Email on a new domain: the 20-minute setup

Updated 2026-08-23

MX for receiving, SPF/DKIM/DMARC so anything you send is believed, and a free forwarding option to start. The minimum records, in order.

Receiving: MX records

MX records name the servers that accept mail for your domain. You don’t run these yourself — you point at a provider:

  • Google Workspace (paid): one record, smtp.google.com, priority 1.
  • Microsoft 365 (paid): <your-domain>.mail.protection.outlook.com.
  • Cloudflare Email Routing (free forwarding): route1/route2/route3.mx.cloudflare.net — forwards yourname@yourdomain to an inbox you already have. The usual zero-cost start.
  • Explicitly no email? Publish a null MX (a single MX with priority 0 and target “.”, RFC 7505) so senders fail fast instead of retrying for days.

Being believed: SPF, DKIM, DMARC

Receiving is one record; being trusted when you send takes three more, all TXT records your provider gives you:

  • SPF — one TXT at the root like v=spf1 include:_spf.google.com ~all, naming who may send as you. One SPF record only; multiple records break validation.
  • DKIM — a public key under a selector (e.g. google._domainkey) so receivers can verify signatures. Copy it exactly from your provider.
  • DMARC — a TXT at _dmarc telling receivers what to do when SPF/DKIM fail. Start with v=DMARC1; p=none; rua=mailto:you@… to observe, tighten to quarantine/reject once reports look clean. Major providers now expect DMARC from any domain sending real volume.

Check your work

dig MX yourdomain.com +short should show your provider; dig TXT yourdomain.com +short should show exactly one SPF record. Our free DNS checker reads the MX side and tells you which company your email depends on — worth a look if your registrar, DNS, and mail all turn out to be the same one.

Check any domain’s provider concentration in ten seconds — free, no signup.

Run the DNS checker