Infrabox

Infrabox vs. doing it by hand

The manual path is not mysterious and it is not beyond anyone. You can register a domain, add it to a Google Workspace, publish the records, get the domain verified and turn DKIM on. Thousands of people have.

The question is not whether you can. It is what happens on the ninth domain, at the end of a long week, when one SPF include is wrong and nothing anywhere reports an error.

01the approach

The other approach, fairly

What doing it by hand actually involves.

Described properly, not caricatured. If this list looks straightforward to you, that is a real signal about which column you belong in.

  1. 01

    Register the domain with a registrar, then point its nameservers somewhere you can actually write records — because everything that follows is a DNS record.

  2. 02

    Add the domain to a Google Workspace, create the admin account that will own its mailboxes, and get through Google's activation.

  3. 03

    Publish MX so the domain can receive, SPF so receivers know which servers may send as it, and DMARC so they know what to do when the first two disagree.

  4. 04

    Ask Google to verify you own the domain, then wait — for propagation, for Google's checks, for however long that takes today.

  5. 05

    Generate the DKIM key in the Admin Console, publish it to DNS, and remember to come back and switch signing on, which is a separate action people routinely miss.

  6. 06

    Get each mailbox to the point where a sending tool can use it — which is where the manual path gets genuinely awkward, because a brand-new Workspace user has to sign in and clear an identity challenge before it can hold a sending credential at all.

  7. 07

    Then do the whole thing again for the next domain, identically, from memory.

02side by side

Side by side

The comparison itself.

A dash instead of a tick means the row is a trade-off rather than a win — the two approaches simply differ, and which side you want depends on you.

Infrabox vs. doing it by hand: a criterion-by-criterion comparison
CriterionoursInfraboxthe alternativeDoing it by hand
Who publishes MX, SPF and DMARCYes:Published during provisioning, with the values Google expects, as step four of eight.You do, in your DNS provider, once per domain, from a support article.
DKIMYes:Key generated, published to DNS and signing switched on as step six. If it fails, it is reported rather than hidden.Generated in the Admin Console per domain, published by hand, and then switched on in a second, separate step that is easy to forget.
Domain verification with GoogleYes:Token published and re-checked automatically, backing off and retrying for hours rather than failing on the first miss.Attempted manually. If DNS has not propagated yet it fails, and you come back later — if you remember.
Getting a usable sending credentialYes:Minted and then verified against Gmail before hand-off. No app password, no per-mailbox secret for you to hold.Requires signing in as each new mailbox and clearing Google's identity challenge before a credential can exist at all.
Consistency across domainsYes:The same eight steps, in the same order, every time. The ninth domain is done exactly like the first.As consistent as the person doing it was that afternoon.
Visibility while it runsYes:The dashboard shows which of the eight steps each mailbox is on and which one it is waiting for.A browser tab, a mental checklist, and a spreadsheet if you are organised.
Admin Console accessTrade-off:Not yours — the platform holds the admin account so the pipeline can run unattended.Entirely yours, with everything that implies in both directions.
CostTrade-off:A per-mailbox monthly fee on top of the domain.No platform fee. You pay the registrar and Google, and you pay in hours that never show up on an invoice.

03where we lose

Where we lose

When doing it by hand is the right answer.

Every comparison page should have this section and almost none do. These are the cases where we would tell you not to buy from us.

You need one or two mailboxes, once

For a single domain that you will set up and then never think about again, the manual path is fine. An afternoon is an acceptable price for one afternoon of work. It stops being fine when it repeats.

You need the Admin Console

If you need to hold Workspace admin yourself — for policy, compliance, or because the mailboxes are also real human inboxes with Drive and Calendar attached — do it by hand. The platform holding the admin account is precisely what makes provisioning unattended, and you cannot have both.

You already have a working process and someone who runs it

If a person on your team already does this well, has automation of their own, and has not been bitten by it, replacing something that works with something new is a cost rather than a saving.

The bottom line

Do it by hand when it is a one-off, or when you need to own the Admin Console. Use a pipeline when the same fiddly, silent-failing sequence has to happen correctly on the tenth domain as reliably as it did on the first.

Our side of it costs $3.79 per mailbox per month.

Plus the domain, priced per TLD per year. That is the entire price list — no provisioning fee, no onboarding fee, no volume tier to negotiate. Put your own numbers in.

See the full price list

04questions

Questions

On this comparison.

Can I really not do this myself?

Of course you can. Every individual step is documented by Google and none of it requires special access. What is hard is not any one step — it is doing all eight, identically, every time, on a schedule set by DNS propagation rather than by you.

What is the one thing people get wrong most often?

Two things, and both are silent. SPF gains an extra include or trips the DNS lookup limit, and DKIM gets generated but never switched on. Neither throws an error. Both are only visible later, in the reply rate.

Do I lose access to my domains by using Infrabox?

The domains are registered in your account. What you do not hold is the Google Workspace admin account for them — that sits with the platform, which is the thing that lets the pipeline run without a human clicking through the Admin Console.

Is it faster than doing it manually?

Your involvement is far shorter — you choose domains and mailbox counts and then stop. The wall-clock time is not dramatically shorter, because the longest part is Google's domain verification and it waits on DNS propagation whoever kicked it off.

Think you are on our side of the table?

Tell us how many mailboxes across how many domains, and which tool you send with. If one of the other approaches suits you better, we will say that instead.