One visible route from your domain to your inbox.
A plain-language overview of supported changes, approval points, provider boundaries, and how inbound and outbound mail use separate paths.
A plain-language overview of supported changes, approval points, provider boundaries, and how inbound and outbound mail use separate paths.
A message arrives
Someone writes to you
They only ever see your address
It lands in your Gmail
The inbox you already check — nothing new to open
You reply
You write from the inbox you know
Same app, same habits, same history
They see your domain
Not a free address — your name, every time
A read-only preflight checks common website, mail, DNSSEC, and certificate signals; a full-domain move still requires an authoritative export.
Supported records are prepared before cutover, and provider-confirmed checks gate Brand My Inbox readiness states.
The dashboard polls while setup is open, and scheduled monitoring continues for supported activation and health checks.
Three routes, one address on all of them. Most domains should take the first: three records at the DNS host you already use, and nothing else on the domain moves.
On the three-record route you publish the NS set, the _dmarc row and one DKIM CNAME (plus one optional MX if you want to receive at the bare domain), and we install DKIM, SPF, DMARC and the return path inside mail.yourdomain.com. On a full move we install all of them in the domain we now run; with scoped access we publish them inside your account.
| Record | Who publishes it | Value | Why it matters |
|---|---|---|---|
| NS at mail.yourdomain.com | You publish | The name servers shown during setup | Hands the mail.yourdomain.com corner of the domain to us, so the mail records can be hosted and repaired from our side. Nothing else on the domain is affected. |
| CNAME at _dmarc.yourdomain.com | You publish | The target shown during setup | Points your DMARC policy at the record we host, so it stays correct when the policy changes. |
| MX at yourdomain.com (optional) | You publish, only to receive at [email protected] | Provided during setup | Tells the world where mail for the domain should be received. Sending needs nothing more than the three records; receiving at the bare domain needs this one. |
| CNAME at <selector>._domainkey.yourdomain.com | You publish | The target shown during setup (inside mail.yourdomain.com) | Lets receivers verify our DKIM signature on mail from your domain. It points into the corner we host, so key rotation never asks you for a change. Without it, mail is unsigned for your domain and lands in spam. |
| SPF | We install, inside mail.yourdomain.com | Generated for the sending path in use | Authorizes the service that actually sends for your domain, without a conflicting SPF record on the bare domain. |
| DMARC and return path | We install, inside mail.yourdomain.com | Verified before the domain is marked ready | Defines how receivers handle a message that fails the checks, and gives bounces a home we monitor. |
Clear answers