Before You Begin:
You will need to ADD these DKIM and DMARC records to your DNS records, you WILL NOT need to delete your existing DKIM and DMARC record. If you delete your existing DKIM and DMARC records it will reduce deliverability; adding records does not impact email deliverability.
For more information, please watch this demo before you begin.
Setting up email authentication for your domain
As part of moving to our new email infrastructure, we need your domain to have two pieces of email authentication in place: DKIM and DMARC. Your domain is currently missing one or both.
This is worth doing regardless of the migration. Gmail, Yahoo, Apple, and Microsoft have required both for nearly three years, and domains without them are at higher risk of having mail land in spam or get rejected. Think of this as an overdue fix that also clears the way for your migration. Setup usually takes 10 to 20 minutes.
You will make these changes at your DNS host, which is wherever you manage your website domain (commonly GoDaddy, Cloudflare, or Squarespace). If someone else handles your IT or DNS, this is the part to forward to them.
Step 1: Add the DKIM records
Add the following two CNAME records.
| Type | Host / Name | Value / Target |
|---|---|---|
| CNAME | ea1._domainkey.yourdomain.org | ea1.ea.custdkim.bonterratech.com |
| CNAME | ea2._domainkey.yourdomain.org | ea2.ea.custdkim.bonterratech.com |
Replace yourdomain.org with your actual domain. Two things to watch for:
-
If you use GoDaddy, it may automatically add your domain to the Host field, so you would enter only
ea1._domainkeyandea2._domainkeyrather than the full value. -
If you use Cloudflare, set these records to DNS only, not proxied.
Step 2: Add the DMARC record
While you are in your DNS editor, add one TXT record.
-
Host:
_dmarc.yourdomain.com -
Value:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.org; fo=1
What this does: p=none means monitor only, so no mail will be blocked or sent to spam as a result of this record. It is the safe starting point. rua= is where your monitoring reports go, so point it at a dedicated inbox or a free DMARC monitoring service such as Valimail. fo=1 asks for detailed reports that help diagnose any issues. We recommend staying at p=none and watching your reports for at least a month before tightening the policy further.
Step 3: Confirm everything is working
DNS changes usually take effect within a few minutes but can take up to 48 hours. Once they are in, go to your Targeted Email settings page, register your domain, and follow the prompts to validate. The page will confirm whether DKIM is passing and whether your DMARC record is in place.
If DKIM does not validate, the most common cause is a small copy error. Recheck that the CNAME values match exactly with no extra spaces or line breaks.
Step 4: If something does not validate
Here are the most common situations and how to resolve them.
-
DKIM is passing and DMARC shows up. You are all set, nothing more to do before the migration.
-
DKIM is passing but DMARC is not detected. The DKIM records went in correctly but the DMARC record is missing or has not propagated yet. Double check that you added the TXT record from step 2, that the host is
_dmarc.yourdomain.com, and give it a little more time if you just added it. -
DKIM is not passing. Almost always a copy error. Recheck that both CNAME values match exactly with no extra spaces or line breaks. If you are on GoDaddy, confirm you did not accidentally include your domain twice in the Host field (it often appends it for you). If you are on Cloudflare, confirm the records are set to DNS only and not proxied.
-
You just made the changes and nothing shows yet. DNS can take up to 48 hours to propagate, though it is usually much faster. If it has been only a few minutes, wait and re-check.
-
You do not have access to your DNS settings. Forward these instructions to your IT team or website administrator so they can add the records. We can send the full record values in writing for you to pass along.
-
You want a stricter DMARC policy or send mainly to large enterprise inboxes. Reach out to support so we can set up a custom return path for tighter alignment. Otherwise, stay at
p=noneand monitor your reports for at least a month before tightening.
If you have rechecked the values and DKIM still will not validate, contact us and we will take a look with you.
