Help · Email
Authenticate your sending domain
Add the DNS records that prove your mail is really from you. A domain moves from pending to verified once the records are found — and unauthenticated mail is the most common reason for landing in spam.
Updated August 2026
Mailbox providers need a way to tell that mail claiming to be from your domain really is. Domain authentication is that proof, published as DNS records you add once.
It is the highest-value deliverability work there is, and it is a finite task rather than an ongoing one.
Who this is for
An admin, working with whoever controls your domain's DNS.
Before you start
- Access to your domain's DNS settings, or a colleague who has it.
- The domain you actually send from.
- Some patience — DNS changes take time to propagate before verification can succeed.
Three states, and what each one means
A domain starts as pending: the records have been issued and are waiting to be checked. It becomes verified once all the required DNS records are found and validated. It shows as failed when a check ran and the records were missing or incorrect. Failed is not permanent — fix the records and verify again.
Authenticate a domain
- Add the domain you send from
Use the domain in your actual From addresses. Authenticating a domain you do not send from achieves nothing. - Copy the DNS records you are given
You are shown the exact records to publish, formatted for copy-paste. Copy them exactly — a trailing character or a wrong host is the usual cause of a failed check. - Publish them with your DNS provider
Add each record at your registrar or DNS host. If someone else manages DNS, send them the records rather than describing them. - Wait for propagation
DNS changes are not instant. Verifying immediately after publishing often fails simply because the record has not spread yet. - Run the verification
Once the records are live, verify. All required records have to be found for the domain to move to verified. - Fix and re-verify if it fails
A failed check means a record was missing or wrong. Compare what is published against what you were given, character by character, then verify again.
The three domain states
| Status | What it means | What to do |
|---|---|---|
| Pending | Records issued, waiting to be checked | Publish them, then wait for DNS to propagate |
| Verified | All required records found and validated | Nothing — this is the goal |
| Failed | The last check found records missing or wrong | Compare published against issued, then verify again |
What you get
- Mail that is provably from your domain rather than merely claiming to be.
- A meaningfully better chance of landing in the inbox instead of spam.
- A clear verified, pending or failed state rather than guesswork.
- A one-time job that keeps paying off for every message afterwards.
Frequently asked questions
My domain says failed. What now?
Failed means the last check ran and did not find the records, or found them incorrect. Compare the published records against the ones you were given exactly, then verify again. It is not a permanent state.
How long does verification take?
The check itself is quick; DNS propagation is what takes time. If you verify straight after publishing and it fails, wait and try again before assuming the records are wrong.
Do I need this if I only send one-to-one email from my own mailbox?
It matters most for volume sending, but authentication helps any mail from your domain. If you send campaigns at all, do it.
Who should make the DNS changes?
Whoever controls your domain's DNS. Send them the exact records rather than a description — most failures are transcription errors.
Related articles
Email insights and deliverability
Reading your sending health honestly — what the numbers mean, which ones actually predict trouble, and the habits that keep mail landing in inboxes rather than spam.
Read articleSuppressions, bounces and unsubscribes
The suppression list is the record of addresses you should not send to, and why. There are four reasons — unsubscribed, bounced, complained and manual — and each one means something different.
Read articleHave an account issue this guide doesn't cover?
Start free today
Ready to give your team a CRM they'll actually use?
Start free. Bring your whole team. Cancel whenever (you won't).