Understanding Mailgun (Sinch) Email Authentication
Mailgun provides robust transactional email APIs. Mailgun recommends sending from a dedicated subdomain (e.g. mg.yourdomain.com) with SPF and DKIM.
When Mailgun (Sinch) delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Mailgun (Sinch)'s IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.
Required DNS Records for Mailgun
Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):
| Type | Host / Name | Value / Target | TTL | Purpose |
|---|---|---|---|---|
| TXT | @ | v=spf1 include:mailgun.org ~all | 3600 | Mailgun SPF. |
Step-by-Step Setup Instructions
In Mailgun > Sending > Domains > Add New Domain.
Add the TXT SPF record: "v=spf1 include:mailgun.org ~all".
Add the DKIM TXT record at "k1._domainkey.yourdomain.com".
Add Mailgun MX records and click Verify.
Common Mailgun SPF Configuration Mistakes
× Mailgun Verification Yellow Warning
Cause: DNS propagation latency.
Fix: Wait 10 minutes and click Check DNS Records.
Frequently Asked Questions
What is the SPF include for Mailgun?
Use "include:mailgun.org".
Should I send from the root domain or a subdomain with Mailgun?
Mailgun recommends using a dedicated subdomain (e.g. mg.yourdomain.com or mail.yourdomain.com) rather than your root domain. This separates transactional sender reputation from corporate inbox deliverability and avoids MX record conflicts with your business email provider.
What DKIM records does Mailgun generate?
Mailgun provides a 2048-bit RSA TXT DKIM record, typically at the selector k1 or smtp. The record is published at k1._domainkey.yourdomain.com (or k1._domainkey.mg.yourdomain.com if using a subdomain). Mailgun also provides an MX record for bounce handling.
What is the Mailgun Tracking CNAME and is it required?
Mailgun offers an optional tracking CNAME (e.g. email.yourdomain.com pointing to mailgun.org) to white-label click and open tracking links. This is not required for SPF/DKIM/DMARC authentication but removes the mailgun.org domain from tracking URLs in emails.
Why does Mailgun verification show a yellow warning even after I add DNS records?
DNS propagation can take up to 48 hours. Mailgun's verification system polls your DNS records in real time. If you've recently added records, wait 10-30 minutes and click "Check DNS Records" again in the Mailgun dashboard.
Does Mailgun support dedicated IPs for high-volume senders?
Yes. Mailgun offers dedicated sending IPs on higher-tier plans. With a dedicated IP, you own your sender reputation exclusively. Add the dedicated IP using ip4: in your SPF record alongside include:mailgun.org for complete SPF coverage.