SENDING · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP
Domains and DNS
Send from your own domain: the DKIM record, the optional return-path records, SPF and DMARC.
Without a domain, mail goes out from [email protected] with your site’s name as the sender name (relay mode). After you verify a domain, mail goes out from your own address, signed with DKIM as your domain (domain mode).
| Relay mode | Domain mode | |
|---|---|---|
| From address | [email protected] | Your address, for example [email protected] |
| DKIM signature | send.securessmtp.com | Your domain |
| DMARC for your domain | Not involved | Passes through DKIM |
| Counts toward the monthly limit | Yes | No |
| Plan | All plans | Starter and higher |
Choose a domain and From address
- A subdomain such as
mail.example.comis a good choice. It keeps this mail’s reputation apart from your main domain’s. - The From address must be on exactly that domain. For
mail.example.comit must end in@mail.example.com. If you do not give one, we usenotifications@<domain>. - Each site has its own sending domain.
Add the domain
- In the dashboard, open Sites and start + Add website (
/app/forms/sites/new). - At “How should this site send email?”, choose Send from my own domain.
- Enter the sending domain. The wizard shows the DNS records to publish.
- Publish the records at your DNS host, then click Check DNS and verify.
You can also skip this step and finish it later on the Sending Domains page (/app/forms/email). Until the domain is verified, the site sends in relay mode.
To add a domain to a site you already have, use the add_sending_domain tool of the MCP server with domain, from_address and align_mode.
from_address to add_sending_domain. A domain without a From address can verify, but mail keeps going out in relay mode.DNS records
There are two setups. Simple is the default and needs one record. Advanced adds two records so that SPF also aligns with your domain. Copy the exact values from the dashboard; the DKIM key is different for every domain. The examples use example.com.
Simple: one record
| Type | Name | Value |
|---|---|---|
| TXT | securessmtp._domainkey.example.com | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA… |
Mail is signed with DKIM as your domain, so DMARC passes through DKIM. The return path (envelope sender) stays on our shared bounce.securessmtp.com, so you do not change your SPF record.
Advanced: three records
| Type | Name | Value | Priority |
|---|---|---|---|
| TXT | securessmtp._domainkey.example.com | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA… | — |
| MX | bounce.example.com | mx1.securessmtp.com | 10 |
| TXT | bounce.example.com | v=spf1 ip4:178.104.167.244 ip6:2a01:4f8:c0c:7b6c::1 -all | — |
The envelope sender becomes an address on bounce.example.com (b+…@bounce.example.com), so SPF passes for your domain as well as DKIM. Bounces come back to us through the MX record and show up in the email log and in webhooks.
Entering the records
- Many DNS hosts add your domain to the name for you. Then enter only
securessmtp._domainkeyandbounce(for a subdomain such asmail.example.com:securessmtp._domainkey.mailandbounce.mail). Check DNS shows whether the result is right. - The DKIM value is longer than 255 characters. If your DNS host asks for it in pieces, split it into several quoted strings; we join them when we check.
- A name can have only one SPF record. The SPF record in Advanced goes on
bounce.<domain>, not on your main domain. - If your DKIM key is ever rotated, the selector changes to
securessmtp-<number>. Publish the new record the dashboard shows.
Verify
- Publish the records. Most DNS hosts apply changes within minutes; some take a few hours.
- On the Sending Domains page (
/app/forms/email), click Check DNS. Each record shows as found, missing or wrong value. - When all records are found, click Verify DNS. The status changes from Pending DNS to Verified. In Advanced all three records must be in place.
From the next email on, the site sends in domain mode (unless you send with sender_mode: "relay"). To check from code, call GET /mail/domain-status: it returns has_verified_domain and effective_mode.
Switching between Simple and Advanced
On the Sending Domains page, use Simple setup or Advanced setup (or Switch to advanced / Switch to simple). The DKIM record stays the same. Switching sets the domain back to pending until you verify again, and the site sends in relay mode meanwhile — so publish the new records before you switch.
Removing a domain
Remove on the Sending Domains page deletes the domain. The site goes back to relay mode for the next email. You can leave or delete the DNS records afterwards.
SPF for your main domain
You do not need to change the SPF record of your main domain. In both setups the envelope sender of our mail is not your main domain: it is bounce.securessmtp.com (Simple) or bounce.<domain> (Advanced), so receivers check SPF there. Do not add our IP addresses to your main domain’s SPF record.
DMARC
DMARC tells mailbox providers what to do with mail that claims to be from your domain but fails SPF and DKIM alignment. Once your domain is verified, our mail passes DMARC through DKIM. If your domain has no DMARC record yet, start with a policy that only collects reports:
| Type | Name | Value |
|---|---|---|
| TXT | _dmarc.example.com | v=DMARC1; p=none; rua=mailto:[email protected] |
- The DMARC record goes on your main domain. It also covers subdomains such as
mail.example.com. - Read the reports for a few weeks. When every service that sends as your domain passes, move to
p=quarantineand laterp=reject. - Gmail and Yahoo expect a DMARC record from senders of large volumes.
In relay mode none of this applies to your domain: the From domain is send.securessmtp.com, which we manage, with SPF, DKIM and DMARC in place.