Official DNS Guide • Developer Email API & Relay

Mailgun (Sinch) SPF Record Setup & Validator

Step-by-step Mailgun SPF setup (include:mailgun.org), 2048-bit DKIM TXT keys (k1._domainkey), and custom subdomain routing.

Quick Answer • Exact Mailgun SPF Syntax

To authorize Mailgun (Sinch) to send emails on behalf of your domain, add include:mailgun.org to your domain's single DNS TXT SPF record before the terminating ~all mechanism. The standard record is v=spf1 include:mailgun.org ~all.

Live Mailgun DNS Validator

Test your domain's published SPF, DKIM, and DMARC records via global DoH edge nodes in real time.

Zero-Log Client Evaluation

Understanding Mailgun (Sinch) Email Authentication

Mailgun provides robust transactional email APIs. Mailgun recommends sending from a dedicated subdomain (e.g. mg.yourdomain.com) with SPF and DKIM.

When Mailgun (Sinch) delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Mailgun (Sinch)'s IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.

Required DNS Records for Mailgun

Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):

TypeHost / NameValue / TargetTTLPurpose
TXT@v=spf1 include:mailgun.org ~all3600Mailgun SPF.

Step-by-Step Setup Instructions

1

In Mailgun > Sending > Domains > Add New Domain.

2

Add the TXT SPF record: "v=spf1 include:mailgun.org ~all".

3

Add the DKIM TXT record at "k1._domainkey.yourdomain.com".

4

Add Mailgun MX records and click Verify.

Common Mailgun SPF Configuration Mistakes

× Mailgun Verification Yellow Warning

Cause: DNS propagation latency.

Fix: Wait 10 minutes and click Check DNS Records.

Frequently Asked Questions

What is the SPF include for Mailgun?

Use "include:mailgun.org".

Should I send from the root domain or a subdomain with Mailgun?

Mailgun recommends using a dedicated subdomain (e.g. mg.yourdomain.com or mail.yourdomain.com) rather than your root domain. This separates transactional sender reputation from corporate inbox deliverability and avoids MX record conflicts with your business email provider.

What DKIM records does Mailgun generate?

Mailgun provides a 2048-bit RSA TXT DKIM record, typically at the selector k1 or smtp. The record is published at k1._domainkey.yourdomain.com (or k1._domainkey.mg.yourdomain.com if using a subdomain). Mailgun also provides an MX record for bounce handling.

What is the Mailgun Tracking CNAME and is it required?

Mailgun offers an optional tracking CNAME (e.g. email.yourdomain.com pointing to mailgun.org) to white-label click and open tracking links. This is not required for SPF/DKIM/DMARC authentication but removes the mailgun.org domain from tracking URLs in emails.

Why does Mailgun verification show a yellow warning even after I add DNS records?

DNS propagation can take up to 48 hours. Mailgun's verification system polls your DNS records in real time. If you've recently added records, wait 10-30 minutes and click "Check DNS Records" again in the Mailgun dashboard.

Does Mailgun support dedicated IPs for high-volume senders?

Yes. Mailgun offers dedicated sending IPs on higher-tier plans. With a dedicated IP, you own your sender reputation exclusively. Add the dedicated IP using ip4: in your SPF record alongside include:mailgun.org for complete SPF coverage.