MX
Point mail for the domain at mail.mailservicenow.com.
On the dashboard card this row is Type MX, Name @, Priority 10, Content mail.mailservicenow.com.
| Type | Name | Priority | Content |
|---|---|---|---|
| MX | @ |
10 | mail.mailservicenow.com |
mail.mailservicenow.com the preferred MX stops that route.
Mail those hosts deliver today will not keep arriving there.
Change MX when Mail Service Now should receive the domain's mail.
Turn off Cloudflare Email Routing (or your other inbound provider) or delete its MX rows.
Verification requires every best-priority MX to be mail.mailservicenow.com.
Delete every MX row for any other provider. A row left at the same or a better priority keeps sending some of the domain's mail to that provider.
Check DNS requires every best-priority MX (the lowest priority number) to be mail.mailservicenow.com.
If Cloudflare Email Routing is still preferred, the check reports MX points at route1.mx.cloudflare.net (or whichever host is preferred).
Leave existing A records and unrelated TXT records, including _acme-challenge, in place.
Do not add an A record for the mail server on your domain. mail.mailservicenow.com already resolves.
SPF
A domain can have only one SPF record.
That is one TXT at the apex (@, the domain itself) that starts with v=spf1.
Verification rejects two SPF records and reports Publish one SPF TXT.
If an SPF record is already published, merge our ip4: into that record.
Do not add a second SPF TXT.
A new record has this shape.
<MTA_IP from your dashboard> stands in for the sending address on the domain card.
Copy the exact SPF value from that card. Do not type an address from memory, and do not copy one from this sentence.
v=spf1 ip4:<MTA_IP from your dashboard> ~all
The dashboard may show -all instead of ~all.
Publish the Content cell from the card.
This page fills the exact string from the mail DNS config (/mta-dns.json) when it can load it.
That file is the published copy of the config the dashboard and the API already use.
When the mail server moves, that config is the one place the address changes.
Exact SPF from the mail DNS config:
Copy the SPF TXT from your dashboard.
Merge into the existing record
Keep the include: mechanisms that are already there, and add the ip4: mechanism to that same TXT.
An existing record:
v=spf1 include:_spf.example.com include:example.net ~all
After the merge, still one TXT:
v=spf1 ip4:<MTA_IP from your dashboard> include:_spf.example.com include:example.net ~all
Leave other TXT records alone, including site verification and _acme-challenge.
The check looks for a pass mechanism ip4: plus the address from the dashboard (or that address with /32).
It does not follow include: chains, so the ip4: mechanism has to be on this record.
DKIM
Publish a TXT at mail._domainkey.
Copy the Content cell from the dashboard exactly.
The value starts with v=DKIM1.
This page does not include the key. Retyping it will not match.
| Type | Name | Priority | Content |
|---|---|---|---|
| TXT | mail._domainkey |
— | Copy the Content cell from the dashboard |
The full name is mail._domainkey.example-domain.com.
Some DNS panels want the name relative to the zone (mail._domainkey) and some want the full name.
Use the Name cell on the card.
A long TXT may be stored as more than one string. Check DNS joins those strings.
The p= value has to match the dashboard.
DMARC
DMARC is Recommended. Check DNS does not require it, and a missing _dmarc row does not change verification.
Start with monitoring, then tighten the policy after the reports look clean.
| Type | Name | Priority | Content |
|---|---|---|---|
| TXT | _dmarc |
— | v=DMARC1; p=none; rua=mailto:admin@example-domain.com; fo=1; adkim=r; aspf=r |
Replace example-domain.com with the domain on the card.
The dashboard builds the same value with admin@ that domain.
If a _dmarc TXT is already published, edit that row instead of adding a second one.
- Start with
p=none. Receivers still deliver mail. They send aggregate reports and do not quarantine or reject on DMARC. - After 1–2 weeks of clean aggregate reports, change
p=nonetop=quarantine. - After another clean stretch, change it to
p=reject.
rua is the address that receives aggregate reports.
Receiving servers mail summaries there: how many messages they saw, and whether SPF and DKIM passed.
Those reports are counts and results, not copies of the messages.
fo=1 asks for a failure report when either SPF or DKIM fails.
adkim=r and aspf=r use relaxed alignment, so a subdomain can align with the domain in the From header.
How to verify
Verification runs only when you add the domain, when you click Check DNS on the domain card, or when you call POST /verifyDomain.
Nothing re-checks DNS in the background.
After you publish the records, click Check DNS.
DNS propagation may take a while, so a check can fail until the nameservers return the new rows.
These lookups show the same records. Use your domain in place of example-domain.com.
# MX. The best-priority exchange must be mail.mailservicenow.com
dig MX example-domain.com
# SPF. Exactly one apex TXT that starts with v=spf1, and it includes our ip4
dig TXT example-domain.com
# DKIM. The TXT at mail._domainkey must match the dashboard
dig TXT mail._domainkey.example-domain.com
# DMARC is recommended. It is not part of the verification result
dig TXT _dmarc.example-domain.com
verified: true means the best-priority MX is mail.mailservicenow.com, exactly one SPF record includes our ip4, and the TXT at mail._domainkey.<domain> matches the mail DNS config.
DMARC is not part of that result.
Send a message to a mailbox you can open, then read the headers.
In Gmail, open the message and choose Show original.
Look for spf=pass, dkim=pass, and dmarc=pass.
A DMARC pass needs the _dmarc TXT to be published. The domain can still show as verified before that row exists.
The steps after a standard key, including addDomain and addMailbox, stay on Domain and mailboxes.
Sending address
Always set from on send_mail and POST /sendMail to an address on a verified domain you own, for example support@example-domain.com.
If it's omitted and the account has exactly one sendable hosted mailbox, that mailbox is used as a fallback; with more than one, omitting from is an error.
{
"to": "recipient@example.com",
"from": "support@example-domain.com",
"subject": "Hello",
"text": "Sent via MailServiceNow."
}