Send from your own domain — with full email authentication
Custom email domains with SPF, DKIM, and DMARC authentication are the single biggest factor in email deliverability. Pingovo makes the setup effortless.
- SPFsender authorised
- DKIM2048-bit signed
- DMARCp=quarantine
- BounceCNAME routed
4
DNS records auto-generated
<10 min
average domain setup time
SPF + DKIM + DMARC
full authentication
∞
domains per account
You do not need a separate DKIM generator or DMARC record generator to get started. Add your domain and Pingovo produces every value for you — an SPF record listing the IPs that may send as you, a 2048-bit DKIM key pair whose public half is printed as a ready-to-paste TXT record, a DMARC record already set to p=quarantine with a reporting address, and a CNAME that routes bounces back through your own domain. Paste them at your DNS host, then let Pingovo re-check them until they all read verified.
Your DNS records — generated automatically by Pingovo
Everything included with custom domains
SPF, DKIM & DMARC auto-setup
Pingovo generates the exact DNS records you need — all four, including the bounce CNAME — and verifies them automatically. No guesswork.
Branded from address
Send from your own domain — [email protected] — instead of a shared platform domain.
Better inbox placement
Authenticated custom domains consistently achieve higher deliverability rates than shared senders.
DMARC enforcement
Prevent spoofing of your domain with DMARC policy enforcement and weekly aggregate reports.
Build domain reputation
Your sending reputation stays attached to your domain, not a shared IP pool.
Verification in minutes
Pingovo checks your DNS records and marks your domain as verified within minutes of setup.
Get your domain authenticated in 4 steps
Enter your domain
Type in the domain or subdomain you want to use for sending, e.g. mail.yourcompany.com.
Add DNS records
Pingovo generates SPF, DKIM, and DMARC records. Add them to your DNS provider.
Verify authentication
Click "Verify" — Pingovo checks all records live and confirms your domain is authenticated.
Start sending
Your domain is now active. Select it as the sending domain for any campaign.
What each record does — and what breaks without it
SPF, DKIM and DMARC are three separate promises about the same message, and a DKIM generator or DMARC record generator only hands you the text. What matters is which promise each one makes, because that is what decides how a receiving server treats mail that fails it.
SPF
TXTyour domain, at the rootLists who is allowed to send mail carrying your domain. A receiver looks it up and checks the connecting server against it.
Without it: Mail from your domain arrives unauthenticated and is far more likely to be filtered — and anyone can forge your From address without contradiction.
DKIM
TXTpk1-xxxxxxxx._domainkeyPublishes the public half of a 2048-bit RSA key pair. Pingovo signs every message with the private half; the receiver verifies the signature against this record.
Without it: Nothing proves the message body left your domain untampered, and DMARC has only SPF to align against.
DMARC
TXT_dmarcTells receivers what to do when SPF and DKIM fail, and where to send the aggregate reports. Pingovo generates it at p=quarantine with a reporting address already filled in.
Without it: Receivers decide for themselves what a failure means, you get no reporting, and Gmail and Yahoo treat bulk senders without a DMARC policy as a deliverability risk.
Bounce
CNAMEpgbouncePoints a subdomain of your own domain at the Pingovo bounce host, so delivery failures return through your domain instead of a shared one.
Without it: The domain a receiver scores in the SMTP transaction is a Pingovo one rather than yours — and the domain is not marked verified.
None of these replaces your MX records. MX says where mail addressed to your domain should be delivered, and it stays pointed at whoever hosts your mailboxes — Google Workspace, Microsoft 365, or anyone else. Authenticating a sending domain with Pingovo touches only the records above, so your inbound mail is unaffected throughout.
Adding the records at your registrar
The values Pingovo generates are the same wherever you host DNS. What differs is how each control panel wants the host field written, and that is where most failed verifications come from — a record published one level too deep, at _dmarc.example.com.example.com, resolves to nothing.
GoDaddy. Use @ for the root domain when adding the SPF TXT record, and the sub-part only for the others — _dmarc, not _dmarc.yourdomain.com. GoDaddy appends the domain for you.
Cloudflare. Enter the full name; Cloudflare normalises it either way. Leave TXT and CNAME records DNS-only — proxying a CNAME through the orange cloud rewrites what resolvers see and the check fails.
Google Workspace / Google Domains. Host names are entered without the domain suffix. Adding an SPF record here does not change your MX records, which stay pointed at Google for inbound mail.
Namecheap, Hostinger and most cPanel hosts. Use @ for the root and the bare sub-part elsewhere. Set TTL to the lowest offered while you are setting up, so a correction takes minutes to take effect instead of hours.
One more rule catches people out: a domain may carry only one SPF record. If you already publish an SPF record for Google Workspace or Microsoft 365, do not add a second — merge Pingovo's include: into the record you already have. Two SPF records on one domain is a permanent error, and receivers treat it as no SPF at all. DKIM and the bounce CNAME have no such limit, because each one lives at its own hostname.
Verified once is not verified forever
DNS drifts. A record gets tidied up during a migration, a registrar change drops a TXT entry, someone replaces an SPF record instead of merging into it. Pingovo re-checks each record rather than trusting the tick it gave you on setup day, and a domain is only verified when every record passes — anything less is partial, and says which record is missing.
- Four states, not two: pending, partial, verified, failed
- Each record carries its own pass/fail and the time it was last looked up
- Re-check on demand — publish a fix and confirm it without waiting for a sweep
- If your sending setup changes, the domain is flagged for re-authentication rather than left silently wrong
- SPFchecked 2 min ago
- DKIMchecked 2 min ago
- DMARCchecked 2 min ago
- Bounce CNAMEno record found
Frequently asked questions
Four: an SPF TXT record, a DKIM TXT record, a DMARC TXT record, and a CNAME at pgbounce that routes delivery failures back through your own domain. The dashboard prints the exact values to copy-paste into your DNS provider and marks each one verified or not as it re-checks them — no guesswork.
No. MX records control where mail addressed to your domain is delivered, and they stay pointed at whoever hosts your mailboxes. Authenticating a sending domain only adds the SPF, DKIM and DMARC TXT records plus the bounce CNAME, none of which affect inbound mail.
No — a domain may publish only one SPF record, and two is a permanent error that receivers treat as having no SPF at all. Merge Pingovo's include: mechanism into your existing record rather than creating another TXT record alongside it.
No. Adding the domain generates a 2048-bit RSA key pair and prints the public half as a ready-to-paste DKIM TXT record, and produces a DMARC record already set to p=quarantine with a reporting address and failure reporting enabled. The private key is encrypted at rest and never leaves Pingovo.
Once you add the records, click Verify in the Pingovo dashboard. In most cases, records are verified within minutes. In rare cases where DNS propagation is slow, it can take up to 24 hours.
Yes, and this is often recommended. Using a sending subdomain like mail.yourcompany.com keeps your main domain's reputation isolated, so any deliverability issues from email sending don't affect your website's domain.
No — you can send using Pingovo's shared infrastructure without any domain setup. But custom domains significantly improve deliverability and make your From address look professional ([email protected] vs. a shared platform address).
Start for free
Connect your custom domain, then add credits or a plan to start sending authenticated email.