Subdomain Delegation for Mailgun Dedicated Sending Domain
Learn how to correctly delegate a subdomain to Mailgun for dedicated sending. Avoid bounces, improve deliverability, and verify your setup with real-time.
Why Subdomain Delegation Matters for Mailgun Sending Domains
You’re using Mailgun to send transactional and marketing emails. Your open rates are steady. But then one day, a batch lands in spam, or worse—gets blocked entirely. No warning. No clear reason. You’re left guessing.
One overlooked setup step could be the root cause: not delegating a subdomain for your Mailgun sending domain. Without it, you're treating your email infrastructure like a shared apartment with no locks—any misstep on one side can shut down the whole building.
Proper subdomain delegation isn’t just about DNS syntax—it’s about protecting your sender reputation, ensuring consistent inbox placement, and letting Mailgun authenticate your emails correctly. It’s the quiet foundation of deliverability.
Key takeaways
- Delegating a subdomain isolates Mailgun’s sending volume from your primary domain, preventing sender reputation issues.
- Without delegation, DNS resolution failures can cause rejection or spam filtering of Mailgun-sent emails.
- Correct delegation enables SPF, DKIM, and DMARC to authenticate outbound messages, directly improving inbox placement.
What Happens When You Don’t Delegate a Subdomain Correctly?
If you don’t delegate your subdomain properly for Mailgun, your emails won’t pass authentication checks. Mailgun can’t prove it’s authorized to send on your behalf, so major providers like Gmail or Outlook will reject the messages or flag them as spam. Even if DKIM signs the email, missing or incorrect DNS records for the subdomain can cause 100% delivery failure.
Authentication Fails at the Root
When Mailgun sends from a subdomain like mail.yourdomain.com, it relies on your DNS setup to confirm authorization. Without a correctly configured SPF record pointing to Mailgun’s IP ranges, or a missing CNAME for subdomain delegation, email receivers have no way to verify the sender’s legitimacy. This breaks the trust chain, even if the content is clean.
Spam filters don’t just look at content — they trace the email back to the domain’s DNS. If the subdomain isn't properly delegated, the message lacks a verifiable origin. This commonly triggers filters used by providers like Yahoo and Outlook, which rely heavily on sender reputation and alignment signals from DNS records.
Even DKIM Isn’t Enough Without Proper Delegation
DKIM is strong, but it only validates the domain of the signing entity. If your subdomain is not correctly delegated, the receiving mail server will see that the signing domain doesn’t match the sender’s domain as it’s validated through DNS. This mismatch can result in rejection, even with valid cryptographic signatures.
Let’s say you set up DKIM for mail.yourdomain.com but forget to create the required CNAME record pointing to Mailgun. The signature validates, but the server can’t confirm Mailgun is authorized to use that subdomain. The system sees this as a potential forgery, and delivery fails. In practice, this means no email lands in the inbox.
Mailgun’s documentation and tools like bulk verification help you catch configuration issues before deployment. But DNS isn’t a one-time fix — it’s a foundation. Misconfigured delegations can silently block thousands of messages, especially in high-volume campaigns.
For a deeper technical reference, the SPF specification outlines how sender authorization works. It’s built on the idea that every sending domain must explicitly authorize its senders. If the subdomain lacks delegation, you’re bypassing that mechanism entirely.
How Mailgun Subdomain Delegation Works: The Core Mechanics
You create a subdomain like mail.yourcompany.com, then configure DNS records to let Mailgun handle email delivery and receipt for that domain. This includes setting an MX record to route incoming mail to Mailgun’s servers, adding an SPF record to authorize Mailgun to send on your behalf, and publishing a DKIM key to verify message authenticity. These steps let you send emails using a custom domain while Mailgun handles infrastructure, routing, and reputation management.
Set Up the Subdomain Infrastructure
- Register a subdomain with your DNS provider. Choose a name like mail.yourcompany.com. This becomes your dedicated sending domain, isolated from your main domain’s email traffic.
- Point inbound mail using MX records. Add an MX record for the subdomain that routes incoming mail to Mailgun’s inbound servers. Without this, emails sent to your subdomain won’t arrive.
- Authorise sending with SPF. Add a TXT record with the policy
v=spf1 include:mailgun.org -all. This tells receiving servers that Mailgun is allowed to send emails on your behalf. Without it, your messages risk being flagged as spam. - Verify authenticity with DKIM. Generate a DKIM key in your Mailgun dashboard. Publish it as a TXT record under the subdomain. This cryptographically proves that messages sent from your subdomain weren't altered in transit.
Why the Setup Matters
Each DNS record plays a specific role in email trust. MX ensures incoming mail reaches your system. SPF and DKIM are fundamental to sender reputation and inbox placement. Major providers like Gmail and Outlook inspect these records before delivering your message.
When you don’t configure them correctly, you risk delivery failure, spam filtering, or blacklisting. Even a single missing record can result in 30–50% lower inbox placement, depending on the recipient’s filtering policies.
Mailgun handles the technical details of delivery and reputation, but you must get the DNS setup right. A misconfigured SPF policy may trigger false positives. A missing DKIM key can cause emails to fail authentication checks. These are not minor issues — they directly impact whether a message reaches the inbox.
For teams managing email volumes, it’s worth validating the entire setup before full rollout. You can test deliverability using a real inbox tester or verify your DNS records with tools like MxToolbox or RFC 7208. It's faster to catch errors early than to debug high-volume failure patterns later.
Before sending to a large audience, check your verification setup with tools like MailTester’s inbox placement tester to ensure your domain configuration aligns with modern recipient standards.
Common DNS Configuration Mistakes to Avoid
You’re setting up a dedicated sending domain in Mailgun, but your messages are bouncing or landing in spam? Chances are your DNS setup isn’t quite right. The most frequent culprits are misconfigured SPF, using your main domain instead of a subdomain, splitting SPF records, or delaying DKIM setup. Fix these early—and you’ll avoid inbox placement issues before they start.
SPF and DKIM: The Two-Pronged Authentication System
- Don’t forget to update your SPF record to include
include:mailgun.org—omitting this breaks SPF alignment and can mark your messages as unauthenticated. - Never use your primary domain (e.g., yourcompany.com) for Mailgun sending. Doing so exposes your brand’s main domain to reputation risk if Mailgun’s sender reputation dips.
- Never split SPF records across multiple TXT entries. Multiple SPF records trigger evaluation failures. Combine all your SPF policies into one TXT record using
v=spf1 include:mailgun.org -all. - Wait until DKIM is published before sending email. If you enable SPF first and delay DKIM, your messages may still be marked as unauthenticated by receiving servers, harming deliverability.
Why These Errors Matter in Practice
SPF and DKIM are not optional—both are required for consistent inbox placement. According to the IETF’s RFC 7208, SPF records must be evaluated as a single, cumulative policy. Splitting them defeats the purpose and often results in a “soft fail.”
DNS errors like these don’t just cause bounces—they hurt sender reputation. A single misconfigured record can lead to throttling or outright blocking by providers like Gmail or Outlook.
Let’s say you send 10,000 emails. A flawed SPF setup might trigger a 5% to 15% bounce rate during first delivery. That’s not just wasted sends—it’s lost trust with your recipients. And once a domain is flagged, recovery takes time.
Using a dedicated subdomain (e.g. mail.yourcompany.com) isolates Mailgun’s sending behavior from your primary domain. If your Mailgun sending volume spikes and triggers temporary filters, it won’t impact your brand’s core domain reputation.
Want to verify your DNS setup before sending? Check your address pool for invalid, risky, or catch-all emails with MailTester’s email checker—ensuring your list is clean before DNS configuration even begins.
How to Verify Your Subdomain Setup Is Working
Use DNS lookup tools to confirm your MX, SPF, and DKIM records are published correctly, send a test email through Mailgun and inspect the headers for SPF pass and DKIM signature, then verify an email address with a trusted service like MailTester’s real-time API before sending. If anything fails, double-check for typos in your DNS records, especially in the subdomain name or include directives.
- Check your DNS records using a tool like MxToolbox — enter your subdomain and verify that the MX, SPF, and DKIM records appear as expected. Misconfigurations here are the most common cause of deliverability issues. Use MxToolbox to validate real-time record propagation across DNS resolvers.
- Send a test message through Mailgun using your subdomain — use a known inbox to send one message from your dedicated sending domain. Then, open the message’s full headers (in Gmail, click the three dots > “Show original”) and look for two key indicators:
SPF passand a validDKIM signature. Absence of either means authentication failed. - Validate individual addresses with MailTester’s real-time API — before sending to lists, test a single email address to confirm it’s valid and actively receiving messages. This catches disposable or role accounts early, reducing bounce rates and protecting sender reputation. Try it at MailTester’s real-time API to automate this.
- Review your DNS setup if a test fails — common issues include missing trailing dots in TXT records, incorrect subdomain names (e.g.,
mailvsmailgun), or errors ininclude:directives. A single character mistake breaks authentication.
What to watch for in SPF and DKIM records
SPF records must include the correct IP range or include directive (like include:mailgun.org). DKIM requires a specific selector and public key published in a TXT record. Both must be exact — even a misplaced space or incorrect case fails verification.
Use an inbox placement tool for final validation
Even with correct DNS and passing headers, your messages may still land in spam. Use a service like MailTester’s inbox placement tester to simulate delivery across major providers and see where your sent message lands.
These steps aren’t optional. They’re the only way to ensure your subdomain is fully trusted. Skipping any of them means sending blind — and that’s a risk you cannot afford in production.
How Email Verification Prevents Delivery Failures After Delegation
Even after correctly delegating a subdomain to Mailgun, sending to invalid, catch-all, or role-based email addresses still causes bounces, degrades sender reputation, and harms deliverability. MailTester’s bulk verification catches these issues before they reach Mailgun, reducing bounce rates and protecting your domain’s standing. With 98.9% accuracy, you can trust the results to clean your list before integration.
Why Verified Addresses Matter Post-Delegation
You might have set up your subdomain perfectly — SPF, DKIM, DMARC all in place — but that doesn’t guarantee every recipient will accept mail. Invalid addresses bounce immediately. Catch-all domains accept all messages, leading to soft bounces and flagged senders. Role addresses (like admin@ or support@) often end up in spam folders or go unread, hurting engagement metrics. All of these undermine sender reputation, which Mailgun and inbox providers monitor closely.
Let’s be clear: DNS alignment is just one piece of the puzzle. Sender reputation is built on consistent engagement and low bounce rates. Sending to known bad addresses — even if the domain is valid — can trigger rate limits or blocklists. Industry reports from Return Path and MxToolbox highlight that lists with even 2% invalid addresses see measurable declines in inbox placement over time. You don’t need to get that close to the danger zone.
How MailTester Stops Issues Before They Start
MailTester runs a multi-layer check on every address: it validates syntax, probes MX records, checks for disposable domains, identifies catch-alls, and detects role-based or high-risk addresses. You’re not just checking if an email exists — you’re assessing whether it’s likely to receive, open, and engage without friction.
With 98.9% accuracy across millions of checks, MailTester gives you confidence in results. The data is not just fast — it’s trustworthy. That means you can confidently remove invalid and risky entries from lists before sending through Mailgun, whether you're running a newsletter or transactional flows.
Once you’ve cleaned your list, integrate MailTester via API or directly with your CRM or email service. Tools like Mailchimp, HubSpot, Klaviyo, and SendGrid all support pre-send verification. You can also test inbox placement with a real email campaign using MailTester’s built-in inbox tester. This gives you measurable proof of deliverability before going live.
See how it works: verify your entire campaign list or use the real-time API to validate addresses as they’re added. Even a single bad email can hurt more than you expect. Prevention isn’t optional — it’s required for consistent, reliable deliverability.
The Real Impact of Sender Reputation on Mailgun Deliverability
Even with flawless DNS setup, your Mailgun messages won’t land in inboxes if your sender reputation is weak. Providers like Gmail and Outlook track bounce rates, spam complaints, and list hygiene — not just your SPF/DKIM/DMARC alignment. A single bad email list can hurt your deliverability for weeks.
Bounce Rates and Provider Warnings
Any bounce rate above 0.5% signals a problem. High soft or hard bounces trigger automatic alerts from email providers. You may not see them in your Mailgun dashboard, but they’re being logged and factored into your reputation score. A consistent 1% bounce rate, for example, raises flags even if your infrastructure is perfect.
When Mailgun sends to a list with unverified addresses, some destinations assume deliberate spamming. This is why sender reputation isn’t just about headers — it’s about who you send to, how often, and how clean your data is. A reputation penalty can take months to recover from.
Preventing Reputation Damage with Proactive List Cleanup
Let’s be honest: many email lists accumulate dead, role-based, or disposable addresses over time. These aren’t just waste — they actively harm your deliverability. Addresses like admin@, sales@, or temp-mail domains may not bounce, but they’re high-risk. Providers flag senders who consistently contact these accounts as spammers.
That’s where tools like MailTester help. With a bulk verification, you can detect and remove role accounts, expired domains, and disposable addresses before they get sent. Real-time verification via the API ensures new signups are clean — no cleanup needed later.
Spam traps are another hidden threat. These are old, abandoned addresses that now act as canaries in the coal mine. If you accidentally send to one, even once, your reputation takes a hit. Regular list verification reduces exposure to these traps and helps avoid long-term blacklisting.
Remember: Mailgun’s sending infrastructure is sound by default. The real vulnerability is your list. You can configure all the DNS records perfectly, but if you’re sending to a poorly maintained list, your reputation will suffer — and providers like Gmail will notice.
DMARC Enforcement: The Final Layer for Subdomain Protection
Setting a DMARC policy on your primary domain is the final step that ensures emails sent via your Mailgun subdomain are properly authenticated, even if SPF or DKIM checks fail. Without it, spam filters may silently reject messages, breaking deliverability. DMARC gives receiving servers clear instructions—like quarantining or rejecting failed emails—and gives you visibility through reports to catch issues early.
How to configure DMARC for your Mailgun subdomain
- Add a DMARC DNS record to your primary domain. Use a policy like
v=DMARC1; p=quarantine; rua=mailto:[email protected]. This tells receivers how to handle emails that fail SPF or DKIM, even when sent through a delegated subdomain likemail.yourcompany.com. - Ensure your subdomain’s SPF includes the delegate. If you’ve set up
mail.yourcompany.comto use Mailgun’s sending infrastructure, your main domain’s SPF record must explicitly allow Mailgun’s IP ranges viainclude:_spf.mailgun.org. SPF alone isn’t enough—DMARC validates the full chain. - Monitor DMARC reports via your postmaster mailbox. Receiving servers send aggregate reports to the
ruaaddress you specify. These reports show which emails passed or failed, and help you detect misconfigurations in time. - Verify alignment with DKIM and SPF. DMARC checks alignment. If your DKIM signature uses
mail.yourcompany.combut theFromheader is[email protected], alignment fails. Use consistent domains across headers and signatures. - Test your setup with inbox placement tools. Use tools like inbox placement testing to see if DMARC-protected emails land in inboxes. A failed test often reveals overlooked alignment or policy issues.
Why skipping DMARC leaves you exposed
Without DMARC, your subdomain might appear correctly configured, but messages still fail silently in filters. Recipients don’t see bounces, but inboxes remain empty. According to RFC 7483, DMARC’s purpose is to protect domains from spoofing and ensure that authentication results are acted upon. It’s not optional when you delegate sending responsibility.
Even if your Mailgun subdomain passes SPF and DKIM, poor alignment, weak policies, or reporting gaps leave deliverability fragile. Let’s say a forged email from [email protected] uses your subdomain—without DMARC, it may slip through. With DMARC, it gets quarantined or rejected.
For ongoing checks, you can validate that your domain’s authentication stack holds up using MailTester’s email checker before sending campaigns. It flags common problems like missing or misaligned records.
Why You Shouldn’t Skip DNS Verification Before Sending
You should never assume your DNS changes are live just because you’ve added the TXT record. Propagation delays can take up to 72 hours, depending on your DNS provider and TTL settings. Sending emails before verification risks bounces, poor deliverability, and reputational harm. Always confirm your records are visible to the public before testing.
DNS Propagation Isn't Instant — And It Varies
- Setting a TXT record doesn’t mean it’s immediately available globally. DNS changes propagate at different rates, from as fast as 5 minutes to as slow as 72 hours.
- Propagation speed depends on how your domain’s TTL (Time to Live) is configured and your DNS provider’s caching behavior.
- Some providers, like Cloudflare or AWS Route 53, propagate changes quickly—others take longer due to conservative caching policies.
Verify Before You Send: A Step-by-Step Check
- Use a public DNS lookup tool like MXToolbox or DNSChecker.org to confirm your TXT record appears worldwide.
- Check multiple locations (e.g., different regions or ISPs) to rule out localized caching.
- Do not depend solely on your internal DNS tools — they may show the record locally while it’s invisible externally.
- Let’s be clear: if the record isn’t visible across the internet, your Mailgun domain isn’t ready for sending.
Once your DNS changes are confirmed, run a real-time inbox-placement test to simulate delivery across Gmail, Outlook, Apple Mail, and others. Use MailTester’s inbox-placement test to see exactly where your mail lands—inbox, spam, or junk—before you send to real users.
The Best Practice: Combine Subdomain Delegation with List Hygiene
Delegating a subdomain for Mailgun isn’t just about technical setup—it’s about proving you’re a legitimate sender. But even with perfect DNS config, your emails won’t land in inboxes if your list contains invalid, disposable, or catch-all addresses. Clean data paired with correct delegation is the only path to consistent inbox placement.
Delegation Handles the How, Hygiene Handles the Why
Subdomain delegation proves to email providers that you control the sending domain. It’s a foundational step, but it doesn’t guarantee deliverability on its own. You still need to earn trust, and that starts with your list. Sending to addresses that don’t exist, or can’t receive mail, generates bounces and triggers spam filters.
Let’s be clear: catch-all domains accept all messages, so they’re often used by spammers. Delivering to them can hurt your sender reputation. Disposable email domains are usually short-lived and designed to avoid engagement. They’re a red flag for providers like Gmail or Outlook.
Verify Before You Send—Especially at Scale
With high-volume campaigns, even a 1% error rate means hundreds of bad addresses. Every one of them hurts deliverability. That’s why you should use a tool like MailTester’s bulk verification to scan your entire list before sending through Mailgun.
It checks for syntax, domain existence, mailbox responsiveness, and flags risky addresses—including catch-alls and disposable domains—before you even begin. This isn’t theory. According to Spamhaus, domains with high proportions of invalid or disposable email addresses are frequently blacklisted.
Use the MailTester API to automate checks in real time, especially if you’re syncing data from forms or third-party sources. You’re not just avoiding bounces—you’re protecting your sending reputation.
Final note: there is no shortcut. A well-delegated subdomain without a clean list is a signal of poor sender hygiene. A clean list without proper delegation is ignored by systems that validate sender legitimacy. Only the combination works.
Conclusion: Trust Your Setup, Verify the Output
Delegating your subdomain for Mailgun dedicated sending requires more than just setting DNS records. You must include mailgun.org in your SPF, publish valid MX and DKIM records, and enforce DMARC to establish sender authenticity.
DNS changes take time to propagate. Never assume they’re live—use public tools like MxToolbox or dig to confirm the records are correctly published before sending.
Even with a properly configured domain, your message only reaches the inbox if your list is clean. Use MailTester’s bulk or real-time API to filter out invalid, risky, or disposable addresses before deployment.
Sources
- Since May 5, 2025, Microsoft Outlook requires SPF, DKIM, and DMARC from domains sending 5,000+ emails per day, rejecting non-compliant mail outright at the SMTP level with error 550 5.7.515. — Microsoft Outlook requirements (via MailOver bulk-sender requirements guide) (2025)
- Sending from a domain with at least three months of history improves inbox placement by 28% compared with a brand-new domain. — Woodpecker data (via WarmForge deliverability statistics) (2025)
Keep reading
- Deliverability testing inside your ESP, CRM and sending platform (complete guide)
- Configure Subdomain Delegation for AWS SES Sending Domain
- How to Verify Domain Ownership in SendGrid for Cold Email Campaigns
- Fixing Email Verification Service Integration with Mailchimp Auth Issues
- Using SendGrid or Mailgun from Kubernetes Without Sidecar
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
Can I use my main domain instead of a subdomain for Mailgun?
You can, but it exposes your primary domain to reputation risk. Using a subdomain isolates Mailgun’s sending profile and improves inbox placement.
Does Mailgun require SPF, DKIM, and DMARC for sending?
Yes. These records are required for authentication. Without them, messages are likely rejected or marked as spam.
How long does it take for DNS changes to propagate?
Typically 5 minutes to 48 hours, depending on TTL settings and DNS provider. Always verify propagation before sending.
Can I use MailTester with Mailgun?
Yes. MailTester integrates with Mailgun workflows to verify lists before send, reducing bounces and improving deliverability.
What does 'catch-all' mean in email verification?
A catch-all domain accepts all incoming messages, even to invalid addresses. These are often disposable or risky and should be removed from your list.
Why do some emails fail SPF even with mailgun.org in the record?
Common causes include multiple SPF records, missing include directive, or incorrect subdomain in the record. Double-check the full SPF policy.
How does DKIM affect Mailgun delivery?
DKIM signs each email. If the signature doesn’t match, providers reject the message. Ensure the DKIM key is published as a TXT record.
Can a disposable email address harm my sender reputation?
Yes. If you send to disposable addresses, you’ll get hard bounces or no delivery at all — both harm reputation and increase spam complaints.
Do I need DMARC if I’m using a subdomain?
Yes. DMARC ensures the sender is authorized and provides visibility into failed authentication attempts, even across subdomains.
How accurate is MailTester’s email verification?
MailTester achieves 98.9% accuracy across all verdict types – valid, invalid, catch-all, and risky – using real-time checks and verified data.