Add your DNS records one by one

The six-record path for hosts that cannot add the one NS record, what each record does, and how to read the checks.

Updated · 4 min read

Where it is in the app

Open Home, choose Email & SMS, then Reports › Reputation.

  • Home
  • Email & SMS
  • Reports
  • Reputation

Most people add one record and are done (see "Set up your sending domain"). Some DNS hosts cannot add that record, and some people prefer to see every record. For them there is a list of six. It works exactly as well. It is just more to copy.

Use the six-record path if:

  • your host has no NS record type (Squarespace, and some Wix and Shopify managed domains), or
  • you want your From address on your main domain, or
  • you would rather see everything.

One difference: when we need to replace a signing key later, you add a new record yourself. On the one-record path we do it for you.

#Get to the list

If your host cannot do the short way, The records to add shows the six records on the setup card. Otherwise:

  1. On the one-record card, press I'll add the records myself. The page says "Switched to the full list of records. Add them all, then press Check now."

  2. Or go to Settings → General → Domains, find your domain, and press Finish setup (DNS records once it is verified).

    On screenSettings › General › Domains

A window lists each record with Type, Name, Value and Status. Next to each name and value is a button, copy name and copy value. Use the right one for each box. Pasting a name into a value box is the most common mistake.

#The six records

  1. A signing key (type CNAME, name starting s1-, ending ._domainkey. and your domain). It signs your email so Gmail can prove it came from you. Without it, your mail is unsigned and goes to spam.

  2. A spare signing key (a second CNAME, s2-…). It costs nothing and lets us replace a key without any downtime. Add it now.

  3. The bounce address (type MX, name bounce. plus your domain). It catches the replies that say an address is dead. Microsoft refuses mail from a sender who cannot receive these.

  4. The sending policy (type TXT on the same bounce name). It says which servers may send for you.

  5. Click tracking (type CNAME, name t. plus your domain). Your links open on your own domain, not ours.

  6. DMARC (type TXT, name _dmarc. plus your domain). It turns on delivery reporting.

#The MX record

Some hosts show two boxes, Priority and Mail server. The window shows both. Priority is 10. The mail server is ours, not yours. Do not type your own mail server there.

#If you already have DMARC

A name can have only one DMARC record. If you already have one, the row says Yours now and Change it to. Edit your record. Do not add a second one, because receivers then ignore both. If you have two, the row warns you: keep one, set it to the value shown, and delete the other.

#Read the status

Each record shows Verified, Not right yet or Not checked yet. Under it a line says one of:

  • "The value at your DNS provider matches"
  • "Not found yet — DNS changes can take a few minutes to spread"
  • "Found, but different:" followed by what we found

If any record is wrong, a box lists each one and what we found. Press Check now after you fix it, or Close, keep checking. We recheck on our own every 10 minutes.

The domain table shows the count, such as 4 of 6, then 6 of 6 verified. When the three checks (sending policy, signing and DMARC) all pass, the window shows: "This domain meets Google, Yahoo and Microsoft's requirements for bulk senders." The text under it says what your DMARC policy does. A policy of p=none reports on impersonation but does not stop it. That satisfies the three providers. Tightening it is your choice, later.

If your DMARC record is set to strict (aspf=s), Reputation → Domains & warmup shows a note headed "Your domain's DMARC policy is set to strict. That's fine." It explains what to expect in your reports.

#Cloudflare

Every record here must be DNS only, the grey cloud. An orange cloud makes Cloudflare answer instead of us, and your mail goes out unsigned. Nothing shows an error.

#Click tracking

#Replace a signing key

On the same page, Signing keys has Make a new key. We publish it first. When it has spread (usually minutes), press Switch to it. The old key stays published. Nothing stops sending while it changes.

#If it didn't work

  • "Found, but different". Compare the value letter by letter. Remove spaces at the ends.
  • Namecheap. The Host box wants only the first part of the name.
  • Still "Not found yet" after an hour. Check that you added it to the right domain.
  • Your host does not allow a name that long. Email support@aminoengine.com with the host's name.
Was this helpful?

Still stuck? A person answers.

Email support@aminoengine.com and we answer within one business day.