XiaTools

Configuring Custom Business Email on Mailgun Using DNS Manager

Updated 10 Oct 2026

Setting up a custom sending domain on Mailgun requires adding specific DNS records—including TXT, MX, and CNAME entries—to prove ownership and ensure high email deliverability. Without a properly configured DNS setup, your emails will likely land in spam folders or fail delivery altogether due to strict DMARC, DKIM, and SPF authentication checks.

Before you begin making changes to your live zone file, it is wise to check your current mail server configurations using the MX Lookup tool on XiaTools to understand your baseline routing and identify any existing conflicting records.

Preparing for Your Mailgun DNS Configuration

To configure your domain successfully, you need administrative access to the DNS management console of your domain registrar or cloud DNS hosting provider (such as Cloudflare, AWS Route 53, Google Cloud DNS, or GoDaddy). While menu paths vary by provider, you will generally look for a section labeled DNS Management, Zone Editor, or Manage DNS.

Mailgun requires you to add records under either your root domain (e.g., example.com) or, more commonly, a dedicated subdomain (e.g., mg.example.com or mail.example.com). Using a dedicated subdomain is an industry best practice because it isolates your transactional or marketing mail reputation from your corporate Google Workspace or Microsoft 365 inbox.

Step-by-Step Mailgun DNS Setup Guide

Log in to your Mailgun account, navigate to the Sending section, select Domains, and click Add New Domain. Enter your chosen domain or subdomain, select your region (US or EU), and Mailgun will generate a unique set of DNS records. Copy these values precisely into your clipboard as you proceed through the following record types.

1. Adding the TXT Records (SPF and DKIM)

Mailgun provides two critical TXT records for authentication. The first is your SPF (Sender Policy Framework) record, which authorizes Mailgun to send emails on behalf of your domain. The second is your DKIM (DomainKeys Identified Mail) signature, which cryptographically signs your emails to prevent tampering.

  • SPF Record Syntax:

    • Type: TXT
    • Host/Name: mg (or @ if using your root domain)
    • Value: v=spf1 include:mailgun.org ~all
  • DKIM Record Syntax:

    • Type: TXT
    • Host/Name: krs._domainkey.mg (Mailgun provides a specific selector like krs or pic)
    • Value: A long string starting with k=rsa; p=MIGfMA0GCS...

2. Adding the MX Records (Inbound Routing)

If you plan to receive or parse incoming emails using Mailgun, you must add inbound mail exchange (MX) records. If you only use Mailgun for outbound sending, you can skip this step.

  • Primary Inbound MX:

    • Type: MX
    • Host/Name: mg
    • Priority: 10
    • Value: mxa.mailgun.org (or mxa.eu.mailgun.org for European regions)
  • Secondary Inbound MX:

    • Type: MX
    • Host/Name: mg
    • Priority: 10
    • Value: mxb.mailgun.org (or mxb.eu.mailgun.org for European regions)

3. Adding the CNAME Record (Tracking Links)

Mailgun uses a CNAME record to track email opens and clicks through custom tracking domains.

  • Tracking Record Syntax:
    • Type: CNAME
    • Host/Name: email.mg
    • Value: mailgun.org (or eu.mailgun.org for European regions)

Verifying Your DNS Records

Once you have published all required records in your DNS manager, return to the Mailgun dashboard and click Verify DNS Settings. DNS propagation can take anywhere from a few minutes up to 24 hours depending on your TTL (Time to Live) settings.

You can manually verify your records from your local terminal using standard command-line tools. For example, use dig to check your TXT records on Unix-like systems:

dig TXT krs._domainkey.mg.example.com +short

On Windows PowerShell, you can query your MX records using:

Resolve-DnsName -Name mg.example.com -Type MX

A correct response confirms that global nameservers are serving your updated Mailgun configurations.

Comparison of Mailgun DNS Record Types

Record Type Purpose Example Host Example Value Required?
TXT (SPF) Authorize sending servers mg v=spf1 include:mailgun.org ~all Yes
TXT (DKIM) Cryptographic email signing krs._domainkey.mg k=rsa; p=MIGf... Yes
MX Inbound email routing mg 10 mxa.mailgun.org Optional (Inbound only)
CNAME Open and click tracking email.mg mailgun.org Recommended

Common Mistakes and How to Fix Them

Even experienced engineers occasionally run into roadblocks during setup. Watch out for these frequent pitfalls:

  • Conflicting SPF Records: A domain can only have one active SPF record. If your domain already has an SPF record for Google Workspace (include:_spf.google.com), you must merge them into a single record rather than creating a second one: v=spf1 include:_spf.google.com include:mailgun.org ~all
  • Trailing Dots in Hostnames: Some DNS management panels automatically append your root domain to the host field. If you enter mg.example.com into a host field that already appends the apex domain, your record might accidentally become mg.example.com.example.com. Always check your provider's formatting rules.
  • Cloudflare Proxy Status: If you use Cloudflare as your DNS provider, ensure that any CNAME or A records associated with Mailgun tracking are set to DNS Only (grey cloud) rather than Proxied (orange cloud). Proxied tracking links will break SSL certificates and redirect validation.

Setup Checklist

Review this quick checklist before testing your email campaigns:

  • Dedicated subdomain chosen (e.g., mg.example.com).
  • SPF TXT record published without duplicates.
  • DKIM TXT record added with the correct selector.
  • MX records configured (if receiving mail through Mailgun).
  • CNAME tracking record set to DNS-only mode.
  • DNS propagation verified via terminal commands or dashboard lookup.

Frequently asked questions

How long does Mailgun DNS propagation take?

DNS propagation typically takes anywhere from 5 minutes to 4 hours, though it can occasionally take up to 24 hours globally. The exact duration depends on the Time to Live (TTL) values set on your DNS records prior to making updates.

Can I use my root domain instead of a subdomain for Mailgun?

Yes, you can configure Mailgun directly on your root domain (e.g., example.com) by setting the host field to '@'. However, using a dedicated subdomain like mg.example.com is strongly recommended to protect your primary corporate email reputation.

What should I do if my SPF verification fails?

SPF verification usually fails because of syntax errors, typos in the include statement, or having multiple conflicting SPF records on the same domain. Ensure you only have one SPF record that combines all authorized email service providers.

Why is my DKIM record failing verification in Mailgun?

DKIM verification failures are commonly caused by long key strings being truncated when pasted into the DNS provider's interface, or by incorrect selector names. Double-check that the host name matches the exact selector provided by Mailgun.

Do I need MX records if I only send outbound emails?

No, MX records are strictly required if you intend to receive, forward, or parse incoming emails through Mailgun. If you only send transactional or marketing emails, configuring SPF, DKIM, and CNAME records is sufficient.

Related articles

Free tools