SPF · DKIM · DMARC
Set up SPF, DKIM and DMARC on Mailgun
The DNS records that make Mailgun a verified sender for your domain — publish them on your sending subdomain, click Verify, and confirm they resolve.
Before you start
What Mailgun needs from your DNS.
Mailgun is a sending platform, not your mailbox host, so it authenticates a dedicated sending subdomain — typically mg.yourdomain.com — rather than your root domain. SPF authorises Mailgun's servers to send for that subdomain, DKIM signs each message with a key Mailgun generates for you, and DMARC on your root domain ties both back to the address recipients see.
None of these records is created for you. Mailgun shows the exact values under Sending → Domain settings → DNS records the moment you add a domain, but they do nothing until you publish them at your own DNS host and click Verify. Because Mailgun generates a unique DKIM selector and key per domain, you cannot copy a DKIM value from a guide — you must read it from your own control panel.
Since February 2024, Gmail and Yahoo require anyone sending in bulk to publish SPF, DKIM and DMARC. If you already send from your root domain through a mailbox provider, keep that record intact: add Mailgun on its own subdomain and let DMARC alignment cover both.
The records to publish
Copy these into your DNS.
Add each record at your DNS provider — the company where your domain is registered, not Mailgun. Then run the checker to confirm every one resolves.
SPF record
v=spf1 include:mailgun.org ~all
Publish this on your Mailgun sending subdomain (mg.yourdomain.com), not the root. If a record already exists there, merge include:mailgun.org into it rather than adding a second SPF record, which voids both. Your root-domain SPF for your mailbox provider stays untouched.
DKIM record
value generated by Mailgun
Mailgun generates the selector and the key per domain, so both come from your control panel under Domain settings → DNS records — copy the exact host and value it shows. The selector varies (mx, smtp, k1, pic and others all appear); do not assume it from another guide.
DMARC record
v=DMARC1; p=none; rua=mailto:[email protected]
DMARC lives on your root domain and covers the whole organisation, including the mg subdomain. Start at p=none to watch who sends as you, then raise to quarantine and reject once reports show every legitimate sender aligning. Point rua at an address you read.
Tracking (optional) record
mailgun.org
Only needed if you want open, click and unsubscribe tracking. Add it as a CNAME, never a TXT. Without it your mail still sends and authenticates, you just lose the tracking stats.
Receiving (optional) record
mxa.mailgun.org and mxb.mailgun.org
Two MX records, both at priority 10, only needed if you want Mailgun to receive inbound mail for the subdomain. Skip these if you only send. Do not point your root-domain MX at Mailgun or you divert your normal inbox.
Step by step
The whole setup, in order.
- 1 Add and name your sending domain in Mailgun. In Mailgun, go to Sending → Domains → Add new domain and enter a subdomain such as mg.yourdomain.com. A subdomain keeps Mailgun's SPF and DKIM separate from your mailbox provider's records on the root.
- 2 Copy the records from Domain settings. Open the new domain's DNS records tab. Mailgun lists the SPF TXT, the DKIM TXT with its generated selector, and the optional tracking CNAME and MX rows. Copy each value exactly — the DKIM host and key are unique to your domain.
- 3 Publish them at your DNS host. At your registrar or DNS provider — not in Mailgun — add the SPF and DKIM TXT records on the mg subdomain. Add the tracking CNAME and MX rows too if you want tracking or inbound mail. Leave your root-domain SPF alone.
- 4 Publish DMARC on the root domain. Add the _dmarc TXT record at your root domain. Begin at p=none so you break nothing while you read the reports, and keep rua pointed somewhere you will see it.
- 5 Click Verify, then wait. Back in Mailgun, use Verify DNS Settings. Propagation can take up to 24 to 48 hours; Mailgun rechecks periodically, so a first failure often just means DNS has not caught up yet.
- 6 Confirm it landed. Once Mailgun shows the domain verified, run a full check here to confirm SPF resolves under the 10-lookup limit, the DKIM selector is found on the mg subdomain, and DMARC is graded on the root.
Where it goes wrong
The mistakes specific to Mailgun.
Confirm it worked
Do not trust it until you have checked it.
DNS takes a few minutes to propagate. Once it has, run a full check: it reads all three records live, counts your SPF lookups, confirms the Mailgun DKIM selector resolves, and grades your DMARC policy — the exact things that decide whether Gmail and Outlook trust your mail.
Common questions
About Mailgun, specifically.
Set it once. Know it stays set.
A DKIM key rotates, a vendor changes its SPF, an IP gets listed — and your carefully-configured domain quietly breaks. Monitoring watches all of it and tells you the day it changes.