Verified sending domains with DKIM, SPF and DMARC
Add a domain and we generate the exact records it needs. Publish them, and verification runs on its own until every one resolves.
Domains ›
mail.northwind.dev
| Type | Name | Content | TTL | Priority | Status |
|---|---|---|---|---|---|
| TXT | rasket._domainkey.mail | p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A… | Auto | PendingNot found yet | |
| CNAME | rasket.mail | us1.rasket.net | Auto | PendingNot found yet | |
| CNAME | links.mail | links1.… | Auto | PendingOptional |
Two ways to publish the records. Pick the way that matches where your domain's DNS lives.
- Connect CloudflareOne click
Published 3 records. Checking DNS now.
Connect CloudflareOne click
Your zone is at Cloudflare. Approve once and we write every record. There is no token to create, and the access is used for that one write and not kept.
- TypeHostValueTXTrasket._domainkeyp=MIIBIj…CNAMErasketus1.rasket.net
Add the records by hand
Copy each row into your DNS panel and we check as you go. We recognise your provider from its nameservers and lay the rows out in its own field names, with a copy button on every cell.
Not ready for DNS yet? Send from your managed address first.
Every team starts with an address we verify for you, so there is nothing to publish and nothing to wait for. It reaches the verified addresses of people on your team and nobody else; a domain of your own is what lets you write to your customers.
What each record does. Two to send, and the ones you can skip.
- VerificationRequired
DKIM signs every message.
A receiving server reads the public key at rasket._domainkey to check the message came from us on your behalf and was not changed on the way. The key is 2048-bit and made for this domain alone; the private half is encrypted at rest.
TXTrasket._domainkeyp=MIIBIjANBgkqh… - SendingRequired
SPF and the return path go together.
The CNAME at rasket.yourdomain sets the envelope sender for your mail. It makes SPF pass and brings bounces and complaints back to us, so they land on the message's timeline and a bad address is suppressed.
CNAMErasketus1.rasket.net - DMARCOptional
DMARC is yours to choose.
It tells mailbox providers what to do with mail that fails its checks. Verifying a domain does not need it. The dashboard builds the value for you: start at p=none, then move up to quarantine and reject when the reports look right.
TXT_dmarcv=DMARC1; p=none - TrackingOptional
Tracked links on your own hostname.
One CNAME puts open and click tracking on a name of yours. Tracking works without it: links use our tracking address until yours is ready, so there is nothing to wait for.
CNAMElinkslinks1.…
And a brand logo, if you want one. Once DMARC is at enforcement you can upload a logo and publish one record at default._bimi, so mail apps that support it show it beside your name. The tracking guide covers opens and clicks on their own.
It keeps checking. Verification runs on its own, and every record says whose move it is.
The schedule
Now
First check, the moment you add the domain
1 min · 5 min · 15 min
Quick re-checks while DNS propagates
Every hour
Until every record resolves, for up to 72 hours
Every 24 hours
Once settled, so a record that disappears is noticed
With the domain page open, it also checks every 30 seconds, so you can watch a record turn green right after you publish it.
Every unverified row says why
- Action neededTXT send
We do not see this record yet. Check it is published at your registrar.
- Waiting on usMX send
Record found; confirming.
- Still checkingTXT rasket._domainkey
Resolvers still disagree about this name, so it is propagating.
Checked where it counts.
Two public resolvers first; when they disagree, your zone's own nameservers decide. The signing records also have to be confirmed by the servers that send your mail.
Drift is reported, not ignored.
A record that verified and later stops resolving goes back to pending and says so: it verified before and no longer resolves to the value we gave you.
You can ask, but you never have to.
Check now runs the same check on demand, up to once a minute per domain. The schedule keeps going whether the page is open or not.
Domains on every plan. Each one gets its own key, its own records and its own status.
Free
3domains
Pro
10domains
Scale
1,000domains
Custom
Set in your contract
Domains add-onPro and Scale
+100for $20 / mo
100 more domains on top of your plan, for a sender per customer or brand. Add or remove it yourself.
Questions about sending domains. What people ask before the first one.
Do I need to move my DNS?
No. Your DNS stays exactly where it is and you add three records to it. If your DNS is on Cloudflare you can connect your account and we publish them for you; we use that access for that one write and do not keep it.
Can I send from a subdomain?
Yes, and it is what we recommend. Adding mail.example.com rather than example.com keeps your sending reputation separate from the rest of your mail, and our records never collide with the ones your mailbox provider already publishes at the root.
How long does verification take?
That depends on how quickly your DNS provider publishes the change. We check as soon as you add the domain and keep re-checking on a schedule, so a record verifies on its own once it resolves and you never have to poll. You can also ask for a check now, up to once a minute per domain.
Do I need a DMARC record?
Not to verify a domain, and we do not publish one for you. It is worth adding, starting at p=none and tightening once the reports look right. If your domain already publishes p=reject, publish our records and verify before you send, or mail may be rejected until alignment is in place.
Which region should I pick?
Each domain has a region, chosen when you add it and fixed after that. It decides where the domain's mail is sent from, which is a deliverability and latency choice. It does not decide where your data is stored.
What if another team already verified my domain?
Adding it is refused, and claiming it is the only way to take it over. Publish the TXT record the claim gives you at the root of the domain, and when it resolves the domain moves to your team with fresh DKIM records of its own. A claim expires after seven days.