Sending provider

Mailgun SPF, DKIM and DMARC setup

Mailgun verifies the domain you add to it, usually a subdomain such as mg.example.com: an SPF TXT record v=spf1 include:mailgun.org ~all, a DKIM key (a TXT record, or the pdk1 and pdk2 CNAMEs with Automatic Sender Security), a tracking CNAME to mailgun.org and two MX records. Mailgun's docs give no DMARC record; add one at _dmarc yourself.

Mailgun

Records at a glance

SPF record
v=spf1 include:mailgun.org ~all
DKIM

TXT key from the Control Panel, or CNAMEs pdk1 and pdk2

DMARC

Not in Mailgun's records: add a TXT at _dmarc

Check Mailgun on your domain

Enter the domain you send from: the check looks for the Mailgun SPF include, its DKIM key and your DMARC record, and says what to fix.

Enter the domain you added in Mailgun, e.g. mg.example.com. Looks for SPF include:mailgun.org, DKIM at pdk1 and pdk2 and a DMARC record. Lookups go from your browser to Cloudflare's public DNS resolver.

DNS records

The Mailgun records

Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.

Good to know

Step by step

Add and verify the domain in Mailgun

  1. Add the domainsource (opens the vendor's page in a new tab)

    In the Control Panel open Send > Sending > Domains, click Add new domain and enter the domain or subdomain you will send from

  2. Pick region and securitysource (opens the vendor's page in a new tab)

    Select the domain region and IP assignment; turn on Automatic Sender Security to get the pdk1 and pdk2 CNAMEs with rotating keys

  3. Copy the recordssource (opens the vendor's page in a new tab)

    Click Add Domain, then copy every record from Domain Settings (Domain Verification & DNS)

  4. Publish themsource (opens the vendor's page in a new tab)

    Create the SPF TXT, the DKIM record, the tracking CNAME and the MX records at your DNS host

  5. Verifysource (opens the vendor's page in a new tab)

    Click Verify DNS settings, or wait for the automatic check. A verified domain shows a green Verified badge

DMARC

DMARC with Mailgun

  • Mailgun's domain records do not include DMARC; publish your own TXT record at _dmarc of the From domainsource (opens the vendor's page in a new tab)
  • Start with v=DMARC1; p=none; rua=mailto:dmarc@<yourdomain> and move to quarantine once the reports show Mailgun and your other senders passingsource
DMARCA safe first record

TXT at _dmarc

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

Replace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.

Troubleshooting

Common Mailgun errors and fixes

For cold email

Mailboxes that come with the DNS records done

If the domain is for cold outreach, keep Mailgun on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.

  • SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
  • $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
  • 1,000+ mailboxesA volume price per mailbox, quoted on a call

Questions

What is the Mailgun SPF record?

v=spf1 include:mailgun.org ~all on the domain you added to Mailgun. If that domain already has SPF, add include:mailgun.org to the existing record; two SPF records on one domain break SPF.

Where do I find the Mailgun DKIM selector?

In the Control Panel under the domain's Domain Verification & DNS records. With Automatic Sender Security the selectors are pdk1 and pdk2, published as CNAMEs.

Does Mailgun need a DMARC record?

Gmail and Yahoo require DMARC from bulk senders, and Mailgun leaves it out of the domain records. Add a TXT record at _dmarc of the From domain, starting with p=none.

Should I use a subdomain for Mailgun?

Mailgun recommends separate domains or subdomains for marketing and transactional mail. A subdomain like mg.example.com keeps its own SPF and DKIM and leaves the root SPF record alone.

Deliverability call

Talk to our deliverability team

Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.

  • Review your domains, DNS records and current inbox placement
  • Size the setup: domains, mailboxes per domain and daily volume per mailbox
  • Plan warm-up and the move from your current provider or sequencer
  • 1,000+ mailboxes: a volume price per mailbox for your setup

Free call

See open times in your time zone and book on this page.

Or open the booking page