Sending provider
Mailgun SPF, DKIM and DMARC setup
Mailgun verifies the domain you add to it, usually a subdomain such as mg.example.com: an SPF TXT record v=spf1 include:mailgun.org ~all, a DKIM key (a TXT record, or the pdk1 and pdk2 CNAMEs with Automatic Sender Security), a tracking CNAME to mailgun.org and two MX records. Mailgun's docs give no DMARC record; add one at _dmarc yourself.
Mailgun
Records at a glance
- SPF record
v=spf1 include:mailgun.org ~all- DKIM
TXT key from the Control Panel, or CNAMEs pdk1 and pdk2
- DMARC
Not in Mailgun's records: add a TXT at _dmarc
Check Mailgun on your domain
Enter the domain you send from: the check looks for the Mailgun SPF include, its DKIM key and your DMARC record, and says what to fix.
Enter the domain you added in Mailgun, e.g. mg.example.com. Looks for SPF include:mailgun.org, DKIM at pdk1 and pdk2 and a DMARC record. Lookups go from your browser to Cloudflare's public DNS resolver.
DNS records
The Mailgun records
Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.
- Name / host
@ (the domain added in Mailgun)Valuev=spf1 include:mailgun.org ~allIf that domain already has an SPF record, add include:mailgun.org to it
- Name / host
<selector>._domainkeyValue<TXT value from Domain Verification & DNS>The default: Mailgun shows the selector and key for each domain in the Control Panel
- Name / host
pdk1._domainkeyValuepdk1._domainkey.<id>.dkim1.mailgun.comWith Automatic Sender Security; <id> is per account (9d876 in Mailgun's example). pdk2 follows the same pattern
- VerificationCNAMEsource (opens the vendor's page in a new tab)Name / host
emailValuemailgun.orgTracking for opens, clicks and unsubscribes; the prefix is email by default
- VerificationMXsource (opens the vendor's page in a new tab)Name / host
@ (the domain added in Mailgun)Value10 mxa.mailgun.org, 10 mxb.mailgun.orgNeeded to receive mail at the domain through Mailgun
Good to know
- Mailgun recommends separate domains or subdomains for marketing and transactional mail and the top-level domain for corporate mailsource (opens the vendor's page in a new tab)
- Manual DKIM keys are 1024 or 2048-bit; Automatic Sender Security uses 2048-bit keys and rotates them every 120 days by defaultsource (opens the vendor's page in a new tab)
- Use the same domain in the From address as the sending domain; Mailgun says a mismatch can land mail in Outlook's junk foldersource (opens the vendor's page in a new tab)
Step by step
Add and verify the domain in Mailgun
Add the domainsource (opens the vendor's page in a new tab)
In the Control Panel open Send > Sending > Domains, click Add new domain and enter the domain or subdomain you will send from
Pick region and securitysource (opens the vendor's page in a new tab)
Select the domain region and IP assignment; turn on Automatic Sender Security to get the pdk1 and pdk2 CNAMEs with rotating keys
Copy the recordssource (opens the vendor's page in a new tab)
Click Add Domain, then copy every record from Domain Settings (Domain Verification & DNS)
Publish themsource (opens the vendor's page in a new tab)
Create the SPF TXT, the DKIM record, the tracking CNAME and the MX records at your DNS host
Verifysource (opens the vendor's page in a new tab)
Click Verify DNS settings, or wait for the automatic check. A verified domain shows a green Verified badge
Where the records go
Field by field for the DNS panel your domain uses:
DMARC
DMARC with Mailgun
- Mailgun's domain records do not include DMARC; publish your own TXT record at _dmarc of the From domainsource (opens the vendor's page in a new tab)
- Start with v=DMARC1; p=none; rua=mailto:dmarc@<yourdomain> and move to quarantine once the reports show Mailgun and your other senders passingsource
TXT at _dmarc
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comReplace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.
Troubleshooting
Common Mailgun errors and fixes
Domain not verified yet
DNS can take 24 to 48 hours; click Verify DNS settings again or call the verify APIsource (opens the vendor's page in a new tab)
Some DKIM keys show Unverified
Only the key the domain is configured to sign with has to verify; the others can stay Unverifiedsource (opens the vendor's page in a new tab)
2048-bit DKIM TXT rejected as too long
Some DNS hosts need the key split into two strings in one recordsource (opens the vendor's page in a new tab)
Old key still signing after rotation
Send test messages to confirm the new key signs, then delete the old onesource (opens the vendor's page in a new tab)
Mail lands in junk at Outlook
Send with a From address on the same domain you verified in Mailgunsource (opens the vendor's page in a new tab)
For cold email
Mailboxes that come with the DNS records done
If the domain is for cold outreach, keep Mailgun on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.
- SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
- $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
- 1,000+ mailboxesA volume price per mailbox, quoted on a call
Questions
What is the Mailgun SPF record?
v=spf1 include:mailgun.org ~all on the domain you added to Mailgun. If that domain already has SPF, add include:mailgun.org to the existing record; two SPF records on one domain break SPF.
Where do I find the Mailgun DKIM selector?
In the Control Panel under the domain's Domain Verification & DNS records. With Automatic Sender Security the selectors are pdk1 and pdk2, published as CNAMEs.
Does Mailgun need a DMARC record?
Gmail and Yahoo require DMARC from bulk senders, and Mailgun leaves it out of the domain records. Add a TXT record at _dmarc of the From domain, starting with p=none.
Should I use a subdomain for Mailgun?
Mailgun recommends separate domains or subdomains for marketing and transactional mail. A subdomain like mg.example.com keeps its own SPF and DKIM and leaves the root SPF record alone.
Sources
Mailgun documentation, checked . Menus and values change; if a step differs, Mailgun's own page is the reference.
Deliverability call
Talk to our deliverability team
Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.
- Review your domains, DNS records and current inbox placement
- Size the setup: domains, mailboxes per domain and daily volume per mailbox
- Plan warm-up and the move from your current provider or sequencer
- 1,000+ mailboxes: a volume price per mailbox for your setup
Free call
See open times in your time zone and book on this page.
Or open the booking pageLoading available times…
Open the booking page instead