Skip to main content

Google Workspace Server-Side Setup

Route your outgoing Gmail through WiseStamp so signatures are applied in transit, identically on every device and every mail client.

How to set up server-side signatures

Server-side signatures are applied in transit, after the message leaves Gmail. Setup takes seven steps and is done once by your Google Workspace super administrator.

  1. Update authentication for every domain you plan to route. Add include:outbound.smtp.wisestamp.net to the domain's SPF record, and add the DKIM record WiseStamp provides. The wizard checks SPF for you and will not let you continue until each domain passes.

  2. Connect Google Workspace to WiseStamp so your employees and their details are imported. Server-side applies signatures to the people in your WiseStamp account, so they need to be there first.

  3. In WiseStamp, open Integrations, click Connect in the Server-side for all email platforms section, and select Google Workspace. Select the domains you want to route, click Connect, and copy the routing code the wizard gives you.

  4. In your Google Admin console, go to Apps > Google Workspace > Settings for Gmail > Hosts and add a route. This is the outbound route to WiseStamp, using your routing code and port 25.

  5. Configure the SMTP relay service so Google accepts the message back from WiseStamp, restricted to WiseStamp's IP addresses and to senders in your own domains, with TLS required.

  6. Add a content compliance rule that sends outbound and internal sending mail to that host and stamps each message with your routing code.

  7. Return to the WiseStamp wizard and click Connect. Then activate your user in WiseStamp and send a test email, including one from a phone, to confirm the signature is appended and that SPF and DKIM pass.

Your employees install nothing and change nothing on their devices. The exact values for steps 4 to 6 are supplied by the wizard and listed in the full configuration guide linked below.

What happens after you set it up

After the configuration is in place, every message sent from your domains passes through WiseStamp on its way out and arrives with the signature already applied.

  • Signatures appear on email sent from any device and any mail client, including phones, tablets, and apps that connect to your mail server. Nothing has to be installed per person or per device.

  • Because the signature is added in transit, it does not appear in the compose window or in the Sent folder. Hybrid mode keeps a signature visible while composing where a client-side signature exists, and applies the server-side one only when it does not.

  • Signatures are always current. The signature is built at send time, so a template change takes effect on the next message without anything being pushed to employees.

What your environment needs

Before you start, confirm the following:

  • Google Workspace, with super administrator access to the Google Admin console.

  • Server-side deployment on your WiseStamp plan. It is available on Platform and Enterprise.

  • SPF updated with include:outbound.smtp.wisestamp.net, and the DKIM record from WiseStamp added, on every domain you route.

  • Your employees in your WiseStamp account, with a signature assigned to each of them.

  • If you already route mail through another third-party service, be aware that Google processes routing, default routing, and content compliance rules in the order they were created, with no way to reprioritize them. Existing rules need to be removed and recreated around the WiseStamp rule.

What you are approving

Server-side deployment routes your outgoing mail through WiseStamp, so it is worth being precise about what that does and does not involve.

  • Mail travels over TLS in both directions. The relay is configured to accept mail only from WiseStamp's IP addresses, and only from senders in your own domains.

  • WiseStamp appends the signature and does not read or store the content of your email. Each account is processed in isolation.

  • Nothing is installed on your servers and no agent runs in your environment. The configuration is entirely settings in your own Google Admin console.

The setup is reversible at any time, and you keep the switch. Disabling the content compliance rule in your Admin console sends mail straight out without passing through WiseStamp, which takes effect immediately. Full security details are on the WiseStamp Security and Compliance page.

Routing only some domains or senders

To route only part of your organization, you can limit the routing to specific domains when you select them in the wizard, or narrow it further to specific senders or groups using the envelope filter on the content compliance rule. Everyone else sends mail exactly as they do today.

Choosing which signature goes out

Once server-side is connected, you decide which signature applies to which message from Integrations > Server-side > Signature rules. Each rule can target:

  • Senders: all employees, specific groups, or specific employees.

  • Email type: all messages, new messages only, or replies only.

  • Recipients: internal or external, either all of them or at least one.

When more than one rule matches a message, the rule with the higher priority number wins.

Did this answer your question?