XiaTools

Configuring Alibaba Cloud DNS for Custom Business Email

Updated 11 Oct 2026

Completing an alibaba cloud dns mail setup correctly is essential for ensuring your custom business email delivers reliably to inboxes and avoids aggressive spam filters. Whether you are migrating to a corporate workspace or setting up a dedicated mail server, you must configure specific DNS records—including MX, SPF, DKIM, and DMARC—within your Alibaba Cloud DNS console.

Before you begin publishing records, it is always a best practice to verify your current mail exchange configuration using the MX Lookup tool on XiaTools to see which mail servers are actively responding for your domain.

Understanding Mail DNS Records

To route email properly and protect your domain reputation, your DNS zone file requires four foundational record types. Each record serves a specific, non-negotiable purpose in email routing and authentication.

MX Records (Mail Exchange)

MX records tell the wider internet which mail servers are authorized to accept incoming emails on behalf of your domain. Every MX record consists of a priority integer (lower numbers mean higher preference) and a target hostname.

SPF Records (Sender Policy Framework)

An SPF record is a TXT record that lists all IP addresses and hostnames authorized to send emails on behalf of your domain. Receiving servers check this list to reject forged sender addresses.

DKIM Records (DomainKeys Identified Mail)

DKIM adds a cryptographic digital signature to the header of every outgoing email. Mail servers use your public key published in your DNS records to verify that the email was genuinely sent by you and was not altered in transit.

DMARC Records (Domain-based Message Authentication, Reporting, and Conformance)

DMARC ties SPF and DKIM together. It instructs receiving mail servers on what to do if an email fails authentication checks—whether to take no action (none), quarantine the email, or completely reject it.

Step-by-Step Alibaba Cloud DNS Mail Setup

Configuring these records in Alibaba Cloud is straightforward once you locate the correct management console. Follow these precise steps to add your mail records.

Step 1: Log in to the Alibaba Cloud Console

  1. Open your web browser and navigate to the official Alibaba Cloud management portal.
  2. Log in using your account credentials.
  3. In the top navigation menu or search bar, look for Alibaba Cloud DNS (also referred to as Domain Name System) and click to open the console.

Step 2: Access Your Domain Zone File

  1. In the DNS dashboard, click on the Manage link next to the domain name you want to configure (e.g., example.com).
  2. This opens the DNS records management page for your zone, displaying existing A, CNAME, and TXT records.

Step 3: Add MX Records

To route incoming mail to your provider, you must add the exact MX records supplied by your email hosting provider. Note that provider names and interfaces may differ slightly.

  1. Click the Add Record button.
  2. Set the Type dropdown to MX.
  3. In the Host (or RR) field, enter @ to represent your root domain, or leave it blank depending on the console layout.
  4. In the Value field, enter your mail provider's server hostname (e.g., mail.example.com or a provider-specific address like smtp.mailprovider.com).
  5. In the Priority field, enter the preference integer provided by your mail host (commonly 10 or 5).
  6. Leave the TTL (Time To Live) at the default setting (usually 600 or 3600 seconds) and click Confirm.

Step 4: Add the SPF TXT Record

Next, authorize your mail servers to send emails by publishing an SPF policy.

  1. Click Add Record again.
  2. Set the Type to TXT.
  3. In the Host field, enter @.
  4. In the Value field, enter your provider's SPF string, such as:
    v=spf1 include:spf.example.com ~all
    
  5. Click Confirm.

Step 5: Add DKIM and DMARC Records

Your email provider will supply a unique DKIM selector and public key string.

  1. Click Add Record, select TXT.
  2. For DKIM, enter your selector prefix combined with ._domainkey in the Host field (e.g., default._domainkey).
  3. Paste the long cryptographic public key string into the Value field.
  4. For DMARC, create a TXT record with the host _dmarc and a value such as:
    v=DMARC1; p=quarantine; rua=mailto:admin@example.com
    
  5. Click Confirm for both.

Verifying Your DNS Configuration

After publishing your records in Alibaba Cloud, you must verify that they propagate globally and respond correctly. DNS propagation typically takes anywhere from a few minutes to a few hours.

Using Command Line Tools

You can use native diagnostic tools like dig or nslookup in your terminal or command prompt to check your records.

To check MX records on Linux or macOS:

dig example.com MX

Sample output:

;; ANSWER SECTION:
example.com.		600	IN	MX	10 mail.example.com.

To check your TXT and SPF records on Windows PowerShell:

Resolve-DnsName -Name example.com -Type TXT

Sample output:

Name             Type TTL   Section   String
----             ---- ---   -------   ------
example.com      TXT  600   Answer    v=spf1 include:spf.example.com ~all

Record Syntax Reference Table

Record Type Host / RR Value / Target Priority Purpose
MX @ mx.example.com. 10 Directs incoming mail traffic
TXT (SPF) @ v=spf1 ip4:192.0.2.1 ~all - Authorizes sending IP addresses
TXT (DKIM) selector._domainkey v=DKIM1; k=rsa; p=MIIBIjAN... - Signs outgoing emails cryptographically
TXT (DMARC) _dmarc v=DMARC1; p=reject; rua=... - Policy for handling failed authentications

Common Mistakes and How to Fix Them

  • Multiple SPF Records: Publishing more than one SPF TXT record breaks authentication entirely, as receiving servers will reject domains with ambiguous policies. Combine all required includes and IP ranges into a single SPF string.
  • Missing Trailing Dots: When specifying absolute hostnames in MX records (like mail.example.com.), forgetting the trailing dot can sometimes cause automated DNS parsers to append your root domain twice, resulting in a lookup failure.
  • Incorrect Priority Values: Entering text instead of integers in the MX priority field will cause validation errors in the Alibaba Cloud DNS interface.
  • Ignoring Propagation Delays: Testing immediately after saving records can lead to false negatives. Always allow time for TTL expiration across global recursive resolvers.

Setup Checklist

  • Logged into Alibaba Cloud DNS console
  • Added primary and secondary MX records with correct priorities
  • Published a single consolidated SPF TXT record at root
  • Added the DKIM record using the exact selector provided by your host
  • Configured a DMARC policy record under _dmarc
  • Verified record resolution using command-line tools or online lookups

Frequently asked questions

How long does Alibaba Cloud DNS propagation take?

DNS changes in Alibaba Cloud usually propagate globally within 10 to 15 minutes. However, depending on the TTL values you configured and intermediate caching by public resolvers like 8.8.8.8, full propagation can occasionally take up to 24 hours.

Can I have multiple MX records with the same priority?

Yes, you can assign the same priority integer to multiple MX records. When mail servers encounter multiple records with identical priority, they load-balance incoming delivery attempts across those servers.

What happens if I make a mistake in my SPF record?

If your SPF record contains syntax errors, invalid IP addresses, or exceeds the maximum DNS lookup limit of 10, receiving mail servers will fail the authentication check. This often causes legitimate emails to be marked as spam or rejected outright.

Do I need both SPF and DKIM configured?

Yes, both are vital for modern email security. SPF verifies that the sending server is authorized by the domain owner, while DKIM verifies that the email content itself has not been tampered with during transmission.

Why does my DMARC record need a reporting email address?

Adding rua and ruf tags with a mailto address enables receiving servers to send aggregate and forensic XML reports back to you. These reports provide invaluable visibility into who is sending email on behalf of your domain and whether authentication checks are passing.

Related articles

Free tools