Qelzavo

Domains and the records behind them

03 / Mail setup

Your invoices land in spambecause of one record.

We set up email on your domain for Google Workspace, Microsoft 365 or Fastmail: MX, SPF, DKIM and DMARC, staged so nothing breaks, then two weeks of reading the DMARC reports. For small businesses whose mail goes missing and nobody can say why.

Price basis
From USD 280 per domain
Report reading
14 days included
SPF limit
10 lookups, RFC 7208

SPF, DKIM and DMARC setup, in the right order

Your SPF record allows 10 DNS lookups. Yours is at 13. That is why the invoices land in spam. We see this every month: Google Workspace for staff mail, then Mailchimp for the newsletter, then HubSpot, then a booking tool, each one telling the owner to "add our include". Nobody counts. The receiving server does, and past 10 it returns permerror and treats the whole record as broken.

Fixing it is rarely a mystery. It is arithmetic and a bit of housekeeping: remove the includes for tools you cancelled in 2021, move bulk senders to a subdomain with its own SPF, and stop flattening records by hand into IP lists that go stale the next time a provider changes its ranges.

MX records for Google Workspace, Microsoft 365 and Fastmail

MX tells the world where your mail is delivered. Get it wrong and mail bounces. Get it half right, with an old host still listed at a lower priority, and some mail quietly goes to a mailbox nobody reads. We remove stale MX entries before adding the new ones and we never leave two providers competing.

Google Workspace now uses a single MX target, smtp.google.com, at priority 1. Older setups list five aspmx hosts; they still work and we leave them if they are correct. Microsoft 365 gives each tenant its own target under mail.protection.outlook.com. Fastmail uses two hosts, in1-smtp.messagingengine.com and in2-smtp.messagingengine.com, at priorities 10 and 20.

DKIM: the signature that survives forwarding

SPF checks the sending server. DKIM signs the message itself, so it still passes when mail is forwarded through a mailing list or a university alias. Each provider generates its own key and publishes it under a selector. We use 2048-bit keys where the DNS host accepts the length; some older control panels cut TXT values at 255 characters and need the key split into two quoted strings. We check that the published key matches what the provider is signing with, by sending a test and reading the headers.

DMARC, staged

Set DMARC to p=none first. Watch the reports for two weeks. Then tighten it. A DMARC record jumped straight to p=reject on a domain with an uncounted invoicing tool will reject your own invoices. The reports show every server sending as your domain, which is how forgotten senders turn up. Usually it is the copier that emails scans. Sometimes it is the accountant's software, or the contact form on a website you replaced two years ago, or a payroll service that sends payslips as you.

After the two weeks we send you a short summary: which senders pass, which fail, what to fix, and when to move to p=quarantine. Most small domains are ready for quarantine at week three and reject a month after that. We will not push a policy past what the reports support.

Records / Sample

Sample recordsfor each provider

Values are the provider defaults at time of writing for a fictional example-bakery.com. Providers change them. Your own values come from your admin console, and we check them against it.

MXexample-bakery.com. 3600 IN MX 1 smtp.google.com.
SPF · TXT · 4 lookupsexample-bakery.com. 3600 IN TXT "v=spf1 include:_spf.google.com ~all"
DKIM · TXTgoogle._domainkey.example-bakery.com. 3600 IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqh...(key from Admin console)"

The Google include costs 4 lookups on its own, which leaves 6 for everything else. That budget is why the SPF limit catches Workspace customers first.

DMARC · week 1 to 2 · all providers_dmarc.example-bakery.com. 3600 IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]; fo=1"
13

The SPF lookup count we find most often on a domain that says its mail goes to spam. The limit is 10. Count yours in the SPF lookup calculator.

SPF too many DNS lookups: a typical broken record, counted
MechanismLookupsWhat we do with it
include:_spf.google.com4Keep. Staff mail.
include:servers.mcsv.net1Move to a news. subdomain with its own SPF.
HubSpot include2Keep if HubSpot sends as the root domain, else move.
include:sendgrid.net1Cancelled tool. Remove.
Shopify include2Keep. Order confirmations.
a and mx2Nothing sends from them. Remove both.
include:zoho.com1Left over from 2019. Remove.
Total13 → 8Under the limit with room for one more tool.

How a mail setup runs

Fifteen days on the calendar, about four hours of our time. The two weeks of DMARC reading is most of the calendar, and it is the part that finds the senders nobody listed.

DNS record editor on screen with mail record rows
Changes are made in your DNS account, with your login or a delegated user. Never ours.
  1. Day 1. Inventory

    We list every tool that sends mail as your domain. You tell us what you know; the current SPF and DKIM selectors tell us the rest. We count the SPF lookups and write the target records before touching anything.

  2. Day 1. Lower the TTL

    MX and TXT records drop to 300 seconds. If the old TTL was 86400, we wait a full day before the switch. That is the whole trick to changing mail without losing any.

  3. Day 2. Switch and sign

    New MX, cleaned SPF, DKIM published and switched on at the provider, DMARC at p=none with reports going to an address you own. Test messages to Gmail, Outlook.com and Yahoo, headers read for spf=pass, dkim=pass and alignment.

  4. Days 3 to 14. Read the reports

    Aggregate reports arrive daily from the large mailbox providers. We read them, flag senders that fail, and fix or remove them as they show up.

  5. Day 15. Summary and domain card

    A written summary with the date to move to quarantine, and your domain card showing MX target and SPF lookup count against the limit of 10. Re-checks within 30 days of handover are free.

Questions

Before you changea mail record

Can you guarantee my mail lands in the inbox?

No, and nobody honest can. Inbox placement depends on content, sending volume and how recipients treat your mail, as well as records. We make sure the records are correct, aligned and under the limits, which is the part a domain controls.

Will mail stop while you change the MX records?

Not if the TTL is lowered first. We drop it to 300 seconds a day ahead, wait out the old value, then switch. Mail in flight is retried by the sending server for days, not minutes.

Can I not just paste the records my provider gave me?

Often you can, and for a domain with one sender that is enough. It breaks when you already have an SPF record: a second v=spf1 TXT is itself a permerror. The fix is merging them into one, and that is where the lookup count gets exceeded.

Do I need a domain name for small business mail, or will Gmail do?

A free address works until a customer forwards your quote to their accounts team and it looks like a personal message. A domain costs about the same per year as a lunch. If you do not have one yet, start at the domain name shortlist.

Who is this not for?

If you need ten years of mailboxes migrated between providers, that is a mailbox migration job. We set the DNS side and can name people who do migrations, but we do not move mailbox content. And if the domain itself is in doubt, start with a domain name check.

Inquiry

Tell us the domainand the provider.