# O.I Domain and Mailbox Setup Options

Purpose: create a dedicated, ringfenced email route for Outsourcing Initiative documents.

Recommended mailbox:
- `inbox@outsourcinginitiative.<tld>` or `oi@outsourcinginitiative.<tld>`

Recommended domain styles:
1. `outsourcinginitiative.co.uk`
2. `outsourcinginitiative.uk`
3. `oi-regulatory.co.uk`
4. `outsourcing-oversight.co.uk`
5. `thirdpartyoversight.co.uk`

Recommended registrar/email providers:

## Option A — Cloudflare Registrar + Cloudflare Email Routing + Gmail/Outlook destination
Pros:
- Low-cost domain registration.
- Strong DNS/security controls.
- Easy inbound forwarding aliases, e.g. `oi@domain` -> selected destination.
Cons:
- Email Routing forwards inbound only; it is not a full mailbox unless paired with Gmail/Outlook/other mailbox.
- Attachments still land in another mailbox unless we add a downstream mailbox/poller.

## Option B — Microsoft 365 / Outlook mailbox on custom domain
Pros:
- Best fit if documents may originate from work/regulated environments.
- Full mailbox, audit, security controls, MFA, retention options.
Cons:
- More setup; needs Microsoft tenant/admin access and subscription.

## Option C — Google Workspace mailbox on custom domain
Pros:
- Full Gmail-style mailbox with custom domain.
- Straightforward IMAP/OAuth integration.
Cons:
- Monthly cost.
- Must ensure it is acceptable for work/regulatory document handling.

## Option D — Proton Mail custom domain mailbox
Pros:
- Privacy-focused mailbox.
- Good for dedicated ringfenced mailbox.
Cons:
- Automation/IMAP generally requires Proton Bridge on a machine, which is less convenient on a VPS.

Recommendation:
For anything potentially confidential or work-related, use an approved Microsoft 365/shared mailbox or another employer-approved route. If this is only for non-confidential public/regulatory documents, Cloudflare + Google Workspace or Gmail forwarding can work.

Hermes/O.I integration target:
- Inbound O.I documents land in a dedicated mailbox.
- O.I profile polls that mailbox only.
- Attachments are saved to `/data/workspace/outsourcing-initiative/05-email-uploads/`.
- A manifest/audit log is written.
- No automatic deletion/mutation unless explicitly enabled later.
