Skip to main content

One visible route from your domain to your inbox.

A plain-language overview of supported changes, approval points, provider boundaries, and how inbound and outbound mail use separate paths.

Setup, end to end

1Enter domainwe scan your DNS2Pick a routethree records, scoped access,or full move3Records preparedstaged for review4You update DNSguided per registrar5Livemailboxes activeRUNNING IN THE BACKGROUNDExisting records read before anything changes · DKIM, SPF and DMARC installed · Routing table synced · Every change logged and emailed to the administrator

Where a message travels

A message arrives

Someone writes to you

They only ever see your address

Verified ✓

[email protected]

Your address, on your domain

It lands in your Gmail

The inbox you already check — nothing new to open

You reply

You write from the inbox you know

Same app, same habits, same history

Your brand

[email protected]

Your address, on your domain

They see your domain

Not a free address — your name, every time

An address is only marked ready after delivery is confirmed with a real message. Replying as your domain is set up as its own step, and we walk you through it.

How we reduce migration risk

  1. 1

    We scan before we touch anything

    A read-only preflight checks common website, mail, DNSSEC, and certificate signals; a full-domain move still requires an authoritative export.

  2. 2

    Your zone is staged for review

    Supported records are prepared before cutover, and provider-confirmed checks gate Brand My Inbox readiness states.

  3. 3

    We verify the visible switch

    The dashboard polls while setup is open, and scheduled monitoring continues for supported activation and health checks.

Choose your route

Three routes, one address on all of them. Most domains should take the first: three records at the DNS host you already use, and nothing else on the domain moves.

Recommended

Three records at your DNS host

[email protected]

  • You add an NS record set for mail., a DKIM CNAME and a DMARC record where your domain already lives; the domain's nameservers stay as they are
  • DKIM, SPF, DMARC and the return path are hosted by us and kept current
  • Your website and any mail already on the domain are not touched
  • Works with any DNS host that accepts an NS record
Already on your own DNS account

Scoped access to your DNS account

[email protected]

  • For a domain that already lives on a DNS account we can connect to with a token
  • You see the exact permissions before you grant anything, and can revoke them at any time
  • We publish and repair the mail records inside your account; your nameservers stay where they are
  • The token is limited to that one domain's DNS
Full move

Move the whole domain to us

[email protected]

  • Your nameservers are replaced with ours, and we then manage every record on the domain
  • We scan the domain first and carry every record over, with a backup taken before the switch
  • You see the complete plan before any change is made
  • The most work up front, and the only route that changes where your website's records are served from

The records, and who publishes each one

On the three-record route you publish the NS set, the _dmarc row and one DKIM CNAME (plus one optional MX if you want to receive at the bare domain), and we install DKIM, SPF, DMARC and the return path inside mail.yourdomain.com. On a full move we install all of them in the domain we now run; with scoped access we publish them inside your account.

RecordWho publishes itValueWhy it matters
NS at mail.yourdomain.comYou publishThe name servers shown during setupHands the mail.yourdomain.com corner of the domain to us, so the mail records can be hosted and repaired from our side. Nothing else on the domain is affected.
CNAME at _dmarc.yourdomain.comYou publishThe target shown during setupPoints your DMARC policy at the record we host, so it stays correct when the policy changes.
MX at yourdomain.com (optional)You publish, only to receive at [email protected]Provided during setupTells the world where mail for the domain should be received. Sending needs nothing more than the three records; receiving at the bare domain needs this one.
CNAME at <selector>._domainkey.yourdomain.comYou publishThe target shown during setup (inside mail.yourdomain.com)Lets receivers verify our DKIM signature on mail from your domain. It points into the corner we host, so key rotation never asks you for a change. Without it, mail is unsigned for your domain and lands in spam.
SPFWe install, inside mail.yourdomain.comGenerated for the sending path in useAuthorizes the service that actually sends for your domain, without a conflicting SPF record on the bare domain.
DMARC and return pathWe install, inside mail.yourdomain.comVerified before the domain is marked readyDefines how receivers handle a message that fails the checks, and gives bounces a home we monitor.

Clear answers

Technical questions, answered simply

Ready to try it on your domain?

Start Setup