Setup guide

SPF · DKIM · DMARC

Set up SPF, DKIM and DMARC on Mailgun

The DNS records that make Mailgun a verified sender for your domain — publish them on your sending subdomain, click Verify, and confirm they resolve.

Before you start

What Mailgun needs from your DNS.

Mailgun is a sending platform, not your mailbox host, so it authenticates a dedicated sending subdomain — typically mg.yourdomain.com — rather than your root domain. SPF authorises Mailgun's servers to send for that subdomain, DKIM signs each message with a key Mailgun generates for you, and DMARC on your root domain ties both back to the address recipients see.

None of these records is created for you. Mailgun shows the exact values under Sending → Domain settings → DNS records the moment you add a domain, but they do nothing until you publish them at your own DNS host and click Verify. Because Mailgun generates a unique DKIM selector and key per domain, you cannot copy a DKIM value from a guide — you must read it from your own control panel.

Since February 2024, Gmail and Yahoo require anyone sending in bulk to publish SPF, DKIM and DMARC. If you already send from your root domain through a mailbox provider, keep that record intact: add Mailgun on its own subdomain and let DMARC alignment cover both.

The records to publish

Copy these into your DNS.

Add each record at your DNS provider — the company where your domain is registered, not Mailgun. Then run the checker to confirm every one resolves.

SPF record

host  mg type  TXT
v=spf1 include:mailgun.org ~all

Publish this on your Mailgun sending subdomain (mg.yourdomain.com), not the root. If a record already exists there, merge include:mailgun.org into it rather than adding a second SPF record, which voids both. Your root-domain SPF for your mailbox provider stays untouched.

DKIM record

host  selector._domainkey.mg type  TXT

value generated by Mailgun

Mailgun generates the selector and the key per domain, so both come from your control panel under Domain settings → DNS records — copy the exact host and value it shows. The selector varies (mx, smtp, k1, pic and others all appear); do not assume it from another guide.

DMARC record

host  _dmarc type  TXT
v=DMARC1; p=none; rua=mailto:[email protected]

DMARC lives on your root domain and covers the whole organisation, including the mg subdomain. Start at p=none to watch who sends as you, then raise to quarantine and reject once reports show every legitimate sender aligning. Point rua at an address you read.

Tracking (optional) record

host  email.mg type  CNAME
mailgun.org

Only needed if you want open, click and unsubscribe tracking. Add it as a CNAME, never a TXT. Without it your mail still sends and authenticates, you just lose the tracking stats.

Receiving (optional) record

host  mg type  MX
mxa.mailgun.org and mxb.mailgun.org

Two MX records, both at priority 10, only needed if you want Mailgun to receive inbound mail for the subdomain. Skip these if you only send. Do not point your root-domain MX at Mailgun or you divert your normal inbox.

Step by step

The whole setup, in order.

  1. 1 Add and name your sending domain in Mailgun. In Mailgun, go to Sending → Domains → Add new domain and enter a subdomain such as mg.yourdomain.com. A subdomain keeps Mailgun's SPF and DKIM separate from your mailbox provider's records on the root.
  2. 2 Copy the records from Domain settings. Open the new domain's DNS records tab. Mailgun lists the SPF TXT, the DKIM TXT with its generated selector, and the optional tracking CNAME and MX rows. Copy each value exactly — the DKIM host and key are unique to your domain.
  3. 3 Publish them at your DNS host. At your registrar or DNS provider — not in Mailgun — add the SPF and DKIM TXT records on the mg subdomain. Add the tracking CNAME and MX rows too if you want tracking or inbound mail. Leave your root-domain SPF alone.
  4. 4 Publish DMARC on the root domain. Add the _dmarc TXT record at your root domain. Begin at p=none so you break nothing while you read the reports, and keep rua pointed somewhere you will see it.
  5. 5 Click Verify, then wait. Back in Mailgun, use Verify DNS Settings. Propagation can take up to 24 to 48 hours; Mailgun rechecks periodically, so a first failure often just means DNS has not caught up yet.
  6. 6 Confirm it landed. Once Mailgun shows the domain verified, run a full check here to confirm SPF resolves under the 10-lookup limit, the DKIM selector is found on the mg subdomain, and DMARC is graded on the root.

Where it goes wrong

The mistakes specific to Mailgun.

DKIM records live but domain unverified The records resolve but you never clicked Verify DNS Settings in Mailgun, or you clicked before propagation finished. Mailgun will not send authenticated mail until it confirms the records itself.
Guessing the DKIM selector Mailgun generates the selector per domain — mx, smtp, k1 and pic all appear in the wild. Copying a selector from a tutorial publishes DKIM at the wrong host and it never validates. Read it from your own DNS records tab.
Records on the root instead of the subdomain Mailgun authenticates mg.yourdomain.com. Publishing its SPF and DKIM on the bare root leaves the subdomain unauthenticated and can clash with your mailbox provider's SPF.
Replacing your existing SPF Mailgun's SPF belongs only on the sending subdomain. Do not overwrite the root-domain SPF that authorises your mailbox provider, and never publish two SPF records on one name.
Tracking CNAME added as TXT The email.mg record must be a CNAME pointing at mailgun.org. Adding it as a TXT breaks open and click tracking while leaving sending unaffected, which makes the fault hard to spot.
MX pointed at the wrong name The mxa and mxb.mailgun.org records go on the mg subdomain for inbound Mailgun mail. Putting them on your root domain hijacks the MX that delivers your normal inbox.

Confirm it worked

Do not trust it until you have checked it.

DNS takes a few minutes to propagate. Once it has, run a full check: it reads all three records live, counts your SPF lookups, confirms the Mailgun DKIM selector resolves, and grades your DMARC policy — the exact things that decide whether Gmail and Outlook trust your mail.

Common questions

About Mailgun, specifically.

What is the SPF record for Mailgun? v=spf1 include:mailgun.org ~all, published as a TXT record on your Mailgun sending subdomain such as mg.yourdomain.com. If a record already exists on that subdomain, merge include:mailgun.org into it rather than publishing a second SPF record.
What is the Mailgun DKIM selector? There is no single fixed selector — Mailgun generates one per domain (you will see mx, smtp, k1, pic and others). Read the exact host and value from Sending → Domain settings → DNS records in your control panel and publish that DKIM TXT on the mg subdomain.
Why is my Mailgun DKIM failing? Usually one of three things: you never clicked Verify DNS Settings, you guessed the selector instead of copying the one Mailgun generated, or you published the record on the root domain instead of the mg subdomain. Propagation can also take up to 48 hours.
Should I use a subdomain with Mailgun? Yes. Mailgun recommends a dedicated sending subdomain like mg.yourdomain.com so its SPF and DKIM stay separate from your mailbox provider's records, and so a sending-reputation issue never touches your root domain.
Do I need DMARC for Mailgun? Yes if you send in bulk to Gmail or Yahoo — both have required it since February 2024. Publish the _dmarc TXT on your root domain, start at p=none with a report address, then move to quarantine and reject once reports show every sender aligning.
Where do I add the Mailgun records — in Mailgun or at my registrar? At your DNS host: the registrar or provider that controls your domain's DNS. Mailgun generates the DKIM value and lists every record, but you publish them in your own DNS, then click Verify DNS Settings back in Mailgun.

Set it once. Know it stays set.

A DKIM key rotates, a vendor changes its SPF, an IP gets listed — and your carefully-configured domain quietly breaks. Monitoring watches all of it and tells you the day it changes.