Outbound Routing and Allowances

Backbuild Mail sends your outbound mail through your organization's own Resend account. Routing is chosen per sending domain: each domain you send from is linked to a Resend key and carries its own choice of which categories of mail travel through it, so one domain's setup never changes how another domain's mail is sent. This guide teaches you to verify your domain with Resend, connect your key safely, route your mail, prove the route works, and understand what Backbuild charges for sending. After this page your organization's outbound mail will be routed and verified.

Resend is the only sending provider today. Until a sending domain is set up with your organization's Resend account, outbound mail from that domain is not sent. A built-in Backbuild sender and other providers are on the roadmap and not available yet. Receiving mail does not depend on this: inbound mail to your verified domains arrives whether or not a sender is connected.

Outbound message Server derives the category transactional, system, marketing, or none Routed to your Resend account? your rule for this category Yes No Sent through your Resend signed for your verified domain Not sent route this category to Resend, or route All outbound
The server decides each message's category, so the route cannot be spoofed. A category routed to your Resend account sends, signed for your verified domain; a category with no route has no sender today.

Connect Your Resend Account

After this section you will be able to send outbound mail from Backbuild Mail. Your organization sends through its own Resend account, so you keep your sending reputation and your provider relationship, and nothing about your mail is locked to Backbuild. Repeat these steps for each domain you send from.

  1. Verify the domain in Resend. Resend sends only from a domain verified in your Resend account, so add the domain there and publish the DNS records Resend gives you at your DNS host. These records are what sign your mail for your domain. The Backbuild Mail setup wizard does not add them for you.
  2. Link your Resend key to the domain. In the domain's outbound setup, choose Resend and link your Resend API key through the secure vault-linking step. A key you store for all domains can be reused for each of your domains. The key is stored in the workspace vault and resolved when mail sends; it is never shown back to you or written to a log. Linking a key requires unlocking the vault, so only an authorized person can do it.
  3. Choose which categories route through it. Assign any combination of the categories below to the domain's Resend key. To send all of the domain's mail, choose All outbound.
  4. Test the connection. Test connection asks Resend whether it accepts the linked key. It does not check that the domain is verified in your Resend account; the end-to-end test in Prove the Route Works does.

The categories, called send-scopes, are:

  • All outbound: every outbound message from the domain, including every message you write in Backbuild Mail.
  • Transactional: mail a person's action triggers, such as meeting invitations and the help desk's automatic replies.
  • System: the domain's self-test messages.
  • Marketing: mail sent as marketing.

A message you write in the compose window carries none of the three narrower categories, so it sends only when the domain routes All outbound. A category you do not route to Resend has no sender today, so its mail is not sent. Route All outbound unless you have a reason to send only some categories.

The sender identity is always the mailbox the message is sent from, so you never configure a separate "from" name or address for the connection. You are only choosing the path the mail travels, not changing who it is from.

Which sending providers can I use? Resend, through your organization's own account. Other providers and a built-in Backbuild sender are on the roadmap and not available yet.

Will my mail send if I have not connected Resend? No. Until the domain is verified in your Resend account, linked to your Resend key, and the message's category is routed to it, outbound mail from that domain is not sent. Inbound mail still arrives.

Am I locked in? No. The Resend key lives in the vault, is never returned or logged, and you can replace or disconnect it at any time.

Categories Are Decided by the Server

After this section you will understand why routing cannot be tricked. The category of a message is derived by the server, not set by whoever sends the request. A caller cannot label a message to force it down a particular path, and, as covered in Composing and Sending, the From address and the identifying headers are set by the server based on the mailbox, so a message cannot be sent from an address the sender has no right to use. Routing follows the real category, every time.

How is the send category decided, and can a client spoof it to route the wrong way? The category is derived on the server and is not client-settable, and the sending identity is server-authoritative, so a caller cannot force a message onto the wrong route or send as an address it does not control.

Prove the Route Works Before You Ship

After this section you will be able to verify a route end to end. Send a message from a mailbox on the domain to an address you read in another mail program, confirm it arrives, and check that the receiving program shows it as authenticated for your domain. From code, a self-test mailbox on the domain sends a message along the route and lets your script confirm it arrives; see API and AI Agents.

How do I test that my sending route actually works? Send yourself a message at an address outside Backbuild, confirm it arrives, and check that authentication passes; from code, use the domain's self-test mailbox. Verify both inbound and outbound before you rely on the route.

On the Roadmap

These sending options are planned and not available yet: a built-in Backbuild sender, so mail can send without connecting a provider, with an included allowance and usage credits; and further providers beyond Resend. Today, sending requires your organization's own Resend account.

Allowances and Credits

After this section you will know what Backbuild charges for sending. Email at your own domain is included on every plan, not a per-seat upsell.

  • Mail through your Resend account: no Backbuild allowance applies and Backbuild does not charge for it; Resend bills it under your Resend plan.
  • The built-in sender: when the built-in Backbuild sender ships, an included allowance and usage credits will apply to mail sent through it.
  • Footer line: messages sent from a mailbox you create in the app carry a short footer line at the end of the message, naming the Backbuild free email service.

What does sending cost? Mail you send through your Resend account carries no Backbuild allowance and no Backbuild charge; Resend bills it under your Resend plan. An included allowance and usage credits will apply to the built-in Backbuild sender when it ships.

Related Guides