Choose a mailbox provider on purpose
Pick a reliable workspace or email host based on collaboration needs, storage, admin controls, and support. Then follow that provider’s DNS instructions exactly. Mixing leftover records from an old host is a top cause of failed delivery.
Replace MX records cleanly
Remove obsolete MX values before or as you publish the new set, according to provider guidance. Wait for propagation, then test. Split-brain MX configurations can send mail to the wrong system intermittently.
- Lower TTL a day before MX cutover when possible
- Schedule the change when someone can watch bounce reports
- Keep old provider access until mail flow is confirmed
Publish SPF, DKIM, and DMARC
SPF lists authorized sending services. DKIM cryptographically signs messages. DMARC tells receivers what to do on failures and where to send reports. Enable them in order and tighten DMARC from monitor to enforce as reports look clean.
Authenticate every sending service
Marketing tools, support desks, and billing apps often send as your domain. Include them in SPF where appropriate and enable DKIM for each vendor. Unauthorized or unaligned senders damage reputation for everyone on the domain.
Test delivery like a customer would
Send to major providers and inspect headers for SPF/DKIM/DMARC results. Check spam folders, mobile rendering, and reply paths. Fix failures before printing the new address on invoices or packaging.
Operate the mailbox professionally
Create role addresses such as hello@, billing@, and security@. Enable spam filtering, shared inbox rules where needed, and separate domain-owner contacts from day-to-day mail users when possible.
- Document who owns each role address
- Keep registrar notices off heavily filtered shared inboxes
- Review DMARC reports monthly after enforcement
Key takeaways
- Clean MX cutovers beat mixed old-and-new records
- SPF, DKIM, and DMARC are required for modern trust
- Authenticate every app that sends as your domain
Ready to put this into practice?
Search available names, transfer an existing domain, or review security settings in your portfolio.