Which DNS records do I need?
Publish the records shown for your domain in the dashboard. New managed-DNS domains use these record types:
Copy the exact hostnames and values from your domain page; manual DNS and whitelabel setups can differ.
Why does AhaSend need DNS records?
Email receivers use multiple authentication methods to verify that emails are legitimate. When you properly configure your domain with AhaSend, you’re telling receiving servers that:- You own the domain and have the rights to send emails from it
- You’ve authorized AhaSend to send emails on behalf of your domain
- Your emails are authentic and not spoofed or malicious
Prerequisites
Before setting up your domain, make sure you have:- Access to your DNS provider (usually your hosting provider or domain registrar)
- An AhaSend account with verified email address
- The domain or subdomain you want to use for sending emails
Managed DNS vs manual DNS: New domains in AhaSend use managed DNS (DNS v3) by default. Managed DNS shows two DKIM CNAME records so AhaSend can rotate DKIM keys safely over time. Some older or explicitly manual domains may still use the legacy single-DKIM-TXT setup instead. Your domain details page is always the source of truth for the exact records you need to publish.
Add your domain
Start by adding your domain to your AhaSend account:
- Log in to your AhaSend Dashboard
- Navigate to Domains in the sidebar
- Click “Add Domain”
- Enter your domain name (e.g.,
email.yourcompany.com) - Click “Create Domain”
API Alternative: You can also add domains programmatically using our Domains API.
Configure DNS records
Add the DNS records shown on your domain details page. The exact hostnames and values can vary by account, domain mode, and reseller configuration.
Required for sending: SPF, DKIM, and DMARC must be valid before the domain can send mail.Optional or feature-specific: Return-path, tracking, subscription management, media, and MX records improve deliverability or enable product features, but they are not all required for basic sending.
SPF record (Required)
SPF record (Required)
Sender Policy Framework (SPF) authorizes AhaSend to send emails on your domain’s behalf.Record Type:
TXT
Purpose: Prevents email spoofing by specifying authorized sending serversAhaSend can validate SPF through the return-path setup in some cases, but you should still publish the SPF record shown in your dashboard. It is the most portable and least surprising setup.
DKIM records (Required)
DKIM records (Required)
DomainKeys Identified Mail (DKIM) cryptographically signs your emails to verify authenticity.Record Type: Usually Manual DNS:
CNAME for managed DNS, sometimes TXT for manual DNS
Purpose: Prevents email tampering, confirms sender identity, and enables safe DKIM rotation on managed domainsManaged DNS (DNS v3):Managed DNS domains show two DKIM selectors: one active selector used for signing now, and one standby selector used for future rotation. Your domain can verify with the active selector alone, but publishing both DKIM CNAMEs up front is recommended so future DKIM rotation does not require another DNS change.
If you are working with a legacy or explicitly manual domain, your dashboard will show a single DKIM TXT record instead of the managed CNAME-based setup.
DMARC record (Required)
DMARC record (Required)
Domain-based Message Authentication, Reporting and Conformance (DMARC) provides policy guidance for email authentication failures.Record Type:
TXT
Purpose: Protects your domain from email spoofing and phishing attacksThis DMARC policy asks receiving servers to quarantine messages that fail DMARC. It has no
rua tag and sends no aggregate reports. You can add your own rua=mailto:reports@yourdomain.com address to receive reports. If the domain already has a DMARC record, update that record instead of adding another. Check all services that send from the domain before enforcing a quarantine policy.Subdomains inherit the root record. If you add
mail.example.com, the DNS check first looks for _dmarc.mail.example.com. If there is none, it looks for _dmarc.example.com and accepts that. You only need a DMARC record on the subdomain itself when you want a different policy or reporting address for it.Return-Path record (Highly recommended)
Return-Path record (Highly recommended)
Return-Path specifies where bounce messages and delivery notifications should be sent.Record Type:
CNAME
Purpose: Improves deliverability by providing a communication channel for bounce handling and SPF alignmentEmail tracking record (Optional)
Email tracking record (Optional)
Tracking Domain ensures tracking URLs in your emails come from your domain instead of AhaSend’s.Record Type:
CNAME
Purpose: Improves deliverability and maintains brand consistency for tracked linksEmail tracking is disabled by default and must be explicitly enabled in your account settings, even if you configure the tracking domain.
Subscription management record (Optional)
Subscription management record (Optional)
Subscription management domain hosts unsubscribe and subscription management links on your own domain.Record Type:
CNAME
Purpose: Keeps subscription management links branded on your domainThis record is optional, but recommended if you want subscription management URLs to use your own domain instead of an AhaSend hostname.
Media record (Optional)
Media record (Optional)
Media domain serves hosted media assets from your own domain.Record Type:
CNAME
Purpose: Keeps hosted assets and media URLs branded on your domainThis record is optional and mainly useful if you use AhaSend-hosted assets or want a consistent branded media hostname.
MX record (Recommended)
MX record (Recommended)
Mail Exchanger (MX) specifies the mail server responsible for receiving emails for your domain.Record Type:
MX
Purpose: Required for receiving emails, recommended for better sending reputationWhile not required for sending emails, some receiving servers penalize domains without MX records. Adding this record improves overall deliverability.
Wait for DNS propagation
DNS changes can take time to propagate across the internet:
- Typical time: 5-30 minutes
- Maximum time: Up to 48 hours
- Check status: Use online DNS checkers to verify your records are live
Verify your domain
Once your DNS records are live, verify your domain in AhaSend:
- Return to your domain details page in the dashboard
- Click “Check DNS” to run verification
- Wait for confirmation - this usually takes just a few seconds
- Look for the green checkmarks next to each record type
Success! When SPF, DKIM, and DMARC show as valid, your domain is ready to send emails.
On managed DNS domains, you may see a second DKIM selector that is marked as standby or not currently required. That is expected. Publishing it anyway is recommended so DKIM rotation can happen without a future DNS update.
DNS provider guides
Choose your authoritative DNS provider for record names and setup steps.Cloudflare
GoDaddy
Namecheap
Route 53
Hetzner
IONOS
STRATO
TransIP
OVHcloud
Squarespace
Vercel
How do I manage domains through the API?
For programmatic domain management, use our comprehensive Domains API:Create domain
Add new domains programmatically
List domains
Retrieve all your configured domains
Get domain details
Check domain verification status
Delete domain
Remove domains from your account
API v2 also supports updating domain DNS settings such as tracking, return-path, subscription, media, and DKIM rotation interval, as well as requesting a DNS check for an existing domain.
Why is my domain not verified?
Most records verify within minutes. DNS changes can take up to 48 hours to propagate. After a domain is added or verified, allow up to 2 minutes for the SMTP configuration to refresh if you see556 Invalid account or domain.
DNS records not verifying
DNS records not verifying
Common causes and solutions:
- Wait longer: DNS propagation can take up to 48 hours
- Check record values: Ensure exact copy-paste from dashboard (no extra spaces)
- Verify record type: SPF and DMARC use TXT; DKIM can be
CNAMEorTXTdepending on your domain mode - Remove duplicates: Don’t create multiple SPF records
- Check with DNS tools: Use online DNS checkers to verify records are live
Existing SPF record conflicts
Existing SPF record conflicts
If you already have an SPF record:
- Don’t create a duplicate - domains can only have one SPF record
- Modify your existing record by adding
include:spf.ahasend.com - Place it before the final mechanism (
~allor-all)
Why do I see two DKIM records?
Why do I see two DKIM records?
Managed DNS domains use two DKIM selectors.
- Active selector: Used for signing mail right now and required for verification
- Standby selector: Reserved for the next DKIM rotation
Subdomain vs root domain
Subdomain vs root domain
Understanding the difference:
- Root domain:
yourcompany.com(affects all subdomains) - Subdomain:
email.yourcompany.com(isolated setup)
_dmarc.<root domain> when the subdomain has none.Records like return-path, tracking, subscription management, and media are usually additional subdomains under the domain you add to AhaSend.Still having issues?
Still having issues?
We’re here to help:
- Check our status page for any ongoing DNS issues
- Contact support at support@ahasend.com
- Include your domain name and specific error messages
- Attach screenshots of your DNS configuration if helpful
What’s next?
Once your domain is verified, you’re ready to start sending emails:Send your first email
Follow our quickstart guide to send emails via API or SMTP
Create SMTP credentials
Generate credentials for your applications
Create API keys
Track email delivery and engagement events
Enable tracking
Monitor opens and clicks on your emails
Domain setup complete? Your domain is now ready to send emails through AhaSend. Test it out with our quickstart guide to send your first email!
Common domain questions
Can I keep my existing SPF record?
Yes. Addinclude:spf.ahasend.com to the existing SPF record before its final ~all or -all mechanism. Do not publish a second SPF record.
Why are there two DKIM records?
Managed DNS uses one active key and one standby key so AhaSend can rotate signing keys. Publish both CNAMEs shown in your dashboard.How long does verification take?
Most records verify within minutes. DNS changes can take up to 48 hours to propagate. Check the DNS host, type and value if verification still fails.Should I use a subdomain?
Use a dedicated subdomain when you want to separate transactional sending from other mail on your main domain. Add and verify that subdomain in AhaSend.Domain, Delivery and Migration Guides
- DNS provider guides: record names and setup steps for Cloudflare, GoDaddy, Namecheap, Route 53, Hetzner, IONOS, STRATO, TransIP, OVHcloud, Squarespace and Vercel.
- SPF, DKIM and DMARC: what each check proves and how domain alignment works.
- Bounces and suppressions and SMTP error codes: understand a failed send and choose the next step.
- Deliverability best practices: sender reputation, warm-up, sending subdomains, Gmail and Yahoo requirements, and one-click unsubscribe.
- Migrate from SendGrid, Mailgun, Postmark, Resend or Amazon SES, including suppression imports.
- Troubleshooting and FAQ: domain checks, missing messages, port 465, permission errors and blocked recipients.
- Email glossary and credential security: definitions and practical steps to protect your account.

