Sending domain and DNS
Verifying your domain with DKIM, and why SPF and DMARC matter.
Sending from your own domain is what makes an email look like it came from you rather than from a platform. It is also the single biggest thing you can do for deliverability.
What you are proving
Mailbox providers will not take your word for who you are. Three DNS records let them check:
| Record | What it proves |
|---|---|
| SPF | Which servers are allowed to send mail for your domain. |
| DKIM | That the message really came from your domain and was not altered in transit. |
| DMARC | What a receiver should do when SPF or DKIM fails, and where to report it. |
Setting it up
- 1In
Settings → Domains, enter the domain you want to send from — the bare domain likeyourdomain.com, not a full address. - 2Nectazo shows you three DKIM CNAME records.
- 3Add them at your DNS provider — wherever you manage your domain's records.
- 4Come back and let Nectazo check. It re-checks automatically and shows you the result.
Records usually appear within 15 minutes but can take up to 48 hours. If verification is still failing after a day, the usual cause is the record name being entered with the domain appended twice — many DNS panels add it for you.
SPF and DMARC
The Deliverability page checks whether your domain has SPF and DMARC records and shows you what to add if not. DMARC in particular is worth having: Gmail and Yahoo now require it for anyone sending in volume.
A reasonable starting DMARC record, which only monitors and changes nothing:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
Once you have watched the reports for a few weeks and confirmed all your legitimate mail passes, tighten p=none to p=quarantine.
Setting your from-address to a gmail.com or outlook.com address will see your mail rejected or junked, because those domains publish DMARC policies that forbid anyone else sending as them. Use a domain you own.
Something unclear or wrong? Tell us and we'll fix it.