Mailgun Sending Domain Authentication with SPF and DKIM 2026
Ensure your Mailgun emails reach inboxes by setting up SPF and DKIM authentication correctly. Reduce bounces and boost deliverability with proven steps.
Why does Mailgun sending domain authentication matter?
You send an email through Mailgun. It goes out. But it never reaches the inbox. Instead, it lands in spam—or disappears entirely. Why?
Because modern email providers don’t trust messages without proper SPF and DKIM authentication. These aren’t optional checkboxes. They’re the foundation of sender reputation. Without them, even well-crafted messages fail.
Spam filters at Gmail, Outlook, Apple Mail, and others check for authentication. One missing record, one misconfigured TXT or DKIM key, and your domain loses credibility. Repeated failures degrade your sender reputation—not just for Mailgun, but for your entire domain.
Key takeaways
- SPF and DKIM are mandatory for inbox placement with major email providers like Gmail and Outlook.
- Even small errors in DNS records (like incorrect syntax or missing selectors) cause delivery failures.
- Authentication isn’t just technical—it directly impacts deliverability, sender reputation, and long-term engagement.
What happens when SPF and DKIM aren’t set up for Mailgun?
If you send emails through Mailgun without properly configuring SPF and DKIM, your messages are far more likely to fail authentication checks. Receiving servers may reject them outright, mark them as spam, or delay delivery—leading to higher bounce rates and poor inbox placement. This weakens your sender reputation over time, making future emails harder to deliver. You’re essentially sending mail with no digital ID, which most modern email systems distrust.
SPF failures mean your messages get blocked
Without a valid SPF record, receiving servers can't confirm that Mailgun is authorized to send on your domain’s behalf. The SPF check fails, and many providers—like Gmail, Outlook, or Yahoo—treat this as a red flag. Result? Hard bounces or outright rejection, especially if your domain isn’t on a trusted list. This isn’t just a technical hiccup; it directly impacts your ability to reach real inboxes.
DKIM failures undermine message trust
Even if SPF passes, missing or invalid DKIM signatures mean the receiving server can’t verify that the message hasn’t been altered in transit. A failure here means the server can’t prove authenticity, even if the sender is real. Major providers use DKIM as a core check—without it, your email is at risk of being flagged as suspicious or junk, regardless of content quality. This is especially critical for transactional messages where integrity matters.
When both SPF and DKIM are missing, the effect compounds. The combination of a failed identity check and an unverified content signature creates a strong signal to filters that your emails should be treated with suspicion. Industry standards, like those from the Messaging, Malware, and Mobile Anti-Abuse Working Group (M3AAWG), emphasize that proper alignment of SPF and DKIM is a baseline expectation for reliable delivery.
Even if you’re not getting immediate bounces, inconsistent authentication erodes your sender reputation over time. ISPs track alignment, deliverability patterns, and feedback loops. A pattern of failed checks—even occasional ones—can result in gradual throttling or inclusion on blocklists, reducing reach across months rather than days.
Let’s be honest: setting up SPF and DKIM takes a few minutes, and skipping it is the opposite of smart. If you’re sending through Mailgun, this isn’t optional—it’s required if you want deliverability that works consistently. You can verify your setup with tools like MXToolbox or dmarcian, but checking the technical details isn’t the only thing you need.
Proactive list hygiene helps too. Use a trusted service to clean your email list before sending—like MailTester’s bulk verification—to catch invalid, typo-ridden, or permanently broken addresses before they trigger authentication issues or waste sender reputation. You’re not just validating addresses; you’re validating your sending credibility.
What is SPF, and why does it matter for Mailgun?
You need to set up SPF so Mailgun can send emails on your behalf without being blocked. SPF specifies which servers are allowed to send mail from your domain. If Mailgun’s IP addresses aren’t included in your SPF record, your emails may fail authentication and land in spam or get rejected outright.
How SPF works with Mailgun
When you use Mailgun to send emails from your domain, the receiving server checks your SPF record to verify that the sending server is authorized. If your SPF record doesn’t list Mailgun’s IP ranges, the email fails SPF authentication.
Mailgun provides a list of its outbound IP addresses and domains. You must include this in your SPF record using the include mechanism. For example: include:_spf.mailgun.org. This tells receiving mail servers: “Yes, Mailgun is authorized to send on my behalf.”
Risks of misconfiguration
SPF records can break if they exceed the 10 DNS lookup limit. Too many mechanisms—like multiple include entries—trigger a “permerror” and cause legitimate emails to fail. That’s why you should avoid including outdated or irrelevant senders, especially if you’re managing multiple email services.
It’s also important to avoid mixing SPF with other protocols like DKIM or DMARC unless you understand how they interact. The [RFC 7208](https://tools.ietf.org/html/rfc7208) defines SPF, and following it closely prevents unintended delivery issues. According to industry data, SPF misconfigurations are a top reason for email rejections by major providers like Gmail and Outlook.
Even if you’re using Mailgun, your domain’s overall reputation depends on every sending source. A poorly maintained SPF record can hurt deliverability even if all your Mailgun logs look clean. That’s why checking your domain’s authentication setup before sending is critical.
If you’re managing a large list, consider verifying email addresses before sending. Tools like MailTester offer real-time email verification to catch invalid or risky addresses early. It helps prevent unnecessary bounce rate spikes and improves sender reputation over time.
You can verify a single address instantly using MailTester’s email checker: check an email address before sending. Or for larger lists, use their bulk verification tool to clean your list and identify problematic domains before deployment.
What is DKIM, and how does it secure Mailgun emails?
DKIM (DomainKeys Identified Mail) adds a digital signature to every email sent through your Mailgun domain. Receiving servers check this signature using your domain’s public key in DNS, verifying the message wasn't altered in transit. This prevents spoofing and boosts deliverability, especially when combined with SPF and DMARC.
How DKIM works behind the scenes
When you send an email via Mailgun, the service generates a unique cryptographic signature based on the email’s content and headers. This signature is added to the message header, tied to your domain. Receiving mail servers look up your domain’s public key in DNS, then validate the signature using it. If the signature checks out, the email is trusted as authentic. If not, it may be flagged or rejected.
Think of DKIM like a sealed envelope: only someone with the correct key can verify that the message inside hasn’t been tampered with. This is crucial because spammers often modify message content (like changing the sender address) to bypass filters.
Why DKIM matters for your Mailgun setup
Without DKIM, even if your SPF records are set, attackers can still spoof your domain by altering text or headers in transit. DKIM prevents that by securing the content itself. Major email providers like Gmail and Yahoo use DKIM as part of their spam and fraud detection logic.
According to the IETF’s RFC 6376, DKIM is designed to provide origin authentication for email traffic. It’s not just about identity—it’s about trust in the content. This makes it essential for any sender serious about inbox placement and sender reputation.
Even if you're using Mailgun's infrastructure, you still own your domain’s authentication. You must publish the DKIM public key in your DNS—Mailgun provides the key material to do this. Failure to publish or misconfiguring it breaks validation, which harms deliverability.
For teams using Mailgun, ensuring DKIM is correctly aligned with SPF and DMARC forms a complete trust stack. The combination is industry-standard and expected by large providers. If you're unsure whether your domain’s keys are valid or properly set, verify your entire email setup with a tool that checks authentication in real-world conditions.
Test your email’s inbox placement across multiple providers to see how well your authenticated emails are received—without sending to real users.
How to set up SPF and DKIM for Mailgun in 7 steps
You can authenticate your Mailgun sending domain by setting up SPF and DKIM in your DNS records. SPF prevents spoofing by specifying which servers can send mail for your domain; DKIM adds a digital signature to verify message integrity. Both are required for high deliverability. Use Mailgun’s provided records and verify your setup with tools like MXToolbox or RFC 7208 to avoid common pitfalls like duplicate SPF records.
Set up SPF authentication
- You need to access your DNS provider’s control panel (like Cloudflare, GoDaddy, or Route 53).
- Look for your domain’s TXT record list, which may be under “DNS Management” or “Zone Editor.”
- Add a new TXT record with the name
example.com(your domain) and the valuev=spf1 include:mailgun.org -all. This tells receivers that Mailgun is authorized to send emails from your domain. - Double-check that only one SPF record exists. Multiple SPF records fail validation and harm deliverability—combine them if needed using the
includemechanism.
Enable DKIM signing in Mailgun
- Log in to your Mailgun control panel and go to the Domain settings.
- Find the DKIM section and enable signing. Mailgun will generate a public key and a selector (e.g.,
mailgun). - Copy the full public key string provided. It will look like a long TXT value.
- Create a new TXT record in your DNS provider using the selector name (e.g.,
mailgun._domainkey.example.com) as the record name and the public key as the value.
Once both records are live, DNS propagation may take 15 minutes to 72 hours. Verify your setup using MXToolbox’s SPF checker or a DKIM validator. Properly configured SPF and DKIM increase inbox placement and reduce the risk of your emails being marked as spam. If you’re sending large volumes, test with an inbox placement tool like MailTester's Inbox Placement Test to validate real-world delivery. For ongoing list hygiene, use MailTester’s bulk email verification to remove invalid or risky addresses before sending.
Common SPF and DKIM mistakes with Mailgun
You’re likely blocking your own emails if you’ve set up multiple SPF records, used the wrong DKIM selector, forgot to update DNS after changing subdomains, or added overly permissive includes like include:_spf.google.com alongside Mailgun. These errors trigger authentication failures, hurt sender reputation, and can land your messages in spam folders. Let’s fix them step by step.
SPF setup pitfalls
- Don’t create multiple SPF records — they conflict and fail validation. SPF only allows one record per domain. Combine mechanisms like
include:mailgun.organdinclude:_spf.google.cominto a single, correctly ordered record. - Never use
include:_spf.google.comif you’re not using Google’s infrastructure. Doing so can open your domain to abuse and weaken your authentication. For Mailgun, only includeinclude:mailgun.organd verify it’s the correct source. - Ensure your SPF record doesn’t exceed 10 DNS lookups. Overusing includes (e.g.,
include:mailgun.org include:spf.example.com) can trigger a hard fail. Use RFC 7208 as a guide for proper record construction.
DKIM missteps
- Use the correct DKIM selector and domain. Mailgun typically uses
mailgunas the selector and your subdomain (e.g.,mailgun.domain.com). Incorrectly typed selectors cause DKIM verification to fail. - Double-check the TXT record value. A single typo in the DKIM key — like missing a character or using the wrong domain — breaks authentication. Validate it using tools like MXToolbox or DNSStuff.
- Update DNS records when changing Mailgun subdomains or API keys. If you switch from
mailgun.domain.comtosend.domain.com, the old DKIM key becomes invalid. Failure to update leads to consistent authentication failures.
Even if your email sends, a misconfigured SPF or DKIM can still result in poor inbox placement or reputation penalties. Use MailTester’s inbox placement tester to check whether your messages reach the inbox, not spam, under real-world conditions — and verify your domain records with real sending behavior.
How to test if your SPF and DKIM are working
You can verify your Mailgun sending domain’s SPF and DKIM configuration by sending a test email from your domain to a service like MailTester, then checking the full email header analysis for successful SPF and DKIM validation results. If both checks pass, your authentication is working. If not, review your DNS records for typos or misconfigured selectors.
Send a test email and analyze the headers
Let’s walk through it: send a test message from your Mailgun-registered domain to an inbox you control—or better yet, use MailTester’s inbox-placement test. This sends your email through real mailbox environments and returns a detailed breakdown of how it was received.
Once the test completes, access the full header analysis. Look for two lines in the results: one showing SPF: Pass and another showing DKIM: Pass. These are direct indicators that your domain’s authentication setup is valid and recognized by receiving servers.
Fix issues by reviewing DNS records
If SPF or DKIM fails, don’t panic—this is common with misconfigured entries. The most frequent issue is a typo in your TXT record, like a missing hyphen or an incorrect selector (e.g., mailgun._domainkey vs mailgun._domainkey.txt).
Double-check your DNS records using tools like MxToolbox or RFC 7208 (which defines SPF) to ensure the record is properly formatted. Remember, SPF and DKIM work together: SPF validates the sending server, while DKIM ensures the message content hasn’t been altered in transit.
If you’re unsure what a record should look like, consult Mailgun’s official documentation or use their domain setup wizard. Small changes—like adding a missing space, correcting a selector, or updating the expiration—can fix problems that otherwise appear as bounces or spam filtering.
How MailTester helps verify SPF and DKIM effectiveness
MailTester verifies SPF and DKIM by sending test emails to real inboxes across Gmail, Yahoo, Outlook, and other major providers, checking whether your domain’s authentication passes from the receiving server’s perspective. Unlike basic syntax checks, it confirms whether your setup works in practice—catching issues like misconfigured policies, missing records, or relaxed alignment that silently harm deliverability.
Real inboxes, real feedback
When you run an inbox-placement test with MailTester, the message actually reaches a real user’s inbox at a major email provider. The results reflect how the receiving server interprets your SPF and DKIM signatures. If the alignment fails or the policies are too loose, the test will flag it—exactly how spam filters behave. This is the only way to know if your authentication truly holds up in production.
Because authentication is validated in real time by the recipient’s mail server, you’re not just checking DNS records—you’re validating how your domain behaves in the wild. Tools that only verify DNS syntax miss configuration errors that cause low inbox placement, even when all records are technically present. For example, RFC 7052 (a standard for sender authentication) states that DMARC alignment must match the domain in the "From" header, and MailTester checks that in actual delivery.
Pre-send validation and bulk checks
Use MailTester’s real-time API to check individual addresses before sending. If a domain fails SPF/DKIM validation during the check, you’ll catch it before it hits the inbox. This prevents sends to addresses with broken infrastructure—especially common with role accounts, disposable domains, or organizations with weak email hygiene.
For larger campaigns, MailTester’s bulk verification identifies entire domains with weak or missing SPF/DKIM records before launch. You can detect clusters of risk, clean your list early, and improve sender reputation. With this level of insight, you're not just sending emails—you’re ensuring every send is built on strong authentication.
Try it yourself: test a live domain’s delivery readiness with our inbox placement tester, or integrate real-time validation into your workflow using the real-time API. For bulk verification, see how the email list verifier surfaces risk at scale. Each step confirms that your sending domain is not just configured—but trusted.
What other deliverability risks should you watch for?
Even with proper SPF and DKIM set up, your Mailgun domain can still hit deliverability walls. High bounce rates from invalid or disposable emails damage your sender reputation. Role accounts like info@ or sales@ rarely engage, hurting inbox placement. Sending too fast—especially with a new domain—triggers spam filters. Inconsistent sending patterns or frequent list churn also raise red flags. Fixing these issues starts with cleaning your list and monitoring engagement.
Common deliverability pitfalls to avoid
- High bounce rates from invalid or disposable email addresses hurt your sender reputation. Even a 3% bounce rate can trigger filtering by major providers. Use real-time email validation before sending to catch these early.
- Role account addresses (e.g. support@, hr@, sales@) often don't engage. These don’t improve open or click rates and can lower your overall engagement score, increasing the chance your mail gets marked as spam.
- Aggressive sending volume without warming up a new domain is a red flag. Major email providers like Gmail and Outlook track sending velocity. Sudden spikes in volume from an untested domain signal potential spam. Start low and increase gradually.
- Inconsistent sending patterns—like sending every other day, then 200 emails in a single hour—confuse filters. They assume the sender is unreliable or compromised. Stick to a predictable, steady cadence.
- Frequent list changes or importing large batches every few days disrupt your sender history. Providers look at list stability over time. A list with 60% churn in one month will struggle to reach the inbox.
How to verify and prevent these risks
Before you send, verify the quality of your addresses. Tools like MailTester's bulk email verification can identify invalid, disposable, and role-based addresses—helping you prune your list before sending.
For real-time checks at scale, integrate MailTester’s verification API into your signup or onboarding flow. It checks individual addresses for validity and risk level in under 500ms.
Test how your messages land with inbox placement tests. You’ll see if your emails hit spam folders or get filtered out entirely.
Spam filtering rules are based on long-term behavior. The SMTP RFC 5321 defines standard delivery expectations, but real-world filters use behavioral models. The best defense? Clean data, steady sending, and consistent engagement. That’s what builds trust with inbox providers.
How to maintain long-term deliverability with Mailgun
You maintain long-term deliverability with Mailgun by verifying your list regularly, monitoring sender reputation, warming up new domains, and ensuring your SPF and DKIM records remain correct and tested after every DNS update. These steps prevent bounces, reduce spam complaints, and build inbox trust over time.
Core practices for consistent inbox placement
- Run your full email list through a bulk verification tool like MailTester's email list verification every 30–60 days to remove invalid or risky addresses before sending.
- Use inbox placement testing — such as MailTester’s inbox tester — to check how your messages land across major providers like Gmail, Yahoo, and Outlook.
- Enable feedback loops through major email providers (Google Postmaster Tools, Microsoft SNDS) to monitor complaints and spam traps in real time.
- When launching a new domain with Mailgun, start with low-volume sends (50–100 messages/day) and gradually increase volume over 7–14 days to build sender reputation.
Keep authentication stable and effective
- Review your SPF and DKIM configurations monthly—especially after adding new services or changing DNS records—to catch misconfigurations before they hurt deliverability.
- After each DNS change, test your setup using tools like MxToolbox or DMARC Analyzer to confirm records are correct and properly published.
- Use Mailgun’s API or MailTester’s real-time verification API to validate individual addresses in high-risk workflows before sending, reducing risky deliveries.
- Always ensure your SPF record doesn’t exceed 10 mechanisms (including includes), since overly long records can break validation.
Even with proper SPF and DKIM, deliverability isn’t guaranteed. Long-term success depends on consistent list hygiene and behavior tracking. The goal isn’t a single perfect send — it’s a pattern of reliable, trusted delivery over time.
Final step: Confirm your setup works before sending at scale
Even with SPF and DKIM properly configured, your messages can still fail to reach inboxes. The only way to be sure is to test with real email clients using your actual sending domain.
Use MailTester’s inbox-placement tool to send a test message to multiple inboxes across Gmail, Outlook, and Apple Mail. Confirm both SPF and DKIM pass in the report. Check that the message lands in the primary tab, not spam.
Run these tests monthly or whenever you update DNS records or sending infrastructure. Consistent validation ensures long-term deliverability and protects sender reputation.
Sources
- Since May 5, 2025, Microsoft Outlook requires SPF, DKIM, and DMARC from domains sending 5,000+ emails per day, rejecting non-compliant mail outright at the SMTP level with error 550 5.7.515. — Microsoft Outlook requirements (via MailOver bulk-sender requirements guide) (2025)
- The number of top domains at DMARC enforcement grew from 233,249 in 2023 to 411,935 in 2026 — a 77% increase driven largely by mailbox-provider sender mandates. — EasyDMARC 2026 DMARC Adoption & Enforcement Report (2026)
Keep reading
- Email authentication: SPF, DKIM, DMARC, BIMI and MTA-STS (complete guide)
- DNS Provider Uptime and Email Deliverability Performance in 2026
- Troubleshooting DNS Errors on Mailchimp App Domain for Verification
- Klaviyo Sender Authentication to Improve Inbox Placement in 2026
- Best DNS Records for Mailgun Sending Domain Setup in 2026
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
Can I use Mailgun without SPF and DKIM?
No. While Mailgun may accept your messages, most major inbox providers will reject or mark them as spam without proper SPF and DKIM setup.
How many SPF records should I have?
Only one SPF record per domain. Multiple records break SPF validation and cause delivery failures.
What’s the difference between SPF and DKIM?
SPF verifies the sending server’s IP address; DKIM verifies the email’s content and headers using digital signatures.
Can DKIM signatures be forged?
No—because DKIM uses cryptographic keys. If the signature doesn’t match the public key in DNS, the email is rejected.
How long does it take for SPF/DKIM to take effect?
DNS changes typically propagate within 10 minutes to 24 hours, depending on TTL settings and DNS provider caches.
Does Mailgun support DMARC?
Yes—Mailgun supports DMARC, but you must set it up yourself via DNS. DMARC builds on SPF and DKIM to enforce policies.
Can I verify SPF and DKIM with a free tool?
Yes—tools like MxToolbox and Mail-tester.com offer free checks. However, MailTester provides deeper inbox-placement feedback.
Why does my email show SPF pass but DKIM fail?
This usually means the sending server is authorized (SPF), but the email signature wasn’t properly generated or is mismatched in DNS.
Do I need different SPF/DKIM for each Mailgun subdomain?
If you send from multiple subdomains (e.g. marketing.mailgun.com and support.mailgun.com), each needs its own SPF and DKIM configuration.
Can a catch-all email affect SPF or DKIM validation?
Catch-all domains don’t break SPF or DKIM directly, but they indicate poor list hygiene and increase the risk of spam traps and bounces.
How often should I test my SPF and DKIM?
After every DNS change, and at least once a month during active campaigns to ensure consistency.
Do disposable email domains affect SPF/DKIM?
Disposable domains don’t participate in SPF or DKIM validation, and they often have poor deliverability—avoid them in campaigns.