Create and verify a sending domain

Verified sender identities improve trust with receiving mail servers and reduce avoidable deliverability problems.

Module 2Estimated time: 8 minIncludes DNS work

Why domain verification comes early

Email campaigns perform better when mailbox providers can recognise and trust the sending identity. Domain verification is part of that trust. It proves ownership, supports signing, and helps protect the brand from weak sender configuration.

Step 1: Add the domain correctly

  • Enter the root domain that appears after the @ sign in the sender email address.
  • Use a domain that the business actually controls in DNS.
  • Check spelling carefully before saving, because one wrong character can delay the full process.

Step 2: Copy each DNS record exactly

NexaMail shows the exact record type, host, and value required for verification. These details should be copied exactly into the DNS provider panel. Small formatting mistakes often keep the status stuck on pending.

CheckPurposeWhat to remember
Identity verificationConfirms control of the domain.Usually the fastest way to prove ownership.
DKIMAdds a trusted signature to outgoing messages.Improves credibility with receiving servers.
SPFDefines which servers are allowed to send for the domain.There should only be one SPF TXT record for the domain.

Step 3: Understand propagation and re-checking

DNS changes do not appear instantly everywhere. Some records verify within minutes, while others can take much longer. Re-checking is normal. A pending state immediately after saving DNS is not automatically a problem.

Important SPF ruleIf the domain already has an SPF record, the new sending mechanism usually needs to be merged into that existing record instead of creating a second SPF entry.

What users learn from this step

  • Why authentication is part of deliverability, not just technical setup.
  • How to move between NexaMail and the DNS provider without losing accuracy.
  • Why a fully verified identity should be in place before campaigns are created.

How email domain verification protects sender reputation

Mailbox providers evaluate whether a message is genuinely connected to the domain in its From address. Authentication gives those providers evidence that NexaMail is authorised to send for your organisation. It also makes impersonation harder and creates a clearer foundation for investigating delivery problems.

Understand SPF, DKIM and DMARC

SPF lists permitted sending services. DKIM adds a cryptographic signature that receiving systems can validate. DMARC tells receivers how to handle messages that fail authentication and provides reporting. These controls work together, but each record has a different purpose and must be maintained carefully.

South African hosting environmentsYour website host and DNS provider may be different companies. Make changes wherever the domain nameservers are managed, not automatically inside the website hosting panel.

Verification quality checks

  • Confirm that the sender address uses the domain being verified.
  • Keep one valid SPF record and merge authorised services into it.
  • Copy DKIM selectors and values without adding spaces or punctuation.
  • Allow DNS propagation before repeatedly changing correct records.
  • Document who controls DNS so future updates are not delayed.

After verification succeeds, send small tests to business and consumer inboxes. Authentication supports deliverability, but relevant content, permission-based contacts and healthy engagement remain equally important.

Continue learning

Keep building your NexaMail workflow

View all lessons