Authenticate your domain and run a first clean

You will add or fix your authentication records and complete one round of list cleaning.

Most people put off domain authentication because it involves a part of the internet they have never touched. They open their domain settings, see a table of records with names like TXT and CNAME, and close the tab. In practice the work is mostly copying and pasting, because your email tool gives you the exact text. This exercise walks you through it, then runs the first clean of your list using the routine from lesson 3.4.

You need three things before you start: a login for your email tool, a login for wherever your domain's DNS is managed, and the consent audit from lesson 1.4. Allow about thirty-five minutes of work, spread over a day, because DNS changes take time to show up.

Step 1: Find your tool's authentication steps

Every email tool has a section for this, usually under settings, domains or sender authentication. Add your sending domain there. The tool will generate the records it needs you to add: typically one or more records for DKIM, an instruction for including the tool in your SPF record, and sometimes a record to prove you own the domain. Some tools also suggest a DMARC record if you have none.

Copy each record into a document with three columns: the type (TXT or CNAME), the name or host, and the value. Having them in one place makes the next step much less error-prone.

Step 2: Add the records at your DNS host

Log in to your registrar or DNS host and open the DNS settings for your domain. Add each record exactly as the tool gave it. A few things trip people up.

Some DNS hosts add your domain to the name field automatically, so entering the full name produces a doubled domain that never verifies. If your host's existing records show only the short part, enter only the short part.

You can have only one SPF record. If one already exists, perhaps from your Google Workspace or Microsoft 365 setup, edit it to add the include your email tool gave you rather than creating a second record.

If you have no DMARC record, add one at the monitoring policy from lesson 3.2, with an address where you will receive reports. Mei Ling's example looks like this in plain words: a TXT record named _dmarc, with a value that sets the version, sets the policy to none, and gives an address for reports. Your tool's help pages or your DNS host will show the exact format.

Step 3: Wait, then verify

DNS changes are not instant. How long they take to show up depends on the host, from minutes to considerably longer. Give it a few hours, then go back to your email tool and press its verify or check button.

If a record fails, look first at the doubled domain problem, then at typos and stray spaces in long values. Two SPF records is another common cause. Fix, wait again, and recheck.

Then confirm independently with a free checker. MXToolbox is one widely used option, and there are others. Look up your domain's SPF record, your DMARC record, and your DKIM record, which needs the selector your email tool used, shown in the DKIM record's name. All three should be found, with no errors. Take a screenshot of the tool showing your domain verified, and of the checker results.

Finally, send yourself a test email from the tool and repeat the header check from lesson 3.1. SPF, DKIM and DMARC should all now say pass.

Step 4: Suppress before you send

With the domain sorted, run the first clean, so your next send goes only to people who should get it.

First, hard bounces. Find your tool's bounce or cleaned contacts view and confirm they are suppressed. If you imported old lists, you may find more than you expected.

Second, contacts with no consent record. Take the audit from lesson 1.4. Any contact in the transaction-only or unclear groups who is sitting on a marketing list needs to come off it, or be moved to a list you will only use for the one-time permission email. Most tools let you suppress or unsubscribe a group by importing a file of addresses or by filtering on a tag.

Third, quiet contacts, if your list is old enough to have them, go into a segment ready for the re-permission email you planned in lesson 3.4.

Here is Mei Ling's example. Her tool showed 410 contacts on her marketing list, because she had imported order customers before doing her audit. Twenty-three had hard bounced, and 207 came from the order form with no marketing consent. She suppressed both groups, leaving 180 contacts ready for her next send, all of them people who had signed up through her newsletter form.

What done looks like

Your domain shows as verified in your email tool. An independent checker finds SPF, DKIM and DMARC with no errors. Your test email passes all three in its headers. Hard bounces and unconsented contacts are suppressed, and you know the number of each. Work through the steps now. The activity below asks for your screenshots and the number of contacts you suppressed, so keep both.

Produce a screenshot showing your domain verified in your email tool, a checker result for all three records, and a note of how many contacts you suppressed.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).