Choose the domain
Use a dedicated subdomain such asmail.company.com, notifications.company.com, or auth.company.com.
The address security@auth.company.com must be verified under auth.company.com.
Choose the domain before you wire production From addresses into code.
1
Add the domain
Open Domains, select Add domain, enter the sending domain, and choose its region where the dashboard asks for one.
2
Review provider detection
Signal inspects the domain nameservers and identifies common DNS providers.
Use automatic setup when offered or copy the records into your provider manually.
3
Publish the records
Add each host, record type, and value exactly.
Do not add extra quotes.
If the provider automatically appends the zone name, enter only the host portion shown by that provider.
4
Verify
Return to the domain and select Verify.
Verification runs asynchronously, so refresh the record state after public DNS has propagated.
Records Signal uses
Verification states
A pending record has not resolved to the expected value yet. A verified record matches. A failed record needs attention. Compare the exact public response with the value shown in Signal before editing the record again.DNS troubleshooting
- Wait at least one full TTL after a change.
- Disable HTTP proxying for mail-related CNAME records.
- Check whether the provider duplicated the root domain in the host.
- Remove stale records that conflict at the same host.
- Confirm you changed the authoritative nameserver provider, not an old registrar DNS screen.
- Use the domain record view to identify the specific record that remains unresolved.
Domain Connect
Use supported automatic DNS setup.
DMARC
Publish policy and inspect aggregate reports.