XiaTools

MailerLite Custom Domain DKIM Configuration and Validation

Updated 10 Oct 2026

Setting up your MailerLite DKIM record setup is essential for authenticating your outbound emails and protecting your sender reputation. Without valid DomainKeys Identified Mail records, mailbox providers like Google and Yahoo are likely to send your marketing campaigns straight to the spam folder or reject them entirely.

DomainKeys Identified Mail adds a cryptographic digital signature to your email headers, proving to receiving servers that the message genuinely originated from your domain and was not altered in transit. This guide walks you through finding your MailerLite authentication keys, publishing the correct DNS records, and troubleshooting validation errors.

Understanding MailerLite DKIM Architecture

When you send campaigns through MailerLite, the platform signs your outgoing messages using a private key stored on their servers. To verify this signature, receiving mail servers look up the corresponding public key published in your domain's DNS settings.

MailerLite uses CNAME records for its authentication setup rather than traditional TXT records. This approach allows MailerLite to manage and rotate the underlying cryptographic keys automatically without requiring you to update your DNS records manually every time a key update occurs. Typically, your setup will involve adding a specific CNAME record pointing to a MailerLite-managed target.

Finding Your DKIM Values in MailerLite

Before you can create any DNS records, you need to retrieve the specific hostnames and target values generated for your domain by MailerLite.

  1. Log into your MailerLite dashboard using your administrator credentials.
  2. Navigate to your account settings menu, typically found by clicking your profile icon in the top right corner.
  3. Locate and select the Domains or Sender domains section from the navigation panel.
  4. Find the domain you want to authenticate and click on the Protect domain or Authenticate button.
  5. Review the DNS configuration values provided on the screen, which will display the required CNAME records, including their unique hostnames and points-to targets.

Keep this tab open or copy the values to a secure text editor, as you will need to paste them precisely into your DNS provider's management console.

Adding the CNAME Records to Your DNS Provider

Once you have your unique keys, you must log in to the DNS hosting provider where your domain's nameservers are hosted (such as Cloudflare, GoDaddy, or Namecheap). Note that menu paths vary slightly depending on your provider, but you will generally look for an area labeled DNS Management, DNS Zone Editor, or Manage Zone.

To ensure maximum accuracy, you should copy and paste the values directly from your MailerLite dashboard. Do not manually type out long alphanumeric strings, as a single typo will cause authentication to fail.

DNS Record Type Host / Name (Example) Target / Value (Example) TTL
CNAME ml._domainkey ml._domainkey.example.com.mailersend.net Auto / 3600
TXT (SPF) @ v=spf1 include:mailersend.net ~all Auto / 3600

Step-by-Step DNS Entry Creation

  1. Select Add Record or create a new entry within your DNS zone manager.
  2. Choose CNAME as the record type.
  3. In the Name or Host field, enter the selector prefix provided by MailerLite (for example, ml._domainkey). Depending on your DNS host, you may only need to enter the prefix rather than the full domain name, as some panels append your root domain automatically.
  4. In the Target, Points to, or Value field, paste the full destination address provided by MailerLite (for example, ml._domainkey.example.com.mailersend.net).
  5. Set the Time-to-Live (TTL) to the default value or 3600 seconds (1 hour).
  6. Save the record. Repeat this process for any additional CNAME records that MailerLite requires.

Validating Your MailerLite DKIM Record Setup

DNS changes do not always take effect instantly; global propagation can take anywhere from a few minutes up to 24 hours depending on your TTL settings and DNS provider. Before you verify inside MailerLite, you should check your setup independently to confirm the records are publicly visible.

You can use the free DKIM Checker to instantly query public DNS servers, verify that your selector is publishing the correct cryptographic keys, and ensure your configuration matches MailerLite's exact requirements without waiting for slow dashboard updates.

You can also verify record propagation manually using command-line diagnostic tools. Open your terminal or command prompt and run a DNS lookup command:

nslookup -type=cname ml._domainkey.example.com

On Unix-based systems, you can use dig for more detailed information:

dig CNAME ml._domainkey.example.com +short

A correct lookup will return the designated target hostname ending in the MailerLite infrastructure domain. If the command returns no output or an NXDOMAIN error, your DNS records have not propagated or contain a syntax typo.

Once your command-line checks or online tools confirm the records are active, return to your MailerLite dashboard and click the Verify DNS records or Check status button. MailerLite will query your DNS zone, confirm the signatures align, and update your domain status to verified.

Common Mistakes and How to Fix Them

Even experienced administrators occasionally run into authentication hurdles. Review these common pitfalls to keep your setup running smoothly:

  • Double Domain Append: Many DNS management panels automatically append your root domain name to the Host field. If MailerLite asks you to add ml._domainkey.example.com, and your DNS panel already appends example.com, typing the full string will result in ml._domainkey.example.com.example.com, causing an immediate lookup failure. Check your provider's preview window to confirm the final hostname.
  • Conflicting Record Types: Ensure you have not accidentally created a TXT record where a CNAME record is requested, or vice versa. MailerLite specifically relies on CNAME architecture for its automated key management.
  • Ignoring SPF and DMARC: DKIM does not work in a vacuum. Ensure your domain also features a valid SPF record authorizing MailerLite, and implement a DMARC policy (even a basic v=DMARC1; p=none; policy) to achieve full email authentication alignment.
  • Premature Testing: Testing your configuration immediately after saving can lead to false negatives if DNS caching prevents your local network from seeing the updates. Always give the records a brief window to propagate.

MailerLite DKIM Setup Checklist

  • Retrieved exact CNAME host and target values from the MailerLite dashboard.
  • Logged into your domain registrar or DNS hosting provider.
  • Created the required CNAME record(s) with correct host prefixes.
  • Avoided double-domain appending errors in the hostname field.
  • Verified record propagation using command-line tools or online diagnostic utilities.
  • Clicked verify in MailerLite and confirmed a successful authentication status.

Frequently asked questions

How long does it take for MailerLite DKIM records to update?

DNS propagation typically takes anywhere from a few minutes to a few hours, though it can occasionally take up to 24 hours globally. Setting a low TTL prior to making changes can help speed up the discovery process.

Why does MailerLite use CNAME records instead of TXT records for DKIM?

MailerLite uses CNAME records so they can manage and rotate your underlying cryptographic public keys automatically. This eliminates the need for you to manually update your DNS records whenever key security standards or infrastructure configurations change.

What should I do if MailerLite says verification failed?

First, double-check your DNS provider's panel to ensure there are no typos in the host or target values. Next, use command-line tools or online checkers to confirm the record is publicly visible and not blocked by a misconfigured local cache.

Do I need to set up SPF and DMARC alongside MailerLite DKIM?

Yes. While DKIM signs your emails cryptographically, mailbox providers heavily evaluate your overall email security posture. Combining a valid DKIM record with an updated SPF record and a DMARC policy maximizes your inbox placement rates.

Can I use the same DKIM selector for MailerLite and another email service?

No, you cannot share selectors across different email providers because each platform requires its own unique cryptographic keys and target endpoints. Always create the specific selector hostname assigned by MailerLite for your domain.

Related articles

Free tools