SENDING · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP

Domains and DNS

Send from your own domain: the DKIM record, the optional return-path records, SPF and DMARC.

Without a domain, mail goes out from [email protected] with your site’s name as the sender name (relay mode). After you verify a domain, mail goes out from your own address, signed with DKIM as your domain (domain mode).

Relay modeDomain mode
From address[email protected]Your address, for example [email protected]
DKIM signaturesend.securessmtp.comYour domain
DMARC for your domainNot involvedPasses through DKIM
Counts toward the monthly limitYesNo
PlanAll plansStarter and higher
The Free plan cannot add a sending domain. The dashboard shows: “Sending from your own domain needs the Starter plan or higher.” See Plans and limits.

Choose a domain and From address

  • A subdomain such as mail.example.com is a good choice. It keeps this mail’s reputation apart from your main domain’s.
  • The From address must be on exactly that domain. For mail.example.com it must end in @mail.example.com. If you do not give one, we use notifications@<domain>.
  • Each site has its own sending domain.

Add the domain

  1. In the dashboard, open Sites and start + Add website (/app/forms/sites/new).
  2. At “How should this site send email?”, choose Send from my own domain.
  3. Enter the sending domain. The wizard shows the DNS records to publish.
  4. Publish the records at your DNS host, then click Check DNS and verify.

You can also skip this step and finish it later on the Sending Domains page (/app/forms/email). Until the domain is verified, the site sends in relay mode.

To add a domain to a site you already have, use the add_sending_domain tool of the MCP server with domain, from_address and align_mode.

Pass from_address to add_sending_domain. A domain without a From address can verify, but mail keeps going out in relay mode.

DNS records

There are two setups. Simple is the default and needs one record. Advanced adds two records so that SPF also aligns with your domain. Copy the exact values from the dashboard; the DKIM key is different for every domain. The examples use example.com.

Simple: one record

TypeNameValue
TXTsecuressmtp._domainkey.example.comv=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…

Mail is signed with DKIM as your domain, so DMARC passes through DKIM. The return path (envelope sender) stays on our shared bounce.securessmtp.com, so you do not change your SPF record.

Advanced: three records

TypeNameValuePriority
TXTsecuressmtp._domainkey.example.comv=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…—
MXbounce.example.commx1.securessmtp.com10
TXTbounce.example.comv=spf1 ip4:178.104.167.244 ip6:2a01:4f8:c0c:7b6c::1 -all—

The envelope sender becomes an address on bounce.example.com (b+…@bounce.example.com), so SPF passes for your domain as well as DKIM. Bounces come back to us through the MX record and show up in the email log and in webhooks.

Entering the records

  • Many DNS hosts add your domain to the name for you. Then enter only securessmtp._domainkey and bounce (for a subdomain such as mail.example.com: securessmtp._domainkey.mail and bounce.mail). Check DNS shows whether the result is right.
  • The DKIM value is longer than 255 characters. If your DNS host asks for it in pieces, split it into several quoted strings; we join them when we check.
  • A name can have only one SPF record. The SPF record in Advanced goes on bounce.<domain>, not on your main domain.
  • If your DKIM key is ever rotated, the selector changes to securessmtp-<number>. Publish the new record the dashboard shows.

Verify

  1. Publish the records. Most DNS hosts apply changes within minutes; some take a few hours.
  2. On the Sending Domains page (/app/forms/email), click Check DNS. Each record shows as found, missing or wrong value.
  3. When all records are found, click Verify DNS. The status changes from Pending DNS to Verified. In Advanced all three records must be in place.

From the next email on, the site sends in domain mode (unless you send with sender_mode: "relay"). To check from code, call GET /mail/domain-status: it returns has_verified_domain and effective_mode.

Switching between Simple and Advanced

On the Sending Domains page, use Simple setup or Advanced setup (or Switch to advanced / Switch to simple). The DKIM record stays the same. Switching sets the domain back to pending until you verify again, and the site sends in relay mode meanwhile — so publish the new records before you switch.

Removing a domain

Remove on the Sending Domains page deletes the domain. The site goes back to relay mode for the next email. You can leave or delete the DNS records afterwards.

SPF for your main domain

You do not need to change the SPF record of your main domain. In both setups the envelope sender of our mail is not your main domain: it is bounce.securessmtp.com (Simple) or bounce.<domain> (Advanced), so receivers check SPF there. Do not add our IP addresses to your main domain’s SPF record.

DMARC

DMARC tells mailbox providers what to do with mail that claims to be from your domain but fails SPF and DKIM alignment. Once your domain is verified, our mail passes DMARC through DKIM. If your domain has no DMARC record yet, start with a policy that only collects reports:

TypeNameValue
TXT_dmarc.example.comv=DMARC1; p=none; rua=mailto:[email protected]
  • The DMARC record goes on your main domain. It also covers subdomains such as mail.example.com.
  • Read the reports for a few weeks. When every service that sends as your domain passes, move to p=quarantine and later p=reject.
  • Gmail and Yahoo expect a DMARC record from senders of large volumes.

In relay mode none of this applies to your domain: the From domain is send.securessmtp.com, which we manage, with SPF, DKIM and DMARC in place.