Setup Guides
Provider-Specific Email Setup Guides
Documentation that starts where the official docs stop: each guide walks the exact setup for one provider, then covers the failures we actually find in audits - the forgotten toggle, the truncated record, the default signature that never aligns. Every guide ends with a way to verify the fix on a real message.
Microsoft 365 SPFOne record, the right include, and the 10-lookup trapThe v=spf1 include:spf.protection.outlook.com record, how to add third-party senders without blowing the 10-lookup limit, when to switch to -all, and the five failures we find.Read the guide →Microsoft 365 DKIMThe selector1/selector2 CNAMEs everyone forgetsWhy the tenant-default onmicrosoft.com signature never aligns, the 5-step Defender walkthrough with exact CNAME shapes, and the six failures that break it.Read the guide →Microsoft 365 DMARCThe monitor-then-enforce path to p=rejectWhy the onmicrosoft.com default makes alignment the real work, the exact _dmarc record, the safe path from p=none to p=reject, and the connector/relay traps.Read the guide →Google Workspace SPFinclude:_spf.google.com and the 10-lookup trapThe v=spf1 include:_spf.google.com record (which alone spends four of your ten lookups), adding senders safely, ~all vs -all, and the five failures we find.Read the guide →Google Workspace DKIMThe google._domainkey record and the gappssmtp trapGenerate the key, survive your DNS host's TXT limits, remember Start authentication - and the six failures that leave Workspace mail signing as gappssmtp.com.Read the guide →Google Workspace DMARCgappssmtp alignment and the path to p=rejectWhy the gappssmtp default makes alignment the real work, the _dmarc record, the safe path to p=reject, and the Workspace traps (Groups forwarding, relay).Read the guide →Zoho Mail SPFOne record, the right include and the 10-lookup trapThe v=spf1 include:zohomail.com record, the Admin Console verification, and the five failures that break Zoho SPF - including the include:zoho.com permerror many guides still teach.Read the guide →Zoho Mail DKIMThe selector, the key and how to verify itEnable DKIM in the Admin Console, publish the zoho._domainkey TXT record and verify it - plus the failures we find: split keys, CNAME instead of TXT, wrong host, unverified selectors.Read the guide →Zoho Mail DMARCMonitor first, then enforce to p=rejectThe _dmarc TXT record, a safe rollout from p=none to p=reject, and reading the reports with Postbox DMARC Monitor so you enforce only once every legitimate sender aligns.Read the guide →SendGrid AuthenticationDomain Authentication: the CNAMEs for SPF, DKIM and DMARCThe three CNAME records SendGrid generates, why they keep SPF off your root domain, the s1/s2 DKIM selectors and DMARC alignment, link branding, and the failures we find (verifying too early, proxied CNAMEs, single-sender-only).Read the guide →Amazon SES AuthenticationEasy DKIM, a custom MAIL FROM for SPF, and DMARCThe three Easy DKIM CNAMEs, the custom MAIL FROM (MX + SPF) that aligns SPF, why SES never creates your DMARC record, leaving the sandbox, and the failures we find (SPF unaligned by default, wrong-region MAIL FROM MX, partial DKIM).Read the guide →Mailgun AuthenticationThe sending subdomain, the DKIM CNAMEs, and DMARCWhy Mailgun sends from a subdomain, the SPF include everyone gets wrong (mailgun.org, not .net), the DKIM CNAMEs Mailgun rotates for you, when you need MX, and the failures we find (root-vs-subdomain, unsplit 2048-bit TXT, proxied CNAMEs).Read the guide →Klaviyo Dedicated Sending DomainThe branded sending domain, deliverability and DMARCKlaviyo's branded (dedicated) sending domain step by step - the NS-delegation or CNAME records, the km1/km2 DKIM, the SPF and return-path Klaviyo handles for you, the DMARC you publish yourself, and the failures we find (proxied records, verifying too early).Read the guide →HubSpot Email AuthenticationThe two DKIM CNAMEs, SPF, DMARC and the return-pathConnecting a HubSpot email sending domain - the two DKIM CNAMEs, why SPF and DMARC stay yours to publish, the custom return-path for SPF alignment on Enterprise, and the failures we find (partial DKIM, second SPF record, guessed targets).Read the guide →beehiiv Custom DomainThe custom-domain CNAMEs, the root-SPF mistake, and DMARCbeehiiv's custom email domain step by step - the CNAME records it generates, why your root SPF stays untouched, the DMARC record beehiiv requires you to publish yourself, and the failures we find (root SPF includes, proxied CNAMEs, shared-domain lists that grew too big).Read the guide →DMARC EnforcementFrom p=none to p=reject, safelyThe provider-agnostic playbook: what alignment means, every DMARC tag explained, and the monitor-then-enforce path that gets you to p=reject without quarantining your own mail.Read the guide →BIMIYour logo in the inbox, and when you need a VMC or CMCPublish BIMI on top of DMARC enforcement - the SVG Tiny 1.2 P/S logo, the default._bimi record, and the VMC-vs-CMC decision: what shows in Gmail, Yahoo and Apple, and the blue verified check.Read the guide →
More on the wayExchange Online sending limits and the restricted-entities trap, and more provider guides are queued. Meanwhile, test any setup with Postbox Mailtester.
Not sure which part of your setup is broken?