The records, in plain language.
DKIM adds a digital signature to every email. Mailumi gives you three CNAME records that point to signing keys managed for you, so you never handle a private key. SPF lists which servers may send for your domain. Mailumi uses a dedicated return-path subdomain, send.yourbrand.com, with its own SPF and MX record, so your existing SPF record stays untouched.
DMARC tells inboxes what to do when a message fails those checks. If your domain has no DMARC record yet, Mailumi recommends a safe starting policy, v=DMARC1; p=none;, which you can tighten later. A small ownership TXT record links the domain to your workspace.
Step by step.
- Add your domain in Dashboard → Domains, for example yourbrand.com or mail.yourbrand.com.
- Copy each record into your DNS provider. The step-by-step guide on the Domains page detects your provider and shows where to click, with the exact values to enter.
- On Cloudflare, set the CNAME records to DNS only, not proxied.
- Click Verify records. Most changes show up within minutes, and Mailumi keeps checking new domains automatically for 72 hours.
Where to find DNS settings: in Cloudflare, DNS → Records. In Namecheap, Domain List → Manage → Advanced DNS. In GoDaddy, My Products → DNS. In TransIP, Hostinger and IONOS, open the DNS settings of your domain. The record types and values are the same everywhere.
One-click setup on Cloudflare.
If your domain uses Cloudflare, choose Connect Cloudflare. Sign in to Cloudflare, allow Mailumi to edit DNS, check the records and confirm. Mailumi adds only the missing records, and its access ends as soon as they are added. No API tokens or zone IDs to copy.
Existing records are respected. If a hostname already has a conflicting MX, SPF or CNAME record, Mailumi shows it for review instead of overwriting it, so your website and current mailboxes keep working.
Every record and what it does
| Host | Type | Purpose |
|---|---|---|
| _mailumi.yourbrand.com | TXT | Proves the domain belongs to your workspace |
| …._domainkey.yourbrand.com (3 records) | CNAME | DKIM: signs every email with your domain |
| send.yourbrand.com | MX | Return path for bounces and complaints |
| send.yourbrand.com | TXT | SPF for the return path: v=spf1 include:amazonses.com ~all |
| _dmarc.yourbrand.com | TXT | DMARC policy, starting with p=none |
| yourbrand.com or a subdomain | MX | Only when you turn on receiving |
SPF, DKIM and DMARC setup: common questions
- Do I need to change my website hosting or current email?
- No. These records only add email authentication. Your website and existing mailboxes keep working, and because Mailumi uses its own return-path subdomain you do not need to edit your existing SPF record.
- How long does verification take?
- Usually a few minutes after you save the records. Some DNS providers take up to 48 hours. Mailumi re-checks new domains automatically, so you can close the page and come back later.
- Which DMARC policy should I start with?
- Start with p=none to monitor without affecting delivery. Once all your legitimate mail passes SPF and DKIM, move to p=quarantine and then p=reject.
- Why do Gmail and Yahoo require this?
- Since 2024, Gmail and Yahoo require bulk senders to authenticate with SPF and DKIM and to publish a DMARC policy. Authenticated email is also more likely to reach the inbox for every sender, big or small.
- Does it work with Namecheap, GoDaddy and other DNS providers?
- Yes. Any DNS provider that lets you add TXT, CNAME and MX records works. The dashboard has a step-by-step guide for popular providers; on Cloudflare, Mailumi can add the records for you.
Sources
Sources checked . Third-party features and prices may change.