How-to

Check each provider's DNS setup

The Provider setup panel verifies the SPF and DKIM records each detected sending service requires, with a live re-check per provider.

1 min readLast updated 15 August 2026
Jump to section

Every sending service you use — Microsoft 365, SendGrid, Mailgun, your CRM — publishes its own required DNS records. When one is missing, that provider's mail fails authentication no matter how good your DMARC policy is. The Provider setup panel checks them for you.

What it checks

Open a domain and choose Provider setup in the side menu. For each service detected in your report data, the panel shows:

  • SPF — whether your record contains the include that provider requires.
  • DKIM — whether the provider's signing keys are published at the selectors it uses.
  • Missing records — the exact DNS entries to add when something is absent, plus a link to the provider's own setup documentation.
  • The message volume observed from that provider in the window, so you can fix the biggest senders first.

Verify after you change DNS

The Verify button on each provider row re-checks its records live. Run it after publishing a change rather than waiting for the next scheduled sweep — DNS edits typically show within minutes, subject to your records' TTL.

When a provider shows unconfigured but mail is passing

Some providers sign with DKIM keys hosted on their own domain via CNAME, or route returns through their own bounce domain. If alignment on the domain's Sources table looks healthy, treat the provider's documentation link as the tie-breaker.

Still stuck? Email support or open the support widget in the bottom-right.