slots for customer-supplied Microsoft 365 tenants. Additional tenant slots are available separately. Your plan also determines which automation, reporting, integration, and API capabilities are available.

Bring-your-own-tenant is the current customer workflow

The current public TenantCore experience is built around bring your own tenant (BYOT). That means:
  • you provide the Microsoft 365 tenant
  • you remain responsible for having authority to administer it
  • you add domains you already own
  • TenantCore automates and manages supported operations inside those connected resources
TenantCore-managed tenant purchasing is not part of the current self-service workflow and should not be treated as a prerequisite for using the product.

Where to go next

Continue to Prerequisites to confirm what you need before setup. If you already have a Microsoft 365 tenant and sending domain ready, continue to Quickstart for the shortest path from a new TenantCore account to your first working mailbox.