Domains Overview
A verified domain is the foundation of high email deliverability. Connecting your custom sending domain allows you to send marketing campaigns and transactional emails under your own brand identity (e.g., newsletter@yourbrand.com or mail.yourcompany.com) rather than generic shared sender addresses.
Verified sending domain in Emalc with active DKIM, SPF, and DMARC status
Recommended Best Practice: Use a Dedicated Subdomain
For marketing campaigns and automated sequences, we strongly recommend using a dedicated subdomain like mail.yourbrand.com or send.yourbrand.com. This isolates your marketing reputation from your primary corporate email inbox (such as Google Workspace or Microsoft 365).
Why Domain Verification Matters#
Sending emails from an unauthenticated or shared domain puts your messages at severe risk of landing in spam folders or being rejected outright. Modern email providers (Google, Yahoo, Microsoft) enforce strict authentication requirements:
- Sender Reputation & Inbox Placement: Inbox providers track spam complaints, bounce rates, and engagement by domain name. By verifying your domain, you build and own your independent sender reputation.
- Mandatory 2024+ Inbox Requirements: As of 2024, Google and Yahoo require all bulk senders to have DKIM, SPF, and DMARC properly configured. Unauthenticated emails are rejected or quarantined.
- Phishing & Spoofing Protection: Cryptographic DKIM signatures ensure that malicious actors cannot forge emails claiming to be from your company.
- White-Label Deliverability: With Emalc's custom MAIL FROM configuration, emails display your domain in
mailed-byrather than a shared third-party service name.
The Authentication Stack Explained#
When you add a domain to Emalc, our platform provisions a complete set of industry-standard authentication records:
| Record Type | Protocol | What it does | Why it matters |
|---|---|---|---|
| CNAME (x3) | DKIM | Signs every outgoing email with a private cryptographic key generated specifically for your organization. | Inboxes verify that the email body and headers were not tampered with during transit. |
| TXT | SPF | Specifies which mail servers (Amazon SES) are authorized to send email on behalf of your domain. | Stops spammers from spoofing your sender address. |
| TXT | DMARC | Instructs receiving mail servers what to do if an incoming email fails SPF or DKIM checks. | Required by major email providers; protects your domain from identity theft. |
| MX + TXT | Custom MAIL FROM | Aligns the envelope sender (mail.yourdomain.com) with your brand's domain. | Removes "via amazonses.com" notices in Gmail and achieves strict alignment. |
Key Domain Capabilities in Emalc#
- Multi-Domain Support: Add up to 10 custom domains per organization, allowing you to manage different brands, products, or departments independently.
- Smart DNS Provider Detection: Emalc automatically detects your DNS provider (Cloudflare, AWS Route 53, GoDaddy, Namecheap, Porkbun, Hostinger, etc.) and gives you direct links to your DNS console.
- Email Instructions to DevOps: Don't have access to your company's DNS settings? Send the exact DNS records and setup instructions directly to your IT administrator or DevOps team with a single click.
- Granular Tracking Settings: Toggle open tracking (invisible 1x1 pixel) and click tracking per domain, or configure TLS encryption policies (Opportunistic vs Enforced).
- Real-Time Verification: Recheck DNS propagation status on demand from the dashboard without waiting for background sync intervals.
Next Steps#
Ready to connect your sending domain? Follow our step-by-step setup guide: