Setting Up DNS for SaaS Emails
When you create a Software as a Service (SaaS) or a social web platform, one of the often-overlooked parts of it is the email DNS configuration. I learned this too late with my own projects, and as a result, many of my initial emails landed in spam folders. Also, incorrect DNS records can make it easier for attackers to send emails pretending to be from your domain. Here are my learnings about it from 5 years of running a SaaS business. Consider using separate subdomains for different types of email The emails you send generally fall into these categories: direct - emails that you send manually. transactional - emails that your website sends for signup confirmations, two-factor authentications, password resets, etc. marketing - onboarding emails, mailing-list newsletters, birthday greetings, etc. Marketing emails are frequent and not always wanted, so recipients may mark them as spam, which can hurt your sender reputation. Deliverability also depends on factors such as authentication, engagement, list quality, and sending practices (You can check your existing email spamminess at SpamHaus or MxToolbox). For this reason, it can be useful to separate marketing emails from direct and transactional emails using different subdomains. If example.com is your marketing website, and app.example.com is your SaaS, your main emails could be: info@hello.example.com - for marketing / newsletters hello@mail.example.com - for transactional and direct emails MX records for receiving emails An MX record (Mail eXchange record) is a type of DNS record that specifies which mail server is responsible for accepting email on behalf of a domain. When somebody sends an email to you, the sending mail server looks up the MX record for your domain to find out where to deliver that message. In the host field you would set your subdomain (or @ for the root domain). The values contain the domain of the mail server and the priority of that server (a lower preference number means higher priority). If the server with higher priority is unreachable, the mail will fall back to the secondary one. TTL (Time To Live) controls how long DNS resolvers are allowed to cache a record before checking back for updates. While configuring and testing the server you can set it to a low value like 5 min, but when everything is working reliably, you can switch to Automatic. Here is an example setup pointing to FastMail servers. Type Host Value TTL MX Record hello in1-smtp.messagingengine.com. 10 Automatic MX Record hello in2-smtp.messagingengine.com. 20 Automatic MX Record mail in1-smtp.messagingengine.com. 10 Automatic MX Record mail in2-smtp.messagingengine.com. 20 Automatic Note that Fastmail does not allow its service to be used for automated or transactional emails, but you might need these settings for receiving your direct emails and replies. SMTP setup for outgoing emails SMTP (Simple Mail Transfer Protocol) is the protocol used to transfer email between mail servers and from mail clients or applications to mail servers. SMTP will be used no matter whether you send a direct email from an email client like FastMail, or a transactional email from Amazon SES, Postmark, Brevo, Mailjet, Resend, SendGrid, Mailgun, or Postal. SPF records for outgoing emails: Which senders are allowed? An SPF record (Sender Policy Framework) is a type of DNS TXT record that specifies which mail servers are allowed to send email on behalf of your domain. It’s one of the core mechanisms used to prevent email spoofing. SPF has one record per domain or subdomain and multiple senders must be combined into one line. Type Host Value TTL TXT Record hello v=spf1 include:spf.messagingengine.com include:spf.mailjet.com -all Automatic TXT Record mail v=spf1 include:spf.messagingengine.com include:spf.mailjet.com -all Automatic Here: v=spf1 - declares this is an SPF record, version 1. include:domain.com - delegate to another domain’s SPF record. -all - hard fail - SPF fails for unauthorized senders. ~all - soft fail - SPF fails, but the receiver may still accept the message. ?all - neutral - SPF makes no policy statement. Some of the well known includes: include:spf.messagingengine.com - FastMail include:_spf.google.com - Google Workspace include:spf.mailjet.com - Mailjet include:spf.brevo.com - Brevo include:servers.mcsv.net - MailChimp include:amazonses.com - Amazon SES or Resend (which is built on top of Amazon SES) include:sendgrid.net - SendGrid include:mailgun.org - Mailgun DKIM records for outgoing emails: Is the sender valid? A DKIM record (DomainKeys Identified Mail) is a DNS TXT record containing a public cryptographic key that lets receiving mail servers verify that an email genuinely came from your domain and wasn’t altered in transit. Sometimes, it’s a CNAME record pointing to the servers of the mail service, which contains the DNS TXT records with the cryptographic keys. Typically, the Host is