[{"data":1,"prerenderedAt":1224},["Reactive",2],{"navigation":3,"/features/sending-domains":118,"/features/sending-domains-surround":1220},[4,14,43,83,99],{"title":5,"_path":6,"children":7},"Welcome","/welcome",[8,11],{"title":9,"_path":10},"Feature List","/welcome/feature-list",{"title":12,"_path":13},"FAQs","/welcome/faqs",{"title":15,"_path":16,"children":17},"Getting Started","/getting-started",[18,19,22,25,28,31,34,37,40],{"title":15,"_path":16},{"title":20,"_path":21},"Pre-requisites","/getting-started/prerequisites",{"title":23,"_path":24},"Installation","/getting-started/installation",{"title":26,"_path":27},"Upgrading","/getting-started/upgrading",{"title":29,"_path":30},"Configuration","/getting-started/configuration",{"title":32,"_path":33},"DNS configuration","/getting-started/dns-configuration",{"title":35,"_path":36},"Upgrading to v3","/getting-started/upgrade-to-v3",{"title":38,"_path":39},"Upgrading to v2","/getting-started/upgrade-to-v2",{"title":41,"_path":42},"The postal command","/getting-started/postal-command",{"title":44,"_path":45,"children":46},"Features","/features",[47,50,53,56,59,62,65,68,71,74,77,80],{"title":48,"_path":49},"Click & Open Tracking","/features/click-and-open-tracking",{"title":51,"_path":52},"Health & Metrics","/features/health-metrics",{"title":54,"_path":55},"IP Pools","/features/ip-pools",{"title":57,"_path":58},"Logging","/features/logging",{"title":60,"_path":61},"Mail Server Settings","/features/mail-server-settings",{"title":63,"_path":64},"OpenID Connect","/features/oidc",{"title":66,"_path":67},"Routing Incoming E-Mail","/features/routing-incoming-email",{"title":69,"_path":70},"Sending Domains","/features/sending-domains",{"title":72,"_path":73},"SMTP Authentication","/features/smtp-authentication",{"title":75,"_path":76},"SMTP TLS","/features/smtp-tls",{"title":78,"_path":79},"Spam & Virus Checking","/features/spam-and-virus-checking",{"title":81,"_path":82},"Users & Permissions","/features/users-and-permissions",{"title":84,"_path":85,"children":86},"Developer","/developer",[87,90,93,96],{"title":88,"_path":89},"Using the API","/developer/api",{"title":91,"_path":92},"Client Libraries","/developer/client-libraries",{"title":94,"_path":95},"Receiving e-mail by HTTP","/developer/http-payloads",{"title":97,"_path":98},"Webhooks","/developer/webhooks",{"title":100,"_path":101,"children":102},"Other Notes","/other",[103,106,109,112,115],{"title":104,"_path":105},"Auto-Responders & Bounces","/other/auto-responders-and-bounces",{"title":107,"_path":108},"Our container image","/other/containers",{"title":110,"_path":111},"Debugging","/other/debugging",{"title":113,"_path":114},"Wildcards & Address Tags","/other/wildcards-and-address-tags",{"title":116,"_path":117},"Workers & Background Tasks","/other/workers-and-background-tasks",{"_path":70,"_dir":119,"_draft":120,"_partial":120,"_locale":121,"title":69,"description":122,"category":44,"body":123,"_type":1215,"_id":1216,"_source":1217,"_file":1218,"_extension":1219},"features",false,"","Adding and verifying the domains you send mail from, and the DNS records Postal checks.",{"type":124,"children":125,"toc":1202},"root",[126,142,167,174,179,217,231,258,264,269,310,366,371,377,396,417,424,437,456,458,567,573,602,616,617,685,743,870,876,918,938,952,965,966,1042,1048,1075,1076,1144,1150,1196],{"type":127,"tag":128,"props":129,"children":130},"element","p",{},[131,134,140],{"type":132,"value":133},"text","Before a mail server can send mail from an address, the address's domain must be added to Postal and ",{"type":127,"tag":135,"props":136,"children":137},"strong",{},[138],{"type":132,"value":139},"verified",{"type":132,"value":141},". Postal then checks the domain's SPF, DKIM, MX and return path DNS records and shows the results in the web interface so that you can ensure your mail is delivered reliably.",{"type":127,"tag":143,"props":144,"children":146},"callout",{"icon":145},"i-heroicons-information-circle",[147],{"type":127,"tag":128,"props":148,"children":149},{},[150,152,158,160,165],{"type":132,"value":151},"This page covers the DNS records for domains ",{"type":127,"tag":153,"props":154,"children":155},"em",{},[156],{"type":132,"value":157},"you send from",{"type":132,"value":159},". The records that your Postal installation itself needs (the return path domain, SPF include, MX hostnames and so on) are described under ",{"type":127,"tag":161,"props":162,"children":163},"a",{"href":33},[164],{"type":132,"value":32},{"type":132,"value":166},".",{"type":127,"tag":168,"props":169,"children":171},"h2",{"id":170},"organization-and-server-domains",[172],{"type":132,"value":173},"Organization and server domains",{"type":127,"tag":128,"props":175,"children":176},{},[177],{"type":132,"value":178},"Domains can be added in two places:",{"type":127,"tag":180,"props":181,"children":182},"ul",{},[183,201],{"type":127,"tag":184,"props":185,"children":186},"li",{},[187,192,194,199],{"type":127,"tag":135,"props":188,"children":189},{},[190],{"type":132,"value":191},"Organization domains",{"type":132,"value":193}," (organization menu → ",{"type":127,"tag":135,"props":195,"children":196},{},[197],{"type":132,"value":198},"Domains",{"type":132,"value":200},") are available to every mail server in the organization.",{"type":127,"tag":184,"props":202,"children":203},{},[204,209,211,215],{"type":127,"tag":135,"props":205,"children":206},{},[207],{"type":132,"value":208},"Server domains",{"type":132,"value":210}," (server menu → ",{"type":127,"tag":135,"props":212,"children":213},{},[214],{"type":132,"value":198},{"type":132,"value":216},") are only available to that server.",{"type":127,"tag":128,"props":218,"children":219},{},[220,222,229],{"type":132,"value":221},"The same domain name may be added at both levels or to several servers, each with its own DKIM key and verification. When an outgoing message is authenticated, Postal looks for a verified domain matching the ",{"type":127,"tag":223,"props":224,"children":226},"code",{"className":225},[],[227],{"type":132,"value":228},"From",{"type":132,"value":230}," address's domain, preferring a server-level domain over an organization-level one.",{"type":127,"tag":128,"props":232,"children":233},{},[234,236,242,244,249,251,257],{"type":132,"value":235},"Only the exact domain is matched - to send from ",{"type":127,"tag":223,"props":237,"children":239},{"className":238},[],[240],{"type":132,"value":241},"news.yourdomain.com",{"type":132,"value":243}," you need to add ",{"type":127,"tag":223,"props":245,"children":247},{"className":246},[],[248],{"type":132,"value":241},{"type":132,"value":250}," as well as ",{"type":127,"tag":223,"props":252,"children":254},{"className":253},[],[255],{"type":132,"value":256},"yourdomain.com",{"type":132,"value":166},{"type":127,"tag":168,"props":259,"children":261},{"id":260},"verifying-a-domain",[262],{"type":132,"value":263},"Verifying a domain",{"type":127,"tag":128,"props":265,"children":266},{},[267],{"type":132,"value":268},"When you add a domain you must prove that you control it. Global administrators skip this step and their domains are verified immediately. Other users choose one of two methods:",{"type":127,"tag":128,"props":270,"children":271},{},[272,277,279,285,287,293,295,301,303,308],{"type":127,"tag":135,"props":273,"children":274},{},[275],{"type":132,"value":276},"DNS",{"type":132,"value":278}," - add a TXT record at the domain itself (the apex, ",{"type":127,"tag":223,"props":280,"children":282},{"className":281},[],[283],{"type":132,"value":284},"@",{"type":132,"value":286},") with the value shown, which is ",{"type":127,"tag":223,"props":288,"children":290},{"className":289},[],[291],{"type":132,"value":292},"postal-verification {token}",{"type":132,"value":294}," (the prefix is set by ",{"type":127,"tag":223,"props":296,"children":298},{"className":297},[],[299],{"type":132,"value":300},"dns.domain_verify_prefix",{"type":132,"value":302},"). Then click ",{"type":127,"tag":135,"props":304,"children":305},{},[306],{"type":132,"value":307},"Verify TXT record",{"type":132,"value":309},". The token is a 32 character random string.",{"type":127,"tag":128,"props":311,"children":312},{},[313,318,320,326,328,334,335,341,342,348,350,356,358,364],{"type":127,"tag":135,"props":314,"children":315},{},[316],{"type":132,"value":317},"E-Mail",{"type":132,"value":319}," - Postal sends a 6 digit code to one of ",{"type":127,"tag":223,"props":321,"children":323},{"className":322},[],[324],{"type":132,"value":325},"webmaster@",{"type":132,"value":327},", ",{"type":127,"tag":223,"props":329,"children":331},{"className":330},[],[332],{"type":132,"value":333},"postmaster@",{"type":132,"value":327},{"type":127,"tag":223,"props":336,"children":338},{"className":337},[],[339],{"type":132,"value":340},"admin@",{"type":132,"value":327},{"type":127,"tag":223,"props":343,"children":345},{"className":344},[],[346],{"type":132,"value":347},"administrator@",{"type":132,"value":349}," or ",{"type":127,"tag":223,"props":351,"children":353},{"className":352},[],[354],{"type":132,"value":355},"hostmaster@",{"type":132,"value":357}," at the domain (or any of its parent domains). Enter the code to complete verification. This requires the ",{"type":127,"tag":223,"props":359,"children":361},{"className":360},[],[362],{"type":132,"value":363},"smtp",{"type":132,"value":365}," section of Postal's configuration to be working.",{"type":127,"tag":128,"props":367,"children":368},{},[369],{"type":132,"value":370},"Until a domain is verified it cannot be used: messages from addresses on it are rejected at submission, and it is not offered when creating routes or tracking domains.",{"type":127,"tag":168,"props":372,"children":374},{"id":373},"dns-checks",[375],{"type":132,"value":376},"DNS checks",{"type":127,"tag":128,"props":378,"children":379},{},[380,382,387,389,394],{"type":132,"value":381},"Once verified, open the domain (the ",{"type":127,"tag":135,"props":383,"children":384},{},[385],{"type":132,"value":386},"DNS Setup",{"type":132,"value":388}," page) to see the records you need to add. Postal checks these records immediately when you press ",{"type":127,"tag":135,"props":390,"children":391},{},[392],{"type":132,"value":393},"Check my records are correct",{"type":132,"value":395},", and re-checks every domain automatically once an hour. The results are shown as ticks and crosses in the domain list.",{"type":127,"tag":128,"props":397,"children":398},{},[399,401,407,409,415],{"type":132,"value":400},"By default Postal queries the domain's own authoritative nameservers so that changes are seen without waiting for caches to expire. Set ",{"type":127,"tag":223,"props":402,"children":404},{"className":403},[],[405],{"type":132,"value":406},"postal.use_local_ns_for_domain_verification: true",{"type":132,"value":408}," to use the resolvers from ",{"type":127,"tag":223,"props":410,"children":412},{"className":411},[],[413],{"type":132,"value":414},"dns.resolv_conf_path",{"type":132,"value":416}," instead.",{"type":127,"tag":418,"props":419,"children":421},"h3",{"id":420},"spf",[422],{"type":132,"value":423},"SPF",{"type":127,"tag":128,"props":425,"children":426},{},[427,429,435],{"type":132,"value":428},"A TXT record at the apex of the domain beginning ",{"type":127,"tag":223,"props":430,"children":432},{"className":431},[],[433],{"type":132,"value":434},"v=spf1",{"type":132,"value":436}," which includes your installation's SPF include, e.g.",{"type":127,"tag":438,"props":439,"children":442},"pre",{"className":440,"code":441,"language":132,"meta":121,"style":121},"language-text shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","v=spf1 a mx include:spf.postal.example.com ~all\n",[443],{"type":127,"tag":223,"props":444,"children":445},{"__ignoreMap":121},[446],{"type":127,"tag":447,"props":448,"children":451},"span",{"class":449,"line":450},"line",1,[452],{"type":127,"tag":447,"props":453,"children":454},{},[455],{"type":132,"value":441},{"type":132,"value":457},"\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n",{"type":127,"tag":459,"props":460,"children":461},"table",{},[462,481],{"type":127,"tag":463,"props":464,"children":465},"thead",{},[466],{"type":127,"tag":467,"props":468,"children":469},"tr",{},[470,476],{"type":127,"tag":471,"props":472,"children":473},"th",{},[474],{"type":132,"value":475},"Status",{"type":127,"tag":471,"props":477,"children":478},{},[479],{"type":132,"value":480},"Meaning",{"type":127,"tag":482,"props":483,"children":484},"tbody",{},[485,518,542],{"type":127,"tag":467,"props":486,"children":487},{},[488,498],{"type":127,"tag":489,"props":490,"children":491},"td",{},[492],{"type":127,"tag":223,"props":493,"children":495},{"className":494},[],[496],{"type":132,"value":497},"OK",{"type":127,"tag":489,"props":499,"children":500},{},[501,503,508,510,516],{"type":132,"value":502},"A ",{"type":127,"tag":223,"props":504,"children":506},{"className":505},[],[507],{"type":132,"value":434},{"type":132,"value":509}," record containing ",{"type":127,"tag":223,"props":511,"children":513},{"className":512},[],[514],{"type":132,"value":515},"include:{dns.spf_include}",{"type":132,"value":517}," was found.",{"type":127,"tag":467,"props":519,"children":520},{},[521,530],{"type":127,"tag":489,"props":522,"children":523},{},[524],{"type":127,"tag":223,"props":525,"children":527},{"className":526},[],[528],{"type":132,"value":529},"Missing",{"type":127,"tag":489,"props":531,"children":532},{},[533,535,540],{"type":132,"value":534},"No ",{"type":127,"tag":223,"props":536,"children":538},{"className":537},[],[539],{"type":132,"value":434},{"type":132,"value":541}," record exists.",{"type":127,"tag":467,"props":543,"children":544},{},[545,554],{"type":127,"tag":489,"props":546,"children":547},{},[548],{"type":127,"tag":223,"props":549,"children":551},{"className":550},[],[552],{"type":132,"value":553},"Invalid",{"type":127,"tag":489,"props":555,"children":556},{},[557,559,565],{"type":132,"value":558},"An SPF record exists but does not include your Postal SPF include. If you already have an SPF record for another service, add ",{"type":127,"tag":223,"props":560,"children":562},{"className":561},[],[563],{"type":132,"value":564},"include:spf.postal.example.com",{"type":132,"value":566}," to it rather than creating a second record.",{"type":127,"tag":418,"props":568,"children":570},{"id":569},"dkim",[571],{"type":132,"value":572},"DKIM",{"type":127,"tag":128,"props":574,"children":575},{},[576,578,584,586,592,594,600],{"type":132,"value":577},"Postal generates a 1024-bit RSA key pair for each domain when it is added. Publish the public key in a TXT record named ",{"type":127,"tag":223,"props":579,"children":581},{"className":580},[],[582],{"type":132,"value":583},"{selector}._domainkey.yourdomain.com",{"type":132,"value":585},", where the selector is ",{"type":127,"tag":223,"props":587,"children":589},{"className":588},[],[590],{"type":132,"value":591},"{dns.dkim_identifier}-{6 random letters}",{"type":132,"value":593}," (for example ",{"type":127,"tag":223,"props":595,"children":597},{"className":596},[],[598],{"type":132,"value":599},"postal-KJHDSA._domainkey",{"type":132,"value":601},"). The exact name and value are shown on the DNS Setup page and look like:",{"type":127,"tag":438,"props":603,"children":605},{"className":440,"code":604,"language":132,"meta":121,"style":121},"v=DKIM1; t=s; h=sha256; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQ...;\n",[606],{"type":127,"tag":223,"props":607,"children":608},{"__ignoreMap":121},[609],{"type":127,"tag":447,"props":610,"children":611},{"class":449,"line":450},[612],{"type":127,"tag":447,"props":613,"children":614},{},[615],{"type":132,"value":604},{"type":132,"value":457},{"type":127,"tag":459,"props":618,"children":619},{},[620,634],{"type":127,"tag":463,"props":621,"children":622},{},[623],{"type":127,"tag":467,"props":624,"children":625},{},[626,630],{"type":127,"tag":471,"props":627,"children":628},{},[629],{"type":132,"value":475},{"type":127,"tag":471,"props":631,"children":632},{},[633],{"type":132,"value":480},{"type":127,"tag":482,"props":635,"children":636},{},[637,653,669],{"type":127,"tag":467,"props":638,"children":639},{},[640,648],{"type":127,"tag":489,"props":641,"children":642},{},[643],{"type":127,"tag":223,"props":644,"children":646},{"className":645},[],[647],{"type":132,"value":497},{"type":127,"tag":489,"props":649,"children":650},{},[651],{"type":132,"value":652},"Exactly one TXT record exists and its value matches.",{"type":127,"tag":467,"props":654,"children":655},{},[656,664],{"type":127,"tag":489,"props":657,"children":658},{},[659],{"type":127,"tag":223,"props":660,"children":662},{"className":661},[],[663],{"type":132,"value":529},{"type":127,"tag":489,"props":665,"children":666},{},[667],{"type":132,"value":668},"No TXT record was returned for the name.",{"type":127,"tag":467,"props":670,"children":671},{},[672,680],{"type":127,"tag":489,"props":673,"children":674},{},[675],{"type":127,"tag":223,"props":676,"children":678},{"className":677},[],[679],{"type":132,"value":553},{"type":127,"tag":489,"props":681,"children":682},{},[683],{"type":132,"value":684},"Either more than one TXT record exists at the name, or the value does not match the one provided. Check it has been copied exactly.",{"type":127,"tag":128,"props":686,"children":687},{},[688,690,695,697,703,705,710,712,718,720,726,728,734,736,741],{"type":132,"value":689},"Outgoing messages from a domain whose DKIM status is ",{"type":127,"tag":223,"props":691,"children":693},{"className":692},[],[694],{"type":132,"value":497},{"type":132,"value":696}," are signed with the domain's key (",{"type":127,"tag":223,"props":698,"children":700},{"className":699},[],[701],{"type":132,"value":702},"d=yourdomain.com",{"type":132,"value":704},"). If the DKIM record is not ",{"type":127,"tag":223,"props":706,"children":708},{"className":707},[],[709],{"type":132,"value":497},{"type":132,"value":711},", messages are still sent but are signed with the installation's key using ",{"type":127,"tag":223,"props":713,"children":715},{"className":714},[],[716],{"type":132,"value":717},"d={dns.return_path_domain}",{"type":132,"value":719}," instead - which is why you must also publish the record from ",{"type":127,"tag":223,"props":721,"children":723},{"className":722},[],[724],{"type":132,"value":725},"postal default-dkim-record",{"type":132,"value":727}," at ",{"type":127,"tag":223,"props":729,"children":731},{"className":730},[],[732],{"type":132,"value":733},"postal._domainkey.{return path domain}",{"type":132,"value":735}," (see ",{"type":127,"tag":161,"props":737,"children":739},{"href":738},"/getting-started/dns-configuration#return-path",[740],{"type":132,"value":32},{"type":132,"value":742},").",{"type":127,"tag":128,"props":744,"children":745},{},[746,748,754,756,761,762,768,769,775,776,782,783,789,790,796,797,803,804,810,811,817,818,824,825,831,832,838,839,845,846,852,854,860,862,868],{"type":132,"value":747},"Signatures use ",{"type":127,"tag":223,"props":749,"children":751},{"className":750},[],[752],{"type":132,"value":753},"rsa-sha256",{"type":132,"value":755}," with relaxed canonicalisation and cover the ",{"type":127,"tag":223,"props":757,"children":759},{"className":758},[],[760],{"type":132,"value":228},{"type":132,"value":327},{"type":127,"tag":223,"props":763,"children":765},{"className":764},[],[766],{"type":132,"value":767},"Sender",{"type":132,"value":327},{"type":127,"tag":223,"props":770,"children":772},{"className":771},[],[773],{"type":132,"value":774},"Reply-To",{"type":132,"value":327},{"type":127,"tag":223,"props":777,"children":779},{"className":778},[],[780],{"type":132,"value":781},"Subject",{"type":132,"value":327},{"type":127,"tag":223,"props":784,"children":786},{"className":785},[],[787],{"type":132,"value":788},"Date",{"type":132,"value":327},{"type":127,"tag":223,"props":791,"children":793},{"className":792},[],[794],{"type":132,"value":795},"Message-ID",{"type":132,"value":327},{"type":127,"tag":223,"props":798,"children":800},{"className":799},[],[801],{"type":132,"value":802},"To",{"type":132,"value":327},{"type":127,"tag":223,"props":805,"children":807},{"className":806},[],[808],{"type":132,"value":809},"Cc",{"type":132,"value":327},{"type":127,"tag":223,"props":812,"children":814},{"className":813},[],[815],{"type":132,"value":816},"MIME-Version",{"type":132,"value":327},{"type":127,"tag":223,"props":819,"children":821},{"className":820},[],[822],{"type":132,"value":823},"Content-Type",{"type":132,"value":327},{"type":127,"tag":223,"props":826,"children":828},{"className":827},[],[829],{"type":132,"value":830},"Content-Transfer-Encoding",{"type":132,"value":327},{"type":127,"tag":223,"props":833,"children":835},{"className":834},[],[836],{"type":132,"value":837},"Resent-*",{"type":132,"value":327},{"type":127,"tag":223,"props":840,"children":842},{"className":841},[],[843],{"type":132,"value":844},"In-Reply-To",{"type":132,"value":327},{"type":127,"tag":223,"props":847,"children":849},{"className":848},[],[850],{"type":132,"value":851},"References",{"type":132,"value":853}," and ",{"type":127,"tag":223,"props":855,"children":857},{"className":856},[],[858],{"type":132,"value":859},"List-*",{"type":132,"value":861}," (including ",{"type":127,"tag":223,"props":863,"children":865},{"className":864},[],[866],{"type":132,"value":867},"List-Unsubscribe-Post",{"type":132,"value":869},") headers where present.",{"type":127,"tag":418,"props":871,"children":873},{"id":872},"return-path",[874],{"type":132,"value":875},"Return path",{"type":127,"tag":128,"props":877,"children":878},{},[879,881,886,888,894,896,902,904,909,911,916],{"type":132,"value":880},"The ",{"type":127,"tag":135,"props":882,"children":883},{},[884],{"type":132,"value":885},"return path",{"type":132,"value":887}," is the SMTP envelope sender (",{"type":127,"tag":223,"props":889,"children":891},{"className":890},[],[892],{"type":132,"value":893},"MAIL FROM",{"type":132,"value":895},") used for outgoing mail, and it is where bounces are sent. By default it is ",{"type":127,"tag":223,"props":897,"children":899},{"className":898},[],[900],{"type":132,"value":901},"{server token}@{dns.return_path_domain}",{"type":132,"value":903},", a hostname belonging to your Postal installation. This is fine, but because the envelope domain differs from your ",{"type":127,"tag":223,"props":905,"children":907},{"className":906},[],[908],{"type":132,"value":228},{"type":132,"value":910}," domain it will not give SPF ",{"type":127,"tag":135,"props":912,"children":913},{},[914],{"type":132,"value":915},"alignment",{"type":132,"value":917}," for DMARC.",{"type":127,"tag":128,"props":919,"children":920},{},[921,923,929,930,936],{"type":132,"value":922},"To fix this, add a CNAME record at ",{"type":127,"tag":223,"props":924,"children":926},{"className":925},[],[927],{"type":132,"value":928},"psrp.yourdomain.com",{"type":132,"value":294},{"type":127,"tag":223,"props":931,"children":933},{"className":932},[],[934],{"type":132,"value":935},"dns.custom_return_path_prefix",{"type":132,"value":937},") pointing to your installation's return path domain, e.g.",{"type":127,"tag":438,"props":939,"children":941},{"className":440,"code":940,"language":132,"meta":121,"style":121},"psrp.yourdomain.com.  CNAME  rp.postal.example.com.\n",[942],{"type":127,"tag":223,"props":943,"children":944},{"__ignoreMap":121},[945],{"type":127,"tag":447,"props":946,"children":947},{"class":449,"line":450},[948],{"type":127,"tag":447,"props":949,"children":950},{},[951],{"type":132,"value":940},{"type":127,"tag":128,"props":953,"children":954},{},[955,957,963],{"type":132,"value":956},"Once the check passes, Postal uses ",{"type":127,"tag":223,"props":958,"children":960},{"className":959},[],[961],{"type":132,"value":962},"{server token}@psrp.yourdomain.com",{"type":132,"value":964}," as the envelope sender for mail from this domain. Because it is a CNAME, the SPF and DKIM records you published for the return path domain during installation apply automatically, and Postal's SMTP server accepts bounces for any domain beginning with the custom return path prefix.",{"type":132,"value":457},{"type":127,"tag":459,"props":967,"children":968},{},[969,983],{"type":127,"tag":463,"props":970,"children":971},{},[972],{"type":127,"tag":467,"props":973,"children":974},{},[975,979],{"type":127,"tag":471,"props":976,"children":977},{},[978],{"type":132,"value":475},{"type":127,"tag":471,"props":980,"children":981},{},[982],{"type":132,"value":480},{"type":127,"tag":482,"props":984,"children":985},{},[986,1010,1026],{"type":127,"tag":467,"props":987,"children":988},{},[989,997],{"type":127,"tag":489,"props":990,"children":991},{},[992],{"type":127,"tag":223,"props":993,"children":995},{"className":994},[],[996],{"type":132,"value":497},{"type":127,"tag":489,"props":998,"children":999},{},[1000,1002,1008],{"type":132,"value":1001},"A single CNAME pointing at ",{"type":127,"tag":223,"props":1003,"children":1005},{"className":1004},[],[1006],{"type":132,"value":1007},"{dns.return_path_domain}",{"type":132,"value":1009}," was found. Postal will use the custom return path.",{"type":127,"tag":467,"props":1011,"children":1012},{},[1013,1021],{"type":127,"tag":489,"props":1014,"children":1015},{},[1016],{"type":127,"tag":223,"props":1017,"children":1019},{"className":1018},[],[1020],{"type":132,"value":529},{"type":127,"tag":489,"props":1022,"children":1023},{},[1024],{"type":132,"value":1025},"No record exists. Postal uses the default return path. This is acceptable but not recommended.",{"type":127,"tag":467,"props":1027,"children":1028},{},[1029,1037],{"type":127,"tag":489,"props":1030,"children":1031},{},[1032],{"type":127,"tag":223,"props":1033,"children":1035},{"className":1034},[],[1036],{"type":132,"value":553},{"type":127,"tag":489,"props":1038,"children":1039},{},[1040],{"type":132,"value":1041},"A record exists but does not point at the right hostname.",{"type":127,"tag":418,"props":1043,"children":1045},{"id":1044},"mx",[1046],{"type":132,"value":1047},"MX",{"type":127,"tag":128,"props":1049,"children":1050},{},[1051,1053,1058,1060,1065,1067,1073],{"type":132,"value":1052},"MX records are only needed if you want to ",{"type":127,"tag":135,"props":1054,"children":1055},{},[1056],{"type":132,"value":1057},"receive",{"type":132,"value":1059}," mail for the domain through Postal (see ",{"type":127,"tag":161,"props":1061,"children":1062},{"href":67},[1063],{"type":132,"value":1064},"Routing incoming e-mail",{"type":132,"value":1066},"). Postal checks that every hostname listed in ",{"type":127,"tag":223,"props":1068,"children":1070},{"className":1069},[],[1071],{"type":132,"value":1072},"dns.mx_records",{"type":132,"value":1074}," appears among the domain's MX records (case-insensitively).",{"type":132,"value":457},{"type":127,"tag":459,"props":1077,"children":1078},{},[1079,1093],{"type":127,"tag":463,"props":1080,"children":1081},{},[1082],{"type":127,"tag":467,"props":1083,"children":1084},{},[1085,1089],{"type":127,"tag":471,"props":1086,"children":1087},{},[1088],{"type":132,"value":475},{"type":127,"tag":471,"props":1090,"children":1091},{},[1092],{"type":132,"value":480},{"type":127,"tag":482,"props":1094,"children":1095},{},[1096,1112,1128],{"type":127,"tag":467,"props":1097,"children":1098},{},[1099,1107],{"type":127,"tag":489,"props":1100,"children":1101},{},[1102],{"type":127,"tag":223,"props":1103,"children":1105},{"className":1104},[],[1106],{"type":132,"value":497},{"type":127,"tag":489,"props":1108,"children":1109},{},[1110],{"type":132,"value":1111},"All of your Postal MX hostnames are present.",{"type":127,"tag":467,"props":1113,"children":1114},{},[1115,1123],{"type":127,"tag":489,"props":1116,"children":1117},{},[1118],{"type":127,"tag":223,"props":1119,"children":1121},{"className":1120},[],[1122],{"type":132,"value":529},{"type":127,"tag":489,"props":1124,"children":1125},{},[1126],{"type":132,"value":1127},"None are present. Incoming mail will not reach Postal, which is fine if you only send.",{"type":127,"tag":467,"props":1129,"children":1130},{},[1131,1139],{"type":127,"tag":489,"props":1132,"children":1133},{},[1134],{"type":127,"tag":223,"props":1135,"children":1137},{"className":1136},[],[1138],{"type":132,"value":553},{"type":127,"tag":489,"props":1140,"children":1141},{},[1142],{"type":132,"value":1143},"Some but not all are present.",{"type":127,"tag":418,"props":1145,"children":1147},{"id":1146},"overall-status-and-notifications",[1148],{"type":132,"value":1149},"Overall status and notifications",{"type":127,"tag":128,"props":1151,"children":1152},{},[1153,1155,1160,1162,1167,1168,1173,1175,1180,1182,1194],{"type":132,"value":1154},"A domain is considered fully configured when SPF and DKIM are ",{"type":127,"tag":223,"props":1156,"children":1158},{"className":1157},[],[1159],{"type":132,"value":497},{"type":132,"value":1161}," and both MX and Return Path are either ",{"type":127,"tag":223,"props":1163,"children":1165},{"className":1164},[],[1166],{"type":132,"value":497},{"type":132,"value":349},{"type":127,"tag":223,"props":1169,"children":1171},{"className":1170},[],[1172],{"type":132,"value":529},{"type":132,"value":1174},". If an automatic hourly check finds a ",{"type":127,"tag":135,"props":1176,"children":1177},{},[1178],{"type":132,"value":1179},"server-level",{"type":132,"value":1181}," domain in any other state, a ",{"type":127,"tag":161,"props":1183,"children":1185},{"href":1184},"/developer/webhooks#dns-error-event",[1186,1192],{"type":127,"tag":223,"props":1187,"children":1189},{"className":1188},[],[1190],{"type":132,"value":1191},"DomainDNSError",{"type":132,"value":1193}," webhook",{"type":132,"value":1195}," is triggered. Domains with problems are also highlighted at the top of the server's pages.",{"type":127,"tag":1197,"props":1198,"children":1199},"style",{},[1200],{"type":132,"value":1201},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":121,"searchDepth":1203,"depth":1203,"links":1204},2,[1205,1206,1207],{"id":170,"depth":1203,"text":173},{"id":260,"depth":1203,"text":263},{"id":373,"depth":1203,"text":376,"children":1208},[1209,1211,1212,1213,1214],{"id":420,"depth":1210,"text":423},3,{"id":569,"depth":1210,"text":572},{"id":872,"depth":1210,"text":875},{"id":1044,"depth":1210,"text":1047},{"id":1146,"depth":1210,"text":1149},"markdown","content:3.features:sending-domains.md","content","3.features/sending-domains.md","md",[1221,1223],{"_path":67,"title":66,"description":1222},"Routes, endpoints and what happens to mail that arrives at your Postal server.",{"_path":73,"title":72,"description":121},1789749433527]