Inbound 1.x

Backup-MX / forwarder. Accepts on port 25 only for listed domains. Recipients are either an allow-list or any address at that domain. Off by default in Compose.

Add inbound domain

Forwarding

DomainDNSUpstreamRecipientsTLS
lists.example.com ok 10.0.0.8:25 12 listed required Delete
backup.example.net error 192.0.2.20:25 any off Delete

The DNS badge is the MX check: at least one MX must point at this server. Results are cached for a few minutes; open a domain for the lookup and a Re-check button.