Why Your Mailgun Domain Setup Fails Without Proper DNS Records

You send a transactional email through Mailgun—confirmation, reminder, alert—and it vanishes. No bounce, no reply, no delivery. Just silence. This isn’t a Mailgun issue. It’s likely a DNS misstep.

For every email to land in an inbox, the domain must pass a series of technical checks. If your Mailgun sending domain lacks or misconfigures SPF, DKIM, and DMARC, the email will be blocked, quarantined, or tagged as spam. Your deliverability hinges on these records—before a single message is sent.

Most send failures aren’t from Mailgun’s infrastructure. They come from DNS records that are missing, incorrect, or outdated. Getting them right isn’t optional—it’s the foundation.

Key takeaways

  • SPF, DKIM, and DMARC records are required for Mailgun domains to pass inbox filtering.
  • Even a single misconfigured DNS record can result in 100% email delivery failure.
  • Verifying DNS settings before sending is the only reliable way to prevent inbox placement issues.

What Are the Best DNS Records for Mailgun Sending Domain Setup?

You need three core DNS records for Mailgun: SPF to authorize Mailgun to send emails from your domain, DKIM to add a cryptographic signature proving email authenticity, and DMARC to specify how receivers should handle failed authentication. For some ISPs, PTR (reverse DNS) is also required to reduce spam flags. Proper setup improves inbox placement and sender reputation.

SPF: Authorizing Mailgun to Send on Your Behalf

SPF (Sender Policy Framework) tells receiving servers which mail servers are allowed to send email from your domain. For Mailgun, you must add a TXT record with a value like v=spf1 include:mailgun.org -all. This explicitly authorizes Mailgun’s sending infrastructure while rejecting unauthorized sources. If you already have SPF records, combine them using include: rather than duplicating; multiple SPF records cause validation failures. RFC 7208 defines the standard.

DKIM: Proving Email Authenticity with Cryptography

DKIM adds a digital signature to every outbound email. Mailgun generates a unique key pair — you publish the public key in DNS as a TXT record. The receiving server uses it to verify the email wasn’t altered in transit. This prevents spoofing and boosts trust. You’ll find the required DKIM record in your Mailgun control panel under “Domains.” Without DKIM, your emails may be flagged as suspicious, especially on major providers like Gmail or Outlook.

DMARC: Setting the Rules for Failed Authentication

DMARC builds on SPF and DKIM by telling receivers what to do if either check fails. You set a DMARC policy in DNS — typically v=DMARC1; p=none; during setup (monitor reports), then p=quarantine or p=reject once confident. This helps identify phishing attempts and improves sender reputation. Tools like dmarc.org provide guidance on policy implementation.

PTR (Reverse DNS): A Less Common but Important Step

While not required by Mailgun, some ISPs and enterprise email systems enforce PTR records for outbound mail validation. If your sender IP doesn’t have a reverse DNS entry, some providers may reject or mark your emails as spam. You’ll need to work with your hosting provider or Mailgun (via dedicated IP) to set this up. Not all providers use it, but it’s worth confirming if you're targeting enterprise inboxes.

Correct DNS setup is foundational. Use a tool like inbox placement tester to validate whether emails from your domain reach inboxes after configuration. Also, verify your entire list with a tool like bulk email list verification before sending—this helps avoid sending to invalid, catch-all, or disposable addresses that degrade your reputation.

How to Verify Your DNS Records Are Correctly Set Up

You must validate each DNS record (SPF, DKIM, MX, and TXT) using a real-time lookup tool, check exact values including spaces and quotes as specified by Mailgun, test all domains and subdomains if sharing an account, and use an API like MailTester’s to verify sender domains before sending. This prevents bounces, blocks, and poor deliverability.

Use Real-Time DNS Lookup Tools

  1. After setting up your Mailgun domain, use a live DNS lookup tool—like MXToolbox or DNSChecker.org—to confirm records resolve correctly. These tools show current global DNS states, not cached or local versions.
  2. Check each record independently: SPF, DKIM, DKIM selector, MX, and TXT. A single misconfigured record can trigger rejection or filtering.
  3. Verify propagation across geographies. DNS changes can take up to 48 hours to propagate globally; test from multiple locations to be sure.

Check TXT Values with Precision

  1. Mailgun’s TXT record values are case-sensitive and exact. Even a single extra space or missing quote changes the verification result. Double-check using Mailgun’s setup guide.
  2. If you’re using a single Mailgun account for multiple domains or subdomains, each must have its own correctly configured TXT and SPF entries. Shared SPF records without proper mechanisms can cause failures.
  3. Use MailTester’s real-time verification API to test your sending domains and subdomains before sending mail. It checks DNS records as part of a broader validation flow.

If you’re managing a bulk list, use MailTester’s bulk verification feature to screen all sender domains for DNS issues at scale.

Even small discrepancies in DNS records—like a misplaced space—can break deliverability. Accuracy matters.

Always verify records after editing. Many tools return cached or outdated results. For consistent reliability, test with multiple providers. This step isn’t optional—it’s the first line of defense against sending failure.

SPF, DKIM, and DMARC: Roles in Mailgun Domain Deliverability

You need SPF to authorize Mailgun’s IP addresses to send on your domain, DKIM to cryptographically sign each email so receivers can verify it wasn’t tampered with, and DMARC to set policies on how receivers handle emails that fail SPF or DKIM. Set them correctly, and you dramatically improve inbox placement. Too many includes or overly strict policies can break delivery. Let’s break down each one.

How Each DNS Record Works in Practice

SPF tells receivers which IPs are allowed to send mail for your domain. You list Mailgun’s outbound IPs in a TXT record, or use a mechanism like include:mailgun.org. But avoid nesting too many includes—some receivers reject records with more than 10 includes.

DKIM uses a private key hosted by Mailgun to sign each email. The public key is published in a TXT record under a selector (like mailgun._domainkey.yourdomain.com). Receiving servers retrieve it to verify the signature. This is crucial: without DKIM, many ISPs treat your messages as suspicious.

DMARC controls what happens when emails fail SPF or DKIM. Start with p=none to monitor delivery without blocking. After a few weeks, move to p=quarantine or p=reject once you’re confident alignment is correct.

Record Type What It Does How to Set It Up with Mailgun Common Pitfalls
SPF Authorizes IPs to send on your domain Add a TXT record: v=spf1 include:mailgun.org -all Too many includes (over 10), incorrect syntax, missing -all or +all
DKIM Signing mechanism to verify email integrity Mailgun generates a public key. Paste it in a TXT record under a selector (e.g., mailgun._domainkey.yourdomain.com) Wrong selector, missing DNS propagation time, expired key
DMARC Enforces policies on failed SPF/DKIM Create a TXT record: _dmarc.yourdomain.com with policy like p=none or p=quarantine Setting p=reject too early, missing rua and ruf for reporting

Check your records with a tool like MxToolbox or RFC 7483 to ensure they’re properly formatted and applied. You can also test deliverability before sending by checking if your domain passes SPF, DKIM, and DMARC in real inboxes via our inbox placement tester. This lets you catch issues early—before they hit your campaign performance.

“DNS records aren’t optional. They’re the foundation of sender reputation.”

Common DNS Mistakes That Break Mailgun Deliverability

You’re likely losing deliverability because of a single DNS misconfiguration. SPF duplicates, incorrect DKIM selectors, weak DMARC policies, or stale DNS after a change—these are the silent killers. Even one error can send Mailgun emails straight to spam or the void. Let’s fix the most common pitfalls step by step.

SPF: One Record Only

  • Only one SPF record is allowed per domain. If you have multiple SPF entries, DNS will ignore all of them. This breaks authentication completely.
  • Never split SPF across multiple records. Combine your Mailgun SPF with any existing ones using a single, coherent record like v=spf1 include:mailgun.org -all.
  • Use tools like MxToolbox to check for duplicate or malformed SPF records before sending.

DKIM: Selector Must Match

  • Mailgun uses the default selector. Your DKIM record must include default._domainkey in the DNS TXT record name.
  • Using a custom selector without updating Mailgun’s configuration will cause DKIM failures. Stick to default unless you’re intentionally changing it.
  • If Mailgun shows DKIM verification errors, verify the record syntax and ensure the selector is correct.

DMARC: Don’t Start with ‘p=reject’

  • Setting a strict DMARC policy like p=reject too soon can block legitimate mail if your setup is incomplete.
  • Start with p=none to monitor reports. Use a DMARC analyzer like DMARC Analyzer to watch for authentication failures.
  • Only move to p=quarantine or p=reject after consistent alignment and zero failed reports for at least 7 days.

Subdomains and IPs: Update DNS After Changes

  • Changing Mailgun subdomains (like newsletter.yourdomain.com) or sending IPs requires updating DNS records immediately.
  • Old DNS entries pointing to defunct IPs will cause bounces or spam filtering even if your email content is clean.
  • Use the MailTester email checker to validate a single address before sending, ensuring the domain and subdomain are correctly configured.

How to Test Domain Configuration Before Sending Campaigns

Before sending any campaign through Mailgun, verify your domain setup with real-world inbox placement tests and a clean email list. Use MailTester to send a test message to 12 real inboxes, simulate delivery conditions, and track exactly how many land in the inbox versus spam. Run a full bulk verification to remove invalid or risky addresses, and confirm all domains in your send list have proper SPF, DKIM, and DMARC records configured. These steps reduce bounces, improve sender reputation, and increase the odds your emails are seen.

Test with Real Inboxes Before You Send

  1. Use MailTester’s inbox placement tester to send a sample message through Mailgun to 12 real inboxes across major providers (Gmail, Outlook, Apple Mail, etc.). This isn’t a simulation—it’s actual delivery to active accounts.
  2. Check the results report: it shows exactly how many reached the inbox, how many were flagged as spam, and why. Most delivery issues come from misconfigured DNS or unverified domains.
  3. Fix any red flags—like missing SPF records or mismatched DKIM selectors—before moving forward. You’re testing the real delivery path, not just a checklist.

Prep Your List and Confirm Domain Auth

  1. Run your entire email list through MailTester’s bulk list verification. It checks every address for validity, catch-all status, disposable domain use, and role account risks.
  2. Remove any invalid, risky, or dormant addresses. Sending to these harms your sender reputation and increases bounce rates. Even a single malformed address can trigger delivery throttling.
  3. Confirm all domains in your list have properly configured DNS records. Use MXToolbox or RFC 7208 (SPF) and RFC 6376 (DKIM) as reference to verify alignment. Misconfiguration is the top reason for inbox rejection.
  4. Use MailTester’s email verification API for real-time checks during signup or list import. This prevents bad data from entering your system in the first place.

These steps aren’t optional—they’re what separate reliable senders from those blocked or filtered.

How SPF and DKIM Prevent Your Emails from Being Marked as Spam

You don’t need a complex email system to understand that SPF and DKIM are essential for proving your emails are legitimate. SPF confirms your sending server is authorized under your domain, while DKIM verifies the message content hasn’t been altered in transit. Together, they significantly reduce the risk of your emails being flagged as spam—even if your content is perfectly clean. Without them, even well-intentioned emails often fail to reach inboxes.

SPF: Authorizing Your Sending Servers

SPF (Sender Policy Framework) acts like a whitelist for your domain. It tells receiving mail servers which IP addresses are allowed to send emails on your behalf. If an email comes from an unauthorized server, the SPF check fails. That’s why failing SPF is a top reason emails get rejected or sent to spam folders.

Let’s say you use Mailgun to send transactional emails. If your SPF record doesn’t include Mailgun’s sending IPs, the receiving server sees your message as suspicious, even if it’s perfectly formatted. You can validate your SPF configuration using tools like MxToolbox or by checking the RFC 7208 spec directly.

DKIM: Securing Message Integrity

DKIM (DomainKeys Identified Mail) adds a digital signature to each outgoing message. Receiving servers use your public key (published in DNS) to verify the signature. If the signature doesn’t match, it means the email was altered after sending—likely by a spammer or malware.

This is especially important for long email chains or messages that pass through multiple relays. Even small changes like reformatting or inserting tracking pixels can break DKIM. Properly set up, DKIM ensures the content your recipients receive is identical to what you sent.

Because DKIM relies on cryptographic proof, it’s one of the most trusted authentication methods used by major providers like Gmail and Outlook. It works alongside SPF to build sender reputation, a key factor in inbox placement.

Without SPF and DKIM, your domain is vulnerable to spoofing. Even a single unauthenticated message from a compromised device can hurt your sender reputation. It’s not just about avoiding spam filters—it’s about maintaining trust with both providers and recipients.

If you’re setting up Mailgun or another ESP, double-check both records. Use a DNS validator to confirm syntax and reach. For bulk sender setup, you can also test deliverability before sending: run an inbox placement test to see how your emails land across major providers.

Best Practices for Maintaining DNS Authentication Over Time

Keep your Mailgun sending domain secure and deliverable by consistently validating DNS records after any change, using automated tools to verify domains at scale, monitoring reputation signals, and ensuring each campaign uses only domains with aligned authentication levels. This reduces bounce rates and prevents inbox placement drops.

Validate DNS after configuration changes

  • Always recheck SPF, DKIM, and DMARC records immediately after switching Mailgun IPs or updating routing rules.
  • Changes can break authentication—especially if you remove or misconfigure SPF mechanisms, leading to rejection by receiving servers.
  • Use RFC 7052 as a reference for proper SPF design, avoiding overly permissive or conflicting policies.

Automate verification during onboarding and audits

  • Use the MailTester verification API to test hundreds of domains in minutes during onboarding or post-migration.
  • Check for valid DNS records, mailbox existence, and catch-all setups without sending actual emails.
  • Pair API results with deliverability testing via MailTester’s inbox placement tool to spot issues before they hit your campaign performance.

Monitor reputation and threat signals

  • Check your domain’s IP reputation regularly using tools like MxToolbox or AbuseIPDB.
  • If your Mailgun IP gets added to a blocklist, investigate the source and update your sender profile accordingly.
  • Reputation decay can start silently—even a single high-spam complaint can trigger filtering.

Keep authentication levels consistent per campaign

  • Avoid mixing domains with full DKIM/SPF with those using only SPF or no authentication in the same campaign.
  • Inconsistent authentication confuses receivers and lowers trust signals, increasing the odds of filtering.
  • Always align your domain’s setup with its intended use—dedicated domains for transactional, bulk, or marketing mail are best practice.
Authentication isn’t a one-time task. It’s a continuous check. A single broken DNS record can undo weeks of inbox placement work.

How MailTester’s Real-Time Verification API Can Prevent Domain Failures

You can stop domain-level send failures before they happen by using MailTester’s Real-Time Verification API to check every email address and its domain before sending through Mailgun. This catches missing or broken DNS records early, avoids bounces from invalid or catch-all domains, and identifies disposable email addresses—all with 98.9% accuracy. It’s a proactive step that keeps your sender reputation intact.

Prevent Failures with Verification Before Send

Let’s be clear: a single broken DNS record on a domain can break your Mailgun campaign before it starts. SPF, DKIM, and DMARC are required for authentication and deliverability. If a domain misses any of these, messages are silently rejected or marked as spam. You don’t want to find out on the 10,000th send that a whole domain fails.

That's where MailTester's API comes in. It checks not just individual addresses, but the underlying domain configuration—spotting missing or malformed records before you add the address to a campaign. This includes catching domains with no SPF, broken DKIM, or misconfigured DMARC policies, all of which are common causes of authentication failures.

Batch Check Lists for Hidden Risks

Manual verification isn’t scalable. When you’re sending to thousands of recipients, even a single invalid domain can trigger ISP rejection. MailTester’s Real-Time API lets you validate entire bulk lists at once. It returns clear verdicts: valid, invalid, catch-all, disposable, or risky.

For example, a "catch-all" domain accepts any address—meaning you can’t verify if an email is actually deliverable. These fake inboxes waste sends and hurt your sender reputation. The API detects them early. Disposable domains, often used for short-term signups, are also flagged and can be excluded before they even touch your Mailgun account.

MailTester’s 98.9% accuracy rate—validated through real-world testing—means you can trust the results. It’s not a guess. It’s based on real SMTP checks, DNS validation, and behavioral analysis. This precision isn’t common in tools that rely only on pattern matching or blacklists.

For teams using Mailgun, this means fewer bounces, better inbox placement, and a cleaner sender reputation. Use the API to automate checks in your workflow, integrate it with your CRM or marketing platform, and avoid domain failures entirely. If you're building a list, check every address with MailTester’s email checker first. And if you're evaluating deliverability, test how inboxes receive your campaigns with inbox placement testing. The goal is simple: send only to addresses that can receive.

Why You Should Test Deliverability Before Sending to a Large List

You should test deliverability before sending to a large list because even one misconfigured domain can harm your sender reputation. A single failed send or high bounce rate can trigger filters, especially with providers like Gmail or Outlook. Testing with real inboxes exposes issues you can’t see through DNS checks alone—like image blocking, spam placement, or corrupted headers—before they damage your brand’s credibility.

How to Test Deliverability Effectively

  1. Run an inbox placement test across major providers using a tool that simulates real email delivery. This tells you whether your messages land in the inbox, spam, or are blocked outright—commonly seen in reports from Spamhaus and Return Path.
  2. Verify every address in your list before sending. Use real-time validation to catch invalid emails, catch-all domains, and disposable addresses. This reduces bounce rates and protects your sender reputation. See how it works: check a single email address.
  3. Check your DNS records against Mailgun’s requirements. Ensure SPF, DKIM, and DMARC are properly configured. Mismatched or missing records are a top reason for delivery failure. A test can show if your setup passes validation in real-world conditions.
  4. Review header and content behavior. Some inboxes block emails with suspicious links, oversized images, or non-standard headers. A real inbox test shows if your message appears as intended or gets stripped down or flagged.
  5. Refine your setup based on test results. Use insights to adjust your DNS, improve content, or avoid problematic domains. This reduces risk before you send to thousands.

Why Testing Beats Guesswork

Without testing, you’re guessing. You might assume your DNS is correct, but mail providers run complex filters that aren’t visible in DNS tools. A single flawed domain—say, an old catch-all or a role address—can degrade your overall sender reputation. According to RFC 5321, email delivery success hinges on technical and reputational compliance, both of which require validation.

MailTester’s inbox-placement tests deliver real results across Gmail, Outlook, Yahoo, and others. You get feedback on delivery outcome, spam score, and content rendering—before you send a single email to your list. This gives you data, not assumptions.

Conclusion: Set Up DNS Right the First Time

Proper DNS configuration—SPF, DKIM, and DMARC—is not optional. It’s the foundation of reliable Mailgun sending and inbox placement.

Even small errors in these records are among the most common reasons emails fail to deliver. Assumptions about correctness are unreliable; verification is required.

Use real tools to test your setup. Don’t guess. MailTester gives you precise feedback on every record, helping you catch issues before they hurt your sender reputation.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Does Mailgun require DNS records for sending?

Yes. You must set up SPF, DKIM, and DMARC records to authenticate your domain and ensure inbox placement.

Can I use Mailgun without setting up DNS records?

No. Without proper DNS authentication, Mailgun will not deliver emails reliably, and they will often be marked as spam.

What happens if my SPF record is too long?

SPF validation fails. Limit includes and use SPF record aggregation if needed to avoid exceeding the 256-character limit.

How do I know if my DKIM record is working?

Check the DKIM signature in the raw email headers. Mailgun signs messages using the default selector unless otherwise configured.

Can I set up DNS records for multiple domains in Mailgun?

Yes. Each domain must have its own SPF, DKIM, and DMARC records configured in DNS and verified in Mailgun.

What does a 'p=none' DMARC policy mean?

It means no action is taken on failed messages. Use this during testing to collect reports without blocking delivery.

Do I need reverse DNS (PTR) for Mailgun?

Not always. Most providers accept SPF and DKIM alone. Some require PTR for high-volume sending or specific IPs.

How can I test my DNS setup before sending?

Use tools like MailTester to verify domains or run inbox-placement tests with real email providers.

Can MailTester check if my Mailgun domain's DNS is valid?

Yes. Use MailTester’s real-time API or bulk verification to test domains for valid DNS records and delivery readiness.

What happens if I ignore DMARC?

Your emails may be rejected or marked as spam if other authentication checks fail, especially on major platforms.

Why do some emails still go to spam after setting up SPF and DKIM?

DMARC misconfiguration, poor sender reputation, or content issues can override authentication. Test with real inboxes to diagnose.

How often should I revalidate my DNS records?

After any DNS change, before major campaigns, and quarterly during routine maintenance.