Mailboxes (Gmail and Microsoft 365)
Connect sending mailboxes, how warm-up and send windows work, and the DNS checks that gate sending.
SignalDock sends outreach from your own mailboxes, never from a shared pool. Connect them under Settings → Mailboxes. Owners and admins only.
Connecting
- Choose Connect Google Workspace or Connect Microsoft 365.
- Grant consent. SignalDock asks for:
- Google:
gmail.send,gmail.readonly(reply detection),calendar.eventsandcalendar.freebusy(meeting booking). - Microsoft:
Mail.Send,Mail.ReadWrite,Calendars.ReadWrite, andoffline_access.
- Google:
- You return to the settings page. The refresh token is stored in Supabase Vault and never returned by the API. Disconnecting deletes the token.
Reconnecting the same address keeps its warm-up progress.
Warm-up, caps, and send windows
| Setting | Default | Meaning |
|---|---|---|
| Warm-up start | 5 | Sends allowed on the first day. |
| Per day + | 3 | Extra sends allowed each following day. |
| Daily cap | 30 | Upper limit once warm-up is done (max 500). |
| Send window | 08:00 to 17:00 | Local hours, weekdays only. |
| Timezone | Europe/Amsterdam | Used for the window and for "sent today". |
Sequences wait for the next window instead of sending at night or at the weekend, and move on to another mailbox when one reaches its cap.
DNS health
On connect and on Re-check DNS, SignalDock looks up the sending domain:
- SPF: exactly one record, ending in
-allor~all. - DKIM: a key for the provider's default selector (
google, orselector1/selector2for Microsoft). - DMARC:
p=quarantineorp=rejectpasses;p=noneis a warning. - MX: required so replies arrive.
A mailbox is only used for sending once SPF, DKIM, and MX pass.
Reply detection
Each mailbox is checked for replies every 15 minutes. With push notifications configured, replies are picked up within seconds:
- Microsoft 365: SignalDock creates a Graph subscription on the inbox
pointing at
https://<api host>/api/webhooks/microsoft, and renews it before it expires. Each notification carries a signedclientStatethat is checked before syncing. - Gmail: create a Pub/Sub topic, grant
gmail-api-push@system.gserviceaccount.comthe Publisher role on it, and add a push subscription tohttps://<api host>/api/webhooks/gmail?token=<push token>. The push token is the hex HMAC-SHA256 ofgmail-pushkeyed withMAILBOX_WEBHOOK_SECRET.
Only answers to SignalDock outreach are stored; see replies.
Microsoft limitations
Microsoft Graph only accepts custom headers that start with x-, so
List-Unsubscribe headers are not set for Microsoft 365 mailboxes. The
unsubscribe link in the footer is always included.
Self-hosting
Set these on the API service:
| Variable | Purpose |
|---|---|
GOOGLE_OAUTH_CLIENT_ID | Google OAuth web client. |
GOOGLE_OAUTH_CLIENT_SECRET | |
MICROSOFT_OAUTH_CLIENT_ID | Entra ID app registration (multi-tenant). |
MICROSOFT_OAUTH_CLIENT_SECRET | |
OAUTH_STATE_SECRET | 32+ random characters; signs the OAuth state. |
MAILBOX_OAUTH_REDIRECT_URI | Optional. Defaults to https://<api host>/api/oauth/mailbox/callback. |
MAILBOX_WEBHOOK_SECRET | Optional. 32+ random characters; enables push notifications. Without it, mailboxes are polled. |
GMAIL_PUBSUB_TOPIC | Optional. projects/<project>/topics/<topic> for Gmail push. |
Register the redirect URI with both providers, and make sure the SaaS origin
is listed in API_ALLOWED_ORIGINS: the callback only returns to allowed
origins.
Last updated on