Why domain verification matters
Email providers — Gmail, Outlook, Yahoo, and others — check every inbound message against the sender domain's DNS records. If your domain doesn't publish records that authorize Yaplet to send on your behalf, receiving servers treat your message as suspicious: your campaigns land in spam folders, or are rejected before they reach the inbox.
Newsletter campaigns can only be sent from an address on a verified custom domain. Until a domain is verified, none of its addresses appear in the sender dropdown, so there is nothing to send from. Verifying your domain is the foundation of every email you send — and the good news is that the setup page now checks your DNS for you, so you're never guessing whether a record went live.
What SPF and DKIM do
- SPF (Sender Policy Framework) — a DNS TXT record listing which mail servers may send email from your domain. Receiving servers check that Yaplet's infrastructure is on that list before accepting your message.
- DKIM (DomainKeys Identified Mail) — DNS CNAME records pointing to public cryptographic keys hosted by Amazon SES (Yaplet's email infrastructure). Yaplet signs every outgoing email; receiving servers verify the signature. DKIM is the record that actually verifies your domain for sending.
Most major providers also check DMARC, which builds on SPF and DKIM — passing both satisfies the most common DMARC policies. Yaplet generates a default DMARC record for you to add — recommended, and if you already have your own DMARC record, it counts and you keep yours.
Step 1 — Add your domain
- Go to Settings → Organization settings → Emailing → Custom Domains.
- Click Add domain.
- Enter your sending domain (e.g.
yourdomain.com— just the domain, nohttps://orwww.). Use a subdomain likemail.yourdomain.comonly if you specifically want to send from one. - Click Add.
Yaplet generates your DNS records, requests an SSL certificate for link tracking, and opens the Setup tab. There's no "Need warmup" toggle anymore — sending speed is managed automatically (see How warmup and deliverability work now, below).
Step 2 — Add the DNS records
The Setup page organizes records into groups by what they do — Sending, Receiving and Secure links — plus a separate Branded link tracking card below them. Every record carries a Required or Optional badge with a short note on why, its copy box lists every field your DNS provider's form asks for (Type, Host, Value, TTL, and Priority for MX records), and a live status badge shows where it stands: Verified (green — found, value matches), Failed (red — a genuinely conflicting value is set), Not detected (grey — not in DNS yet), or Don't add (amber — it conflicts with your existing email setup; see the conflict notes below). Add the records at your DNS provider (Cloudflare, GoDaddy, Namecheap, Route 53, your host's control panel) — the page re-checks automatically every 20 seconds, so you don't have to refresh.
Sending — only the three DKIM records are required
The records that authenticate your mail. Only the three DKIM CNAMEs are required — they alone verify the domain. The rest are optional but recommended: the SPF TXT (Amazon's own sender address already passes SPF checks, so this just adds extra trust), the DMARC TXT (Gmail and Yahoo expect one from bulk senders — your own existing DMARC counts), and the two MAIL FROM records (put your own subdomain on the technical sender address; without them Amazon's fallback works fine).
| Type | Name (host) | Value | Priority |
|---|---|---|---|
| CNAME (×3) | {token}._domainkey.yourdomain.com | {token}.dkim.amazonses.com | — |
| TXT | yourdomain.com | v=spf1 include:amazonses.com ~all | — |
| TXT | _dmarc.yourdomain.com | v=DMARC1; p=none | — |
| MX | mail.yourdomain.com | feedback-smtp.eu-central-1.amazonses.com | 10 |
| TXT | mail.yourdomain.com | v=spf1 include:amazonses.com ~all | — |
The three DKIM CNAMEs use opaque per-domain tokens (something like o7s2vrwryrpqfwhg6sml5myuwhwgmodi) — always copy the exact names and values from your dashboard.
Receiving — optional
Add this single inbound MX record only if you want incoming email for your domain (like customer replies) to land in your Yaplet inbox. Skip it if you only need to send — for example, newsletters. Don't add it if your domain already runs on Google Workspace or Microsoft 365, or it will reroute your existing mail. Only the addresses you added under Emailing get their mail into Yaplet — mail to any other address on the domain is dropped, and its sender gets no bounce.
| Type | Name (host) | Value | Priority |
|---|---|---|---|
| MX | yourdomain.com | inbound-smtp.eu-central-1.amazonaws.com | 10 |
Secure links — optional, recommended
These let Amazon issue an SSL certificate so your campaign's tracking links can be branded. They work in parallel with sending, so add them at the same time. The link. record only appears once the certificate is issued.
| Type | Name (host) | Value |
|---|---|---|
| CNAME | (ACM validation — shown in your dashboard) | (shown in your dashboard) |
| CNAME | link.yourdomain.com (after cert issued) | (CloudFront target — shown in your dashboard) |
One more optional record inside Sending: Gmail monitoring
Gmail is the one major provider that never tells senders when someone marks their mail as spam. This single TXT record connects your domain to Google's own reporting, so Yaplet can watch your Gmail spam rate and protect the domain before trouble escalates. It is listed inside the Sending group above, badged Optional. Sending works without it — but with it, the Deliverability tab gains a Google-reported Gmail spam rate. Keep the record in your DNS permanently; Google re-checks it from time to time.
| Type | Name (host) | Value |
|---|---|---|
| TXT | yourdomain.com | google-site-verification=… (shown in your dashboard) |
Already have email on this domain? Yaplet scans your existing DNS for conflicts and marks each affected record with a note and an amber Don't add badge — the record is faded out with its copy buttons disabled so it can't be added by accident. Four conflicts are detected: an existing SPF record (only one
v=spf1is allowed — mergeinclude:amazonses.cominto yours, e.g. changev=spf1 include:_spf.google.com ~alltov=spf1 include:_spf.google.com include:amazonses.com ~all); amail.subdomain already used by your mail provider (skip both MAIL FROM records — sending works without them); your own DMARC record (keep yours — it counts as Verified); and existing MX records at the root (skip the Receiving record unless you really want your mail rerouted to Yaplet).
On Cloudflare, set every CNAME (the DKIM records and the link-tracking record) to DNS only — the grey cloud, not the orange one. A proxied CNAME breaks DKIM and SSL validation. Yaplet detects Cloudflare and shows this reminder directly on each CNAME row until the record is found.
CAA records are handled for you. If your domain has a CAA record that blocks Amazon from issuing the link-tracking certificate, Yaplet shows a warning and adds the exact record you need: a CAA record on
yourdomain.comwith value0 issue "amazon.com". If you have no CAA record at all, you don't need one — it only affects link tracking, not sending.
Prefer a bulk import? Click Export records at the top of the Setup page to download every record as one zone file, then import it in a single step. If Yaplet detects that your DNS is on Cloudflare you can choose a Cloudflare-tuned file (CNAMEs pre-set to "DNS only"); everywhere else you get the portable BIND file. Records that conflict with your existing setup (a second SPF, the occupied
mail.records, a second DMARC) are left commented out in the file, so the import can't add them. This only works at providers that accept a zone file (Cloudflare, or any BIND-based host); registrars like GoDaddy and Namecheap can't import files, so there you add the records with the copy buttons instead.
Step 3 — Yaplet verifies for you
There's no manual "Verify" button anymore. After you add the records, Yaplet checks DNS automatically — every 20 seconds, and again whenever you return to the tab. A Re-check status button forces an immediate check — you'll find it right inside the status banner while verification is pending. A single badge tracks where you stand:
| Badge | What it means |
|---|---|
| DNS records needed | The three DKIM records — the only required ones — aren't all in your DNS yet. Add them. |
| Verifying — almost there | The three DKIM records are detected (skipped optional records don't hold this up); AWS is verifying — usually 5–60 minutes. |
| Verified for sending | Done. You can send from this domain. |
You can close the page and come back — it re-checks when you return, so there's nothing to sit and wait for. Stuck? Click Ask AI for help: Yaplet's assistant reads your live DNS and tells you exactly which records are still missing and where to add them.
Added your records late? Amazon only searches your DNS for the DKIM records for 72 hours after the domain is added. If you set them up later than that, verification used to stay failed forever — now, pressing Re-check status (or simply opening the Setup page) automatically restarts the search with the same records. Nothing needs to be re-added; verification then completes within minutes to a few hours.
Optional records never block verification. A domain verifies on its three DKIM records alone. If optional records are still missing on a verified domain, Re-check shows a gentle warning — "Verified — optional records not added" — and that's all: sending keeps working, and the remaining records only improve deliverability or unlock extra features.
Turn on branded link tracking
Link tracking rewrites the links in your emails through a link.yourdomain.com subdomain so Yaplet can measure clicks. It has its own switch on the Setup page:
- The switch is locked until your SSL certificate is issued — add the Secure-links records first.
- Once the certificate is issued, the
link.record appears. You can flip the switch on even before that record propagates: tracking stays pending and turns on by itself once the record resolves. Until then your links are sent untouched, so nothing breaks. - Turning it off reverts to plain, untracked links.
Add a verified sender address
A verified domain alone doesn't let you send — you need at least one sender address on it.
- On the verified domain, open the Emails tab and click Add email.
- Enter the local part (e.g.
hellogives[email protected]). - Pick the chat widget the address is linked to. This is required — the form won't save without one. Replies to campaigns sent from this address land in that chat widget's inbox. A chat widget belongs to a brand, and each brand has exactly one, so this choice decides which brand's inbox the replies land in; teammates with restricted access see them only if that brand is granted to them under Brand access on the Organization page.
- Click Add. The address is available in campaigns and email automations immediately.
Add as many sender addresses as your team needs — there is a generous per-account ceiling to prevent abuse, and it can be raised on request. For team setups, see Set up multiple senders on one domain.
How warmup and deliverability work now
Warmup is fully automatic — there are no limits to set by hand. When you send from a new domain, inbox providers are cautious because it has no history. Yaplet handles this for you: it ramps your sending volume up gradually, increasing speed for each email provider (Gmail, Apple, Microsoft, and the rest) as long as your bounce and complaint rates stay healthy, and pulling back automatically if they climb.
There's nothing to configure and nothing to "finish" — the only thing you control is your list quality. You can watch how you're doing on the Deliverability tab, which shows a health score for each provider. See Monitor your email deliverability for how to read it.
By default all Yaplet mail goes out from a shared, pre-warmed IP pool — the right choice for almost everyone. High-volume senders who want a reputation entirely their own can enable a dedicated IP.
Troubleshooting
| Symptom | Likely cause and fix |
|---|---|
| A record still shows "Not detected" after a while | DNS hasn't propagated. Give it an hour or two; the page keeps re-checking. Double-check you entered only the host part if your provider appends the domain automatically. |
| A record shows "Failed" | A genuinely conflicting value is set — in practice an SPF record without include:amazonses.com. Merge it into your existing SPF instead of adding a second record. |
| A record shows "Don't add" | Nothing to fix — it conflicts with your existing email setup, and the note on the row explains why it's safe to leave out. Verification doesn't need it. |
| DKIM won't verify | One of the three DKIM CNAMEs is missing, mistyped, or proxied through Cloudflare (must be DNS-only). Re-copy each name and value. If you added the records more than 72 hours after adding the domain, just press Re-check status — it restarts Amazon's search automatically. |
| Link tracking won't turn on | The SSL certificate isn't issued yet. Add the Secure-links records (including the CAA record if Yaplet flagged one), then wait for AWS to issue the certificate. |
| Domain verified but campaigns still go to spam | SPF and DKIM pass but the domain has low reputation. Send to a small, engaged segment first and watch the Deliverability tab. |
What's next
With your domain verified, add more sender addresses for your team, then send your first campaign.