03 / Mail setup
Your invoices land in spambecause of one record.
We set up email on your domain for Google Workspace, Microsoft 365 or Fastmail: MX, SPF, DKIM and DMARC, staged so nothing breaks, then two weeks of reading the DMARC reports. For small businesses whose mail goes missing and nobody can say why.
SPF, DKIM and DMARC setup, in the right order
Your SPF record allows 10 DNS lookups. Yours is at 13. That is why the invoices land in spam. We see this every month: Google Workspace for staff mail, then Mailchimp for the newsletter, then HubSpot, then a booking tool, each one telling the owner to "add our include". Nobody counts. The receiving server does, and past 10 it returns permerror and treats the whole record as broken.
Fixing it is rarely a mystery. It is arithmetic and a bit of housekeeping: remove the includes for tools you cancelled in 2021, move bulk senders to a subdomain with its own SPF, and stop flattening records by hand into IP lists that go stale the next time a provider changes its ranges.
MX records for Google Workspace, Microsoft 365 and Fastmail
MX tells the world where your mail is delivered. Get it wrong and mail bounces. Get it half right, with an old host still listed at a lower priority, and some mail quietly goes to a mailbox nobody reads. We remove stale MX entries before adding the new ones and we never leave two providers competing.
Google Workspace now uses a single MX target, smtp.google.com, at priority 1. Older setups list five aspmx hosts; they still work and we leave them if they are correct. Microsoft 365 gives each tenant its own target under mail.protection.outlook.com. Fastmail uses two hosts, in1-smtp.messagingengine.com and in2-smtp.messagingengine.com, at priorities 10 and 20.
DKIM: the signature that survives forwarding
SPF checks the sending server. DKIM signs the message itself, so it still passes when mail is forwarded through a mailing list or a university alias. Each provider generates its own key and publishes it under a selector. We use 2048-bit keys where the DNS host accepts the length; some older control panels cut TXT values at 255 characters and need the key split into two quoted strings. We check that the published key matches what the provider is signing with, by sending a test and reading the headers.
DMARC, staged
Set DMARC to p=none first. Watch the reports for two weeks. Then tighten it. A DMARC record jumped straight to p=reject on a domain with an uncounted invoicing tool will reject your own invoices. The reports show every server sending as your domain, which is how forgotten senders turn up. Usually it is the copier that emails scans. Sometimes it is the accountant's software, or the contact form on a website you replaced two years ago, or a payroll service that sends payslips as you.
After the two weeks we send you a short summary: which senders pass, which fail, what to fix, and when to move to p=quarantine. Most small domains are ready for quarantine at week three and reject a month after that. We will not push a policy past what the reports support.
Records / Sample
Sample recordsfor each provider
Values are the provider defaults at time of writing for a fictional example-bakery.com. Providers change them. Your own values come from your admin console, and we check them against it.
The Google include costs 4 lookups on its own, which leaves 6 for everything else. That budget is why the SPF limit catches Workspace customers first.
selector2._domainkey CNAME selector2-example-bakery-com._domainkey.(tenant).onmicrosoft.com.
Microsoft publishes DKIM as two CNAMEs so it can rotate keys. Both must exist before you switch DKIM signing on in the Defender portal, or the toggle refuses.
example-bakery.com. 3600 IN MX 20 in2-smtp.messagingengine.com.
fm2._domainkey CNAME fm2.example-bakery.com.dkim.fmhosted.com.
fm3._domainkey CNAME fm3.example-bakery.com.dkim.fmhosted.com.
Fastmail ships SPF with ?all, a neutral ending. Once DMARC reports confirm every sender, we move it to ~all.
The SPF lookup count we find most often on a domain that says its mail goes to spam. The limit is 10. Count yours in the SPF lookup calculator.
| Mechanism | Lookups | What we do with it |
|---|---|---|
include:_spf.google.com | 4 | Keep. Staff mail. |
include:servers.mcsv.net | 1 | Move to a news. subdomain with its own SPF. |
| HubSpot include | 2 | Keep if HubSpot sends as the root domain, else move. |
include:sendgrid.net | 1 | Cancelled tool. Remove. |
| Shopify include | 2 | Keep. Order confirmations. |
a and mx | 2 | Nothing sends from them. Remove both. |
include:zoho.com | 1 | Left over from 2019. Remove. |
| Total | 13 → 8 | Under the limit with room for one more tool. |
How a mail setup runs
Fifteen days on the calendar, about four hours of our time. The two weeks of DMARC reading is most of the calendar, and it is the part that finds the senders nobody listed.
Day 1. Inventory
We list every tool that sends mail as your domain. You tell us what you know; the current SPF and DKIM selectors tell us the rest. We count the SPF lookups and write the target records before touching anything.
Day 1. Lower the TTL
MX and TXT records drop to 300 seconds. If the old TTL was 86400, we wait a full day before the switch. That is the whole trick to changing mail without losing any.
Day 2. Switch and sign
New MX, cleaned SPF, DKIM published and switched on at the provider, DMARC at
p=nonewith reports going to an address you own. Test messages to Gmail, Outlook.com and Yahoo, headers read forspf=pass,dkim=passand alignment.Days 3 to 14. Read the reports
Aggregate reports arrive daily from the large mailbox providers. We read them, flag senders that fail, and fix or remove them as they show up.
Day 15. Summary and domain card
A written summary with the date to move to quarantine, and your domain card showing MX target and SPF lookup count against the limit of 10. Re-checks within 30 days of handover are free.
Questions
Before you changea mail record
Can you guarantee my mail lands in the inbox?
No, and nobody honest can. Inbox placement depends on content, sending volume and how recipients treat your mail, as well as records. We make sure the records are correct, aligned and under the limits, which is the part a domain controls.
Will mail stop while you change the MX records?
Not if the TTL is lowered first. We drop it to 300 seconds a day ahead, wait out the old value, then switch. Mail in flight is retried by the sending server for days, not minutes.
Can I not just paste the records my provider gave me?
Often you can, and for a domain with one sender that is enough. It breaks when you already have an SPF record: a second v=spf1 TXT is itself a permerror. The fix is merging them into one, and that is where the lookup count gets exceeded.
Do I need a domain name for small business mail, or will Gmail do?
A free address works until a customer forwards your quote to their accounts team and it looks like a personal message. A domain costs about the same per year as a lunch. If you do not have one yet, start at the domain name shortlist.
Who is this not for?
If you need ten years of mailboxes migrated between providers, that is a mailbox migration job. We set the DNS side and can name people who do migrations, but we do not move mailbox content. And if the domain itself is in doubt, start with a domain name check.
Inquiry