How-to
Check each provider's DNS setup
The Provider setup panel verifies the SPF and DKIM records each detected sending service requires, with a live re-check per provider.
Jump to section
Every sending service you use — Microsoft 365, SendGrid, Mailgun, your CRM — publishes its own required DNS records. When one is missing, that provider's mail fails authentication no matter how good your DMARC policy is. The Provider setup panel checks them for you.
What it checks
Open a domain and choose Provider setup in the side menu. For each service detected in your report data, the panel shows:
- SPF — whether your record contains the include that provider requires.
- DKIM — whether the provider's signing keys are published at the selectors it uses.
- Missing records — the exact DNS entries to add when something is absent, plus a link to the provider's own setup documentation.
- The message volume observed from that provider in the window, so you can fix the biggest senders first.
Verify after you change DNS
The Verify button on each provider row re-checks its records live. Run it after publishing a change rather than waiting for the next scheduled sweep — DNS edits typically show within minutes, subject to your records' TTL.
When a provider shows unconfigured but mail is passing
Some providers sign with DKIM keys hosted on their own domain via CNAME, or route returns through their own bounce domain. If alignment on the domain's Sources table looks healthy, treat the provider's documentation link as the tie-breaker.