Email domain authentication

The main email providers such as Yahoo, Microsoft, or Google have published a set of rules to increase the protection of email users against spam and phishing. These requirements will entail the obligation to authenticate each email sent.

This article details what is affected and how to adapt in order to authenticate your email domain in Connectif.

  

These requirements also imply the need to include the unsubscribe button with a single click. You can learn more about this and how Connectif adapts to it in this article.

 

1. Properties

1.1. What does the domain authentication requirement imply?

The main change is the obligation to authenticate the email sending domain (from address). Although Connectif has always recommended authenticating your email sending for best practices and optimal deliverability, it is now mandatory.

  • This authentication refers to DKIM, SPF, and DMARC.
  • It is achieved by adding DNS records at your domain provider.

 

1.2. What will happen if you do not authenticate?

  • Gmail warns that absolutely no unauthenticated email will enter their inboxes.
  • Additionally, it will negatively impact your domain’s reputation.
 

To prevent potential damage to your domain’s reputation, Connectif is forced to require this domain authentication before enabling email sending from your Connectif account.

  • If the domain is not authenticated, all workflows that send emails using unauthenticated senders (from address and reply-to address) will stop working and will be automatically paused.

1.2.1. Which workflows will be affected?

  • All active workflows that have a "Send email" node configured with an unauthenticated domain will stop working and will be automatically paused.

1.2.2. How to solve the problem?

  • You will need to edit the workflows to use an authenticated domain or authenticate the domain in use to be able to resume them.

1.2.3. How to know which workflows have been automatically paused?

  • If your workflows use a domain that is not properly authenticated, you will receive an email listing all workflows that will stop working if the domain is not authenticated.

 

2. How to authenticate your email domain

To prevent sending from being blocked, all accounts must authenticate their sending domain(s) to comply with the requirement imposed by Google and other providers. This operation must also be performed with subdomains and must include the domain extension.

Your domain is the name that distinguishes your website and appears in your email address. The domain name is the part that comes after "www." or, in the case of email, after the "@" symbol. The domain extension is the part that comes after the name (".com", ".es", ".it", for example).

If you need more information about domain structure, you can check out this article.

 

Authenticate the email domain or subdomain

Go to "Store Settings > Channels > Email".

1. In the Domain Authentication tab, click on "Add new domain" and add the domain and extension you want to authenticate.

Authenticate email domain - 1-min.png

2. Enter the domain you want to use for sending (From Address and Reply to Address) and click Confirm.

Authenticate email domain - 2-min (1).png

3. In the domain menu, the domain you just added will appear with the status Pending and certain values that you must add to your domain provider:

  • The CNAME-type DNS records that you need to add to your domain provider.
  • A TXT record for DMARC, which you must also add, in case you have not configured it previously. In this case, it is mandatory to have a valid DMARC record, but there are no restrictions at the policy level; any valid DMARC policy will be considered correct.
 

The number of CNAME records to configure may vary. In any case, all those appearing in the Store must be added to your provider.

Authenticate email domain - 3 (1)-min.png

4. Access your business’s DNS provider platform and add these codes. Once done, update the DNS records. Below, you can access the documentation for the main providers where this process is explained, although you may need to contact your IT team to perform this step:

5. Back in Connectif, click on Verify domain to check that the records have been added correctly.

 

Please note that DNS record propagation may take some time, so if you have just added them and verification is not successful, try again after a while.

Authenticate email domain - 4-min.png

6. As soon as verification is complete, the domain will appear as Verified and email sending will be re-enabled in your Store for the authenticated domains.

 

You can contact the support team at any time with any questions about this process.

Authenticate email domain - 5-min.png

 

Monitor sending via PostMaster Tools

  

We recommend monitoring your sending via PostMaster Tools.

Google offers a free monitoring tool, PostMaster Tools and recommends its use to ensure compliance with best sending practices, including keeping reported spam rates below 0.3%, ideally even below 0.1%.

To configure PostMaster Tools, log in with your Google account at the following link.

Follow the steps provided by Google to configure PostMaster Tools for your domain:

 

Setting up PostMaster Tools is very important because, in case of any deliverability incident involving Gmail, Connectif will require the reports that this tool helps generate.

 

 

 Congratulations!
You have reached the end of the lesson.

  

Do you have any unresolved questions?
Remember that our Connectif specialists are available to you. To contact them, just open a Support ticket by clicking on the blue “Help” button on your dashboard.

 


Keep learning!

To make the most of your Connectif account, we recommend continuing with the following articles: