Skip to main content
email·digit

How to add CNAME and TXT records at Cloudflare, GoDaddy and Namecheap

Email Digit asks you to publish four DNS records once: three CNAMEs and one TXT. Every registrar has a screen for this, and the three mistakes that stop a record verifying are the same everywhere: typing the full hostname where the provider adds your domain for you, leaving an old record at the same name, and, on Cloudflare, leaving the orange proxy cloud on. Here is the exact path at Cloudflare, GoDaddy and Namecheap.

The four records

Open your domain in Email Digit and the records are listed with a copy button next to each value. For a domain called acme.com they look like this:

  • DKIM, first key: a CNAME at ed1._domainkey pointing to a name under dkim.emaildigit.com.
  • DKIM, second key: a CNAME at ed2._domainkey, so a key can be rotated while mail signed with the old one still verifies.
  • DMARC: a CNAME at _dmarc pointing to a name under dmarc.emaildigit.com. The policy behind it is yours to step up in one click.
  • SPF: a TXT at the domain itself, v=spf1 include:_spf.emaildigit.com ~all.

The CNAMEs point at names we control, which is why key rotation and DMARC changes never need you to edit DNS again. The deliverability page shows the full values for the example domain.

Before you start: the three things that break a record

  1. Hostname doubling. Most providers add your domain to whatever you type in the name field. Type ed1._domainkey, not ed1._domainkey.acme.com, or you publish ed1._domainkey.acme.com.acme.com and nothing verifies.
  2. An old record at the same name. DNS does not allow a CNAME beside any other record at the same name. If a previous tool left a TXT at _dmarc or at ed1._domainkey, delete it first. SPF is the opposite case: a domain may have only one TXT that starts with v=spf1, so if one exists, add our include to it instead of adding a second record.
  3. Cloudflare’s proxy. A proxied (orange cloud) CNAME answers with Cloudflare’s own addresses instead of the target name, so a mail server looking up your DKIM key finds nothing. Every one of these records must be DNS only, the grey cloud.

Cloudflare

  1. Log in, pick the domain, and open DNS, then Records.
  2. Click Add record. Set Type to CNAME.
  3. Name: ed1._domainkey. Target: the value copied from Email Digit. Switch Proxy status to DNS only. TTL can stay on Auto. Save.
  4. Repeat for ed2._domainkey and for _dmarc.
  5. Add one more record with Type TXT, Name @, and Content v=spf1 include:_spf.emaildigit.com ~all. If a v=spf1 TXT is already there, edit it and add include:_spf.emaildigit.com before the ~all.

Cloudflare’s own instructions are at developers.cloudflare.com.

GoDaddy

  1. Open My Products, find the domain, and choose DNS (it may be labelled Manage DNS).
  2. Click Add New Record. Type: CNAME.
  3. Name: ed1._domainkey. Value: the target copied from Email Digit. TTL: the default. Save.
  4. Repeat for ed2._domainkey and _dmarc.
  5. Add a TXT record with Name @ and Value v=spf1 include:_spf.emaildigit.com ~all, or add the include to an existing SPF record.

GoDaddy’s help page is at godaddy.com/help.

Namecheap

  1. Open Domain List, click Manage next to the domain, then the Advanced DNS tab.
  2. Under Host Records, click Add New Record and choose CNAME Record.
  3. Host: ed1._domainkey. Value: the target copied from Email Digit. TTL: Automatic. Click the tick to save.
  4. Repeat for ed2._domainkey and _dmarc.
  5. Add a TXT Record with Host @ and Value v=spf1 include:_spf.emaildigit.com ~all, or extend the SPF record that is there.

Namecheap’s help page is at namecheap.com/support.

Then verify

Back in Email Digit, open the domain and click Verify now. Each record is looked up and marked verified as soon as DNS answers. Propagation can take up to an hour, but most providers update within minutes. A record that stays unverified is nearly always one of the three mistakes above; the domain page names which record is still missing, so you know which one to open again.

Not sure what your domain publishes today? The free domain check reads SPF, DKIM, DMARC and MX without an account, and for a missing or broken record shows the exact value to publish.

Sources

  1. Cloudflare: create DNS records
  2. GoDaddy: add a CNAME record
  3. Namecheap: create a CNAME record
Share this guideShare on XShare on LinkedIn