Setup Server-Side Signatures

Prerequisites

Before starting, ensure you have:

  • A Google Workspace Super Admin account.

  • Your Google Customer ID (Admin Console → Account → Account Settings → Profile).

  • The following details ready to provide to Crossware Support:

If you have not yet supplied this information, please complete the Google Workspace Free Trial Form or email support@crossware365.com with the details above.
Wait for confirmation from our support team before continuing.


Configure Domain-wide Delegation

  1. Sign in at admin.google.com.

  2. Go to Security → Access and Data Control → API Controls.

  3. Select Manage Domain-wide Delegation → Add New.

image-20250921-214502.png
  1. Enter Crossware’s client ID: 114734196798062831722

  2. Add the following API scopes:

  3. Click Authorise.

image-20250921-214524.png

Allow Third-party App Access

  1. In API Controls, go to Manage App Access.

image-20250921-214755.png
  1. Click Configure New App.

  2. Enter this client ID:
    928646364906-vjarqcqr254p29bs28n24e5fjabivvev.apps.googleusercontent.com

  3. Search for Crossware Mail Signature and select it.

image-20250921-214952.png
  1. Select All users and click Continue.

image-20260129-220255.png
  1. Set the app access to Limited and click Continue.

image-20250921-215246.png
  1. Click Finish.

image-20260129-220423.png

Create User and Admin Groups

  1. From the Directory menu, choose Groups.

  2. Create a group named CrosswareMailSignatureUsers.

    1. Assign an email address.

    2. Add a description.

    3. Set an owner (preferably a Super Admin).

image-20250921-215808.png
image-20250921-220305.png
  1. Click CREATE GROUP.

  2. Create another group named CrosswareMailSignatureAdmins.

    1. Assign an email address.

    2. Add a description.

    3. Set an owner (preferably a Super Admin).

    4. Tick Security as Group label.

image-20250921-220901.png
  1. Select Only invited users.

image-20250921-221017.png
  1. Click CREATE GROUP.


Configure Routing Host

  1. Go to Apps → Google Workspace → Gmail → Hosts.

  2. Click Add Route.

  3. Enter the following:

    1. Host name: CrosswareOutboundHost

    2. On the host name text field Enter the smart host relevant to your region:

      Australia: gwstrafficsmtp-aus-k1.crossware.co.nz

      Canada: gwstrafficsmtp-can-k1.crossware.co.nz

      United States: gwstrafficsmtp-us-k1.crossware.co.nz

      France: gwstrafficsmtp-france.crossware.co.nz

      Europe: gwstrafficsmtp-eu-k2.crossware.co.nz

      United Arab Emirates: gwstrafficsmtp-uae-k1.crossware.co.nz

      Qatar: gwstrafficsmtp-qat-k1.crossware.co.nz

      India: gwstrafficsmtp-ind-k1.crossware.co.nz

    3. Port: 25

    4. Tick Perform MX lookup on host

image-20250921-222040.png
  1. Save your changes.


Configure Inbound Connector (SMTP Relay)

  1. Navigate to Apps → Google Workspace → Gmail → Routing.

  2. In SMTP Relay Service, click Configure.

  3. Name the connector CrosswareInboundConnector.

  4. Select Only accept mail from the specified IP addresses

  5. Add the IP addresses provided for your region.

You will need to add both IPs for your region.

Region

IP Address

AUS-K1-EAST

20.193.4.65

AUS-K1-SOUTHEAST

20.40.171.166

CAN-K1-CENTRAL

20.116.146.80

CAN-K1-EAST

52.229.72.77

US-K1-EAST

52.190.40.209

US-K1-WEST

20.184.240.123

FRANCEProd-CENTRAL

51.138.217.108

FRANCEProd-SOUT

52.136.153.121

EU-K2-NORTH

20.105.73.92

EU-K2-WEST

20.126.196.163

UAE-K1-NORTH1

40.123.229.48

UAE-K1-NORTH2

20.203.119.149

QAT-K1-CENTRAL1

20.21.234.240

QAT-K1-CENTRAL2

20.21.224.39

IND-K1-CENTRAL

135.235.229.184

  1. Select Require TLS encryption.

  2. Save your changes.

image-20250922-002114.png

Create Outbound Transport Rule

  1. Navigate to Apps → Google Workspace → Gmail → Compliance Content Compliance, click Configure.

  2. Create a new rule named CrosswareTransportRule.

  3. Define the Rule Scope and Criteria:

    1. Email messages to affect: select Outbound and Internal - Sending.

    2. Select If ALL of the following match the message.

    3. Expressions: Advanced content match → Full headers → Not contains text:
      x-cwesigprocessed: Y

    4. Expressions: Sender header → Not contains text:
      drive-shares-dm-noreply@google.com

image-20250922-003905.png
  1. Under Route, choose Change the route → CrosswareOutboundHost.

image-20250922-004100.png
  1. Enable Require secure transport (TLS).

  2. In the Account types to affect section, select both Users and Groups.

  3. In Envelope filter, select Only affect specific envelope senders.

  4. Choose Group membership (only sent mail), then select CrosswareMailSignatureUsers.

  5. Save your changes.

image-20250922-004857.png

Completion

Once the above steps are completed, log in to the Crossware Email Signature Portal to design and manage your signatures.