Skip to main content
EXCLAIMER XCEL PARTNER

Exclaimer: one signature,
every mailbox.
No drama.

Exclaimer sales, fit assessments, and signature design for Microsoft 365 and Google Workspace tenants. We size the right tier, install it properly, and design templates that actually look like your brand.

Exclaimer for Microsoft 365 & Google Workspace
10+ yrs
Exclaimer partner
M365 + GW
Both platforms, daily
0
User clicks required
1 dashboard
Whole organisation
Accreditations & partnerships
Exclaimer
Xcel Partner
Microsoft 365
CSP Partner
Google Workspace
Partner
M365 + GWS
Both platforms daily
ISO 27001
Compliant mail flow
Founded 2001
24 years trading
Exclaimer Xcel Partner, highest tier
M365 & Google Workspace both supported
MSP & reseller pricing available
Direct line, no support queue
The honest picture

Most tenants we audit have four signature variants running simultaneously. Usually more.

Anyone who has rolled out a new signature by emailing staff a Word document knows exactly how it ends. A month later: sales has the old logo, the MD has whatever Outlook defaulted to in 2019, someone in accounts went rogue. Mobile never got the memo. Shared mailboxes have whatever the last person left there.

This isn't a people problem. Outlook signatures live on the device, per profile, per mailbox, sometimes in a roaming policy if Group Policy ever held together. There's no central version. There's no way to push a change without touching every user. When legal rewrites the POPIA disclaimer, it goes out in an email and two thirds of the company gets around to it.

Taking the user out of the loop is what centralised signature management does. Mail passes through a service, gets stamped with the right template for that sender, and goes on its way. Users do nothing. They can't get it wrong. Update the campaign banner once in the dashboard and it's live across the whole org at the next message sent. It removes itself when the campaign ends, no one needs to chase IT in mid-January to pull the Black Friday creative.

Outlook templates via Group Policy and Workspace's append-footer setting do work, for small teams with one brand, no marketing requirements, and unusually disciplined staff. Short list. For everyone else, the licence pays for itself in IT time saved inside a quarter. If you want to work through whether DIY is actually sufficient, we've written up the full comparison of signature options, including where each approach breaks.

One thing the vendor marketing skips: Exclaimer routes your mail through a smart-host. That's the mechanism. It's also why SPF, DKIM and DMARC matter more after the installation than before it. Done right, your DMARC alignment rate goes up. Done without care, your invoices land in junk. The difference is who sets it up.

What we actually deliver

Tier and tenant sizing
Cloud Signatures vs Signature Manager, Standard vs Pro vs Pro+. We map your headcount, mailbox count and shared-mailbox sprawl to the right Exclaimer SKU before you sign anything.
M365 connector and routing
Inbound/outbound connectors with TLS pinning, transport rules, and the Outlook add-in so senders can preview their signature as they type. SOC2 and ISO 27001 compliant mail flow throughout.
Google Workspace routing
Mail routing rules and domain registration in Google Admin, Gmail API integration so signatures appear at compose time, and empty local signature fields locked via policy so you don't get two stacked.
Template and banner design
Brand-aligned HTML templates, marketing banners with start and end dates, A/B variants, and UTM wiring so marketing can prove the click-through.
Managed service and banner ops
Monthly banner swaps, new-starter templates, and seasonal campaign variations, handled by us on a retainer, so marketing doesn't have to chase IT every time a campaign changes.

How a typical engagement runs

01
Fit assessment (30 min)

Tenant size, current signature mess, design ambition, budget. We tell you whether Exclaimer Cloud Signatures, Signature Manager, or honestly Outlook-templates-plus-discipline is the right answer.

02
Technical readiness check

Before the smart-host goes in, we audit your connectors, mail routing, and email authentication setup. If something is going to break, we surface it before rollout.

03
Connector + design build

Connectors and routing in parallel with template design. We stage on a pilot group of 5–10 mailboxes for two working days before tenant-wide rollout.

04
Handover or managed run

Either we hand the dashboard to your marketing team with a one-hour walkthrough, or we run it for you on a monthly retainer: banner swaps, new-starter templates, the lot.

Platform deep dive

How Exclaimer connects, M365, Google Workspace, and the DNS gotchas

The concept is the same on both platforms. The wiring is not. Here's what actually happens under the hood.

Two connectors, one smart-host, every device covered

Exclaimer connects to M365 via two outbound connectors and a transport rule. Mail leaves the mailbox, passes through the connector, hits the Exclaimer smart-host, gets stamped with the right template for that sender, and goes out. The whole loop is server-side, which is what makes it universal, Outlook on Windows, OWA, iPhone Mail, shared mailboxes, all of it.

The Outlook add-in shows senders a live preview as they type, even though the actual stamp happens at the server. The reply detection rule strips the previous signature block before appending the new one, so you don't get the same block repeated four times down a thread. Job title changes in Entra ID show up in signatures at the next send. No helpdesk ticket.

  • Outbound connectors with TLS pinning and transport rule
  • Outlook add-in for compose-time preview
  • Reply detection to prevent stacked signatures
  • Live data pull from Microsoft Entra ID
  • Shared mailboxes, groups, and distribution lists all covered
Book a fit assessment

M365 at a glance

0
User actions required after rollout
5–10
Working days from quote to tenant-wide rollout
All
Devices covered, OWA, mobile, shared mailboxes

Same concept. Different wiring. A few Gmail-specific gotchas.

A routing rule in Google Admin Console sends outbound mail to the Exclaimer endpoint, it's signed, and returned for delivery. The Gmail-specific problem is the local signature field: if it isn't cleared and locked via admin policy, users end up with two signatures stacked, their local Gmail one plus the Exclaimer one. We lock the local field as part of every rollout.

Send-as aliases are what trips up most self-managed rollouts. If your sales team sends from a secondary brand domain using their primary mailbox, Cloud Signatures needs to know which template applies to which alias. Google's routing rule order matters when multiple rules are running, and if you have mail archiving alongside Exclaimer, the firing order determines whether the archived copy is the signed version.

  • Mail routing rule in Google Admin, no agent or desktop client
  • Local signature field locked via admin policy (mandatory step)
  • Gmail API integration for compose-time preview
  • Send-as alias mapping for multi-brand or multi-domain setups
  • Works with Google Vault archiving, Exclaimer fires first
Book a fit assessment

Google Workspace at a glance

1
Admin policy needed to lock the local signature field
Multi
Domain and alias support included
Both
M365 and GWS in the same org? We handle hybrid too.

SPF overflow and DMARC alignment, the two things that break delivery

SPF has a 10-lookup limit. Most tenants are already at 6 or 7 before Exclaimer goes in, the mail platform, a CRM, a newsletter tool, something for invoicing. Add the smart-host without checking the count and you may land at 11. SPF fails at that point, DMARC reads it as a failure, and outbound mail starts getting rejected or junked. We check the lookup count before we touch anything. At 8 or above, we flatten the record first.

The second problem is DMARC alignment. If your domain is at p=reject and DKIM isn't configured for the Exclaimer sending path, a percentage of outbound mail fails DMARC. The fix is DKIM signing through Exclaimer's keys, the selector published at your DNS, alignment checked against live report data. DNS changes that touch mail flow happen on Tuesday mornings, TTLs lowered 24 hours in advance, rollback notes written before we start.

  • SPF lookup count audited before any connector changes
  • SPF flattening where record count is at or near the limit
  • Exclaimer DKIM selector configured and verified
  • DMARC alignment checked against live report data post-rollout
  • DNS changes scheduled Tuesday mornings, not Fridays
Check your DNS readiness

DNS at a glance

10
SPF lookup limit, most tenants are closer than they think
#1
SPF overflow is the most common delivery failure we fix
Tue
We make DNS changes on Tuesdays. Not Fridays.

What the engagement looks like in practice

Real situation, real fix, client name omitted at their request.

Client
Property management group
Financial services · 60 seats
Exclaimer + DMARC
1 week
6 months of wasted licences reclaimed
Challenge

Had Exclaimer licences for 6 months, half-deployed by the previous IT firm. SPF was at 11 lookups. Delivery to Outlook.com recipients showing "soft fail". Two different logos in circulation.

Solution

SPF audit confirmed 11 lookups. We flattened SPF to 6, added the Exclaimer smart-host properly, realigned DKIM, rebuilt the signature template from the brand guide, and added the POPIA disclaimer.

Result

SPF compliant, DMARC delivery recovered, one template across 60 seats, marketing updates banners without IT. DMARC moved to p=reject three weeks later.

What our clients say

We changed the campaign banner once, from a phone at 9pm. It was live across all 140 mailboxes before Monday morning. That is the whole pitch.

S
Samantha Naidoo
Marketing Director · Financial services group, 60 seats

Previous IT firm installed Exclaimer but never finished configuring it. OSH fixed the connectors, got the templates looking right, and had the whole thing live across the organisation in three days.

M
Michael de Villiers
Operations Manager · Professional services firm, Johannesburg

POPIA disclaimers are now on every outbound email including mobile. That was on my compliance checklist for two years. Done in a week.

P
Priya Govender
Compliance Officer · Legal practice, Cape Town

Signatures sorted in 5 days. DMARC intact throughout.

Book a 30-minute fit assessment. We cover tenant size, the right Exclaimer tier, design scope, and DNS readiness. No slide deck, no sales theatre, just the numbers and a recommendation.

Exclaimer questions we get every week

Cloud Signatures is the SaaS product for Microsoft 365 and Google Workspace tenants. Signature Manager is the older on-premise / hybrid Exchange product. If you’re fully cloud, you want Cloud Signatures. If you’re still running an on-prem Exchange box for compliance reasons, we’ll talk Signature Manager. Most engagements in 2026 are Cloud.

Not if it’s set up properly. Exclaimer routes outbound mail through their smart-host, which means your connectors and email authentication need to be correctly configured before you flip the switch. Where we see problems, it’s almost always because someone rushed the technical setup: adding the smart-host without adjusting the authentication configuration to match. We do the readiness check first, so you don’t find out the hard way.

Mobile: yes, because the signature is added server-side during mail flow. Shared mailboxes: yes, with per-mailbox or per-group rules. CRM and transactional senders: depends on whether they relay through your tenant or send direct. If your CRM sends direct via SendGrid, it won’t get an Exclaimer signature unless you specifically route it through M365 or Google Workspace.

From signed quote to tenant-wide rollout, usually 5 to 10 working days. The bottleneck is almost never the technical setup. It’s getting marketing to sign off on the template. Plan for that.

Maybe. Most clients we onboard already have a licence and a half-deployed template from another vendor. The question is usually whether to migrate or fix what they have. If the existing deployment is stable and your team likes the designer, stay. If you’re hitting limits on banner scheduling, multi-domain Google Workspace, or analytics, Exclaimer is the better fit. We’ll do an honest comparison in the fit assessment. If you want to go in with the numbers first, see the full Exclaimer vs CodeTwo vs DIY breakdown.

Yes. Microsoft 365 handles multi-domain natively: different rules per domain, per group, per department. Google Workspace is fiddlier because of how Gmail handles aliases and send-as addresses; we wrote up the multi-domain Google Workspace pattern.

Either works. Most clients prefer to buy through us so they get one billing relationship and a direct line to the engineer who configured their tenant. If you’ve already got an Exclaimer subscription, we’ll do design and integration on top of it without re-selling the licence.

Exclaimer’s per-user list price changes; we’ll quote against your headcount in the fit assessment. As a planning number, budget roughly the cost of a coffee per user per month for the licence, plus a one-off design and integration fee that scales with the number of templates and tenant size.

Book a 30-minute Exclaimer fit assessment

We'll cover tenant size, the right Exclaimer tier, and design scope. No slide deck, no sales theatre. Just the numbers and a recommendation.

Email us directly support@osh.co.za

Get in touch