Configuring Alibaba Cloud DNS for Custom Business Email
Completing an alibaba cloud dns mail setup correctly is essential for ensuring your custom business email delivers reliably to inboxes and avoids aggressive spam filters. Whether you are migrating to a corporate workspace or setting up a dedicated mail server, you must configure specific DNS records—including MX, SPF, DKIM, and DMARC—within your Alibaba Cloud DNS console.
Before you begin publishing records, it is always a best practice to verify your current mail exchange configuration using the MX Lookup tool on XiaTools to see which mail servers are actively responding for your domain.
Understanding Mail DNS Records
To route email properly and protect your domain reputation, your DNS zone file requires four foundational record types. Each record serves a specific, non-negotiable purpose in email routing and authentication.
MX Records (Mail Exchange)
MX records tell the wider internet which mail servers are authorized to accept incoming emails on behalf of your domain. Every MX record consists of a priority integer (lower numbers mean higher preference) and a target hostname.
SPF Records (Sender Policy Framework)
An SPF record is a TXT record that lists all IP addresses and hostnames authorized to send emails on behalf of your domain. Receiving servers check this list to reject forged sender addresses.
DKIM Records (DomainKeys Identified Mail)
DKIM adds a cryptographic digital signature to the header of every outgoing email. Mail servers use your public key published in your DNS records to verify that the email was genuinely sent by you and was not altered in transit.
DMARC Records (Domain-based Message Authentication, Reporting, and Conformance)
DMARC ties SPF and DKIM together. It instructs receiving mail servers on what to do if an email fails authentication checks—whether to take no action (none), quarantine the email, or completely reject it.
Step-by-Step Alibaba Cloud DNS Mail Setup
Configuring these records in Alibaba Cloud is straightforward once you locate the correct management console. Follow these precise steps to add your mail records.
Step 1: Log in to the Alibaba Cloud Console
- Open your web browser and navigate to the official Alibaba Cloud management portal.
- Log in using your account credentials.
- In the top navigation menu or search bar, look for Alibaba Cloud DNS (also referred to as Domain Name System) and click to open the console.
Step 2: Access Your Domain Zone File
- In the DNS dashboard, click on the Manage link next to the domain name you want to configure (e.g.,
example.com). - This opens the DNS records management page for your zone, displaying existing A, CNAME, and TXT records.
Step 3: Add MX Records
To route incoming mail to your provider, you must add the exact MX records supplied by your email hosting provider. Note that provider names and interfaces may differ slightly.
- Click the Add Record button.
- Set the Type dropdown to
MX. - In the Host (or RR) field, enter
@to represent your root domain, or leave it blank depending on the console layout. - In the Value field, enter your mail provider's server hostname (e.g.,
mail.example.comor a provider-specific address likesmtp.mailprovider.com). - In the Priority field, enter the preference integer provided by your mail host (commonly
10or5). - Leave the TTL (Time To Live) at the default setting (usually
600or3600seconds) and click Confirm.
Step 4: Add the SPF TXT Record
Next, authorize your mail servers to send emails by publishing an SPF policy.
- Click Add Record again.
- Set the Type to
TXT. - In the Host field, enter
@. - In the Value field, enter your provider's SPF string, such as:
v=spf1 include:spf.example.com ~all - Click Confirm.
Step 5: Add DKIM and DMARC Records
Your email provider will supply a unique DKIM selector and public key string.
- Click Add Record, select TXT.
- For DKIM, enter your selector prefix combined with
._domainkeyin the Host field (e.g.,default._domainkey). - Paste the long cryptographic public key string into the Value field.
- For DMARC, create a TXT record with the host
_dmarcand a value such as:v=DMARC1; p=quarantine; rua=mailto:admin@example.com - Click Confirm for both.
Verifying Your DNS Configuration
After publishing your records in Alibaba Cloud, you must verify that they propagate globally and respond correctly. DNS propagation typically takes anywhere from a few minutes to a few hours.
Using Command Line Tools
You can use native diagnostic tools like dig or nslookup in your terminal or command prompt to check your records.
To check MX records on Linux or macOS:
dig example.com MX
Sample output:
;; ANSWER SECTION:
example.com. 600 IN MX 10 mail.example.com.
To check your TXT and SPF records on Windows PowerShell:
Resolve-DnsName -Name example.com -Type TXT
Sample output:
Name Type TTL Section String
---- ---- --- ------- ------
example.com TXT 600 Answer v=spf1 include:spf.example.com ~all
Record Syntax Reference Table
| Record Type | Host / RR | Value / Target | Priority | Purpose |
|---|---|---|---|---|
| MX | @ |
mx.example.com. |
10 |
Directs incoming mail traffic |
| TXT (SPF) | @ |
v=spf1 ip4:192.0.2.1 ~all |
- | Authorizes sending IP addresses |
| TXT (DKIM) | selector._domainkey |
v=DKIM1; k=rsa; p=MIIBIjAN... |
- | Signs outgoing emails cryptographically |
| TXT (DMARC) | _dmarc |
v=DMARC1; p=reject; rua=... |
- | Policy for handling failed authentications |
Common Mistakes and How to Fix Them
- Multiple SPF Records: Publishing more than one SPF TXT record breaks authentication entirely, as receiving servers will reject domains with ambiguous policies. Combine all required includes and IP ranges into a single SPF string.
- Missing Trailing Dots: When specifying absolute hostnames in MX records (like
mail.example.com.), forgetting the trailing dot can sometimes cause automated DNS parsers to append your root domain twice, resulting in a lookup failure. - Incorrect Priority Values: Entering text instead of integers in the MX priority field will cause validation errors in the Alibaba Cloud DNS interface.
- Ignoring Propagation Delays: Testing immediately after saving records can lead to false negatives. Always allow time for TTL expiration across global recursive resolvers.
Setup Checklist
- Logged into Alibaba Cloud DNS console
- Added primary and secondary MX records with correct priorities
- Published a single consolidated SPF TXT record at root
- Added the DKIM record using the exact selector provided by your host
- Configured a DMARC policy record under
_dmarc - Verified record resolution using command-line tools or online lookups