Mailgun: SPF, DKIM & DMARC Setup Guide
Mailgun's developer API is powerful, but domain verification is required before you can send. Here's exactly which DNS records to add for full SPF, DKIM, and DMARC authentication.
1SPF Record Setup
Recommended SPF record for Mailgun:
v=spf1 include:mailgun.org ~allMailgun also supports custom MAIL FROM domains, which enables SPF alignment with your From: header domain. This is recommended for DMARC compliance. Without it, Mailgun sends from a mailgun.org subdomain.
Step-by-step setup:
- 1In Mailgun, go to Sending → Domains → your domain → Domain Verification
- 2Mailgun provides TXT records for SPF and DKIM
- 3Add the SPF TXT record to your root domain
- 4For custom MAIL FROM: add the provided MX record to your subdomain (e.g., mg.yourdomain.com)
- 5Add the TXT SPF record for the subdomain: v=spf1 include:mailgun.org ~all
- 6Verify in Mailgun and check with our SPF checker
2DKIM Setup
Example DKIM record location:
mailo._domainkey.yourdomain.comMailgun generates a 1024-bit or 2048-bit RSA key pair. The selector is typically 'mailo' or a custom name. Mailgun provides the full TXT record value to publish.
Step-by-step setup:
- 1In Mailgun domain settings, find the DKIM TXT record
- 2Copy the full value and add as a TXT record at [selector]._domainkey.yourdomain.com
- 3The selector and full TXT value are provided in the Mailgun dashboard
- 4Wait 24–48 hours for propagation
- 5Verify in Mailgun — domain status should show Active
- 6Test with our DKIM checker
3DMARC Policy
Recommended DMARC record:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100Add as a TXT record at: _dmarc.yourdomain.com
With DKIM authentication configured, DMARC will pass via DKIM alignment. If you also set up a custom MAIL FROM, SPF alignment will also pass. Publish your DMARC record at _dmarc.yourdomain.com.
Common Mailgun Deliverability Issues
Domain stuck in 'Unverified' state in Mailgun
Double-check that TXT records were saved correctly. DNS propagation can take up to 48 hours. Use our DNS Lookup tool to verify the records are publicly visible before clicking Verify in Mailgun.
Emails sent via Mailgun rejected with DMARC failure
Ensure DKIM is verified in Mailgun. Check that the d= domain in the DKIM signature matches your From: header domain. Consider setting up a custom MAIL FROM for SPF alignment too.
Mailgun free tier rate limits causing delivery issues
Mailgun's free tier is limited to 100 emails/day. For production use, upgrade to a paid plan. Check your account's sending limits in the Mailgun dashboard.
Is Your Mailgun Domain Blacklisted?
Authentication passing is necessary — but not sufficient. Check if your sending domain or IP is on any of 60 blacklists. Free, instant, no signup.
Check Your Domain FreeChecks all 60 blacklists + SPF, DKIM, DMARC, MX in under 10 seconds