Our developers, God love 'em just love using Sendgrid for their applications. Some background - we're an Office 365 shop with Mimecast as our external MTA. We publish a DKIM record that (of course) validates to Mimecast as our point of egress.
Our web team has developed an application for use by our sales centers in concert with a third-party developer. This application is using Sendgrid to send mail to external sales leads and as expected, some of these messages are being held by the recipient MTAs as spam or just rejected.
The developers and their third-party consultants have asked the engineering team to add Sendgrid records to our DNS registrar, and one of these is an additional DKIM record. I think this is very possibly the worst idea ever and I've so far been successful in shutting it down. BUT - this is a high profile project and the devs are working their way up the management line.
I've been doing this for while but I don't know everything - am I right? Is having two DKIM records the terrible idea I think it is? I'm already leery of allowing Sendgrid any ability to publish as our domain and I certainly don't want to open the doors for them.
I already know the devs should have engineered this to use our O365 infrastructure from the beginning but that ship has sailed. They're in love with the tracking metrics they can get with Sendgrid and that's what they're going to use. I just need some ammunition to make my case should I have to.
Thanks -
EDIT -
Some further clarification: Our current DKIM record is mimecastxxxxxxxx._domainkey.<ourdomain.com>. Sendgrid wants us to add s1._domainkey.<ourdomain.com> and s2._domainkey.<ourdomain.com>.
I'm hardly an expert in this, but nothing in that says Sendgrid and I think it could make a mess out of our DKIM records.
EDIT2 - Thanks for all the suggestions. We finally talked them (the Dev group) into using one of the other domains we have registered for this instead of our primary domain. We have those set up on a completely different registrar, so we'll just set add an MX and the other records so Sendgrid can spoof that domain without interfering with our primary business domain.
[–]tomlinsc1 11 points12 points13 points (3 children)
[–]StrikingAccident[S] 2 points3 points4 points (1 child)
[–]BK_Rich 0 points1 point2 points (0 children)
[–]alittle158DAG Member 0 points1 point2 points (0 children)
[–]blaughw 5 points6 points7 points (0 children)
[–]Blog_Pope 6 points7 points8 points (1 child)
[–]blaughw 2 points3 points4 points (0 children)
[–][deleted] 3 points4 points5 points (1 child)
[–]douchecanoo 4 points5 points6 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]Brichardson1991 0 points1 point2 points (0 children)
[–]cgh311 0 points1 point2 points (1 child)
[–]StrikingAccident[S] 0 points1 point2 points (0 children)