Identity and security
One mail route: reuse beats a new integration
Starting questionNew applications need to send email notifications. Do you connect a separate provider for each of them?
Result
Works
One hardened mail route in the gateway serves every application and alert. A second provider would have doubled rotation and review work.
No. Every application sends through one shared, hardened mail route in the central gateway; alerts reach it through a narrow bridge as well. Every additional provider would bring its own credentials, templates, limits, and review duties.
What we decided and built
All applications send through one hardened mail route in the central gateway. It uses Microsoft Graph, and the other services call it through an internal endpoint.
Monitoring alerts also run through this route via a small bridge, because the monitoring tools cannot do modern SMTP authentication.
What it means for business architecture
Every additional external interface brings its own credentials, templates, limits, and review duties. A shared capability noticeably reduces that load.
Lessons learned
- A second provider doubles the effort for key rotation and review.
- Where tools cannot do modern authentication, a narrow bridge helps. Falling back to passwords does not.
- Brand and privacy notice stay consistent when there is only one family of templates.
- Microsoft Graph
- reuse
- gateway