> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mailofly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# DNS Setup for Mailboxes

> Configure MX, SPF, DKIM, and CNAME records to receive and send business email on your domain.

# DNS Setup for Business Mailboxes

To send and receive emails using Mailofly Business Mailboxes (`user@yourdomain.com`), your domain's DNS provider (e.g., Cloudflare, Route 53, GoDaddy, Namecheap) must be configured with four key DNS records.

***

## Required DNS Records

| Record Type | Host / Name | Priority | Value / Target | Purpose |
| - | - | - | - | - |
| **MX** | `@` (apex) | `10` | `mail.mailofly.com` | Routes all inbound email to Mailofly mail server |
| **TXT (SPF)** | `@` (apex) | — | `v=spf1 include:mailofly.com ~all` | Authorizes Mailofly servers to send on your behalf |
| **TXT (DKIM)** | `mailbox._domainkey` | — | `v=DKIM1; k=rsa; p=MIIBIj...` | Cryptographically signs outbound mailbox emails |
| **CNAME** *(Optional)* | `mail` | — | `mail.mailofly.com` | Direct access to Webmail via `mail.yourdomain.com` |

***

## 1. MX Record (Inbound Mail Routing)

The **Mail Exchanger (MX)** record directs external mail servers (like Google, Microsoft, Yahoo) to deliver messages addressed to `@yourdomain.com` to Mailofly's inbound servers.

* **Type**: `MX`
* **Name / Host**: `@` (or leave blank depending on your DNS provider)
* **Priority**: `10`
* **Value / Destination**: `mail.mailofly.com`
* **TTL**: Auto or `3600` (1 hour)

> \[!WARNING]
> An apex domain can only have **one set of primary MX records**. If your root domain currently has MX records pointing to Google Workspace (`aspmx.l.google.com`) or Microsoft 365, adding Mailofly MX records will cause delivery conflicts. If you wish to use both, host Mailofly mailboxes on a subdomain such as `team.yourdomain.com`.

***

## 2. SPF Record (Sender Policy Framework)

SPF prevents spammers from spoofing emails from your domain by listing authorized outbound IP clusters.

* **Type**: `TXT`
* **Name / Host**: `@`
* **Value**: `v=spf1 include:mailofly.com ~all`

### Combining SPF for Multiple Sending Services

RFC guidelines mandate that a domain must have **exactly one SPF TXT record**. If you already use Amazon SES for transactional API dispatch and Mailofly for business mailboxes, combine both includes into a single record:

```text theme={null}
v=spf1 include:amazonses.com include:mailofly.com ~all
```

***

## 3. DKIM Record (DomainKeys Identified Mail)

DKIM attaches a cryptographic signature to every email dispatched from your mailbox. Recipient mail servers verify this signature against your public key to guarantee the message wasn't tampered with in transit.

* **Type**: `TXT`
* **Name / Host**: `mailbox._domainkey.yourdomain.com`
* **Value**: Generated automatically in your domain settings (e.g. `v=DKIM1; k=rsa; p=MIIBIjANBgkqhki...`)

Mailofly uses 2048-bit RSA keys managed natively through Stalwart JMAP. You can retrieve your exact public key string in **Dashboard -> Domains -> Your Domain -> Mailbox Settings**.

***

## 4. Webmail CNAME Record (Optional)

If you want your employees to log into webmail using a branded URL (such as `mail.yourcompany.com`) rather than the default `mail.mailofly.com`:

* **Type**: `CNAME`
* **Name / Host**: `mail`
* **Value / Target**: `mail.mailofly.com`
* **Proxy Status**: DNS only / Disabled (if using Cloudflare)

***

## Configuring Popular DNS Providers

### Cloudflare

1. Log in to your Cloudflare Dashboard and select your domain.
2. Go to **DNS -> Records -> Add Record**.
3. Add the **MX record**:
   * Name: `@`
   * Mail server: `mail.mailofly.com`
   * Priority: `10`
   * TTL: Auto
4. Add the **TXT (SPF) record**:
   * Name: `@`
   * Content: `v=spf1 include:mailofly.com ~all`
5. Add the **TXT (DKIM) record**:
   * Name: `mailbox._domainkey`
   * Content: Copy your unique DKIM public key from Mailofly.
6. For the **CNAME record** (`mail`), ensure the proxy status is set to **DNS Only** (grey cloud), not Proxied (orange cloud).

### AWS Route 53

1. Open the Route 53 Console and go to **Hosted Zones**.
2. Click **Create Record**.
3. Select **MX**:
   * Record name: Leave blank for root.
   * Value: `10 mail.mailofly.com`
4. Create the SPF TXT record and DKIM TXT record following the table above.

### GoDaddy / Namecheap

1. Go to your domain's **DNS Management** or **Advanced DNS** tab.
2. Under **Mail Settings**, change from "Default Webmail" to **Custom MX**.
3. Enter `mail.mailofly.com` with priority `10`.
4. Save changes.

***

## Verifying DNS Records

DNS propagation typically completes within **2 to 30 minutes**, though some registrars may take up to 24 hours.

To test your configuration:

1. Go to your Mailofly Dashboard under **Domains** and click **Verify DNS**.
2. Or use Mailofly's free public diagnostics:
   * [MX & DNS Lookup Tool](https://mailofly.com/tools/dns-lookup)
   * [DKIM Verification Tool](https://mailofly.com/tools/dkim-checker)
   * [SPF Syntax Checker](https://mailofly.com/tools/spf-checker)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.