Set up SPF, DKIM and DMARC for Mailgun
The exact SPF, DKIM and DMARC records Mailgun needs, where to add them and how to check they pass and align, so Mailgun mail reaches the inbox.
Updated September 30, 2026
Mailgun works best on a sending subdomain such as mg.example.com. On it you publish an SPF record with include:mailgun.org, a DKIM key at <selector>._domainkey.mg (a TXT record, or two CNAMEs with Automatic Sender Security), two MX records and a tracking CNAME. Because Mailgun uses that subdomain as the envelope sender and signing domain, both SPF and DKIM align with example.com under relaxed DMARC alignment.
Records at a glance
| Host | Type | Value |
|---|---|---|
mg | TXT | v=spf1 include:mailgun.org ~all |
<selector>._domainkey.mg | TXT | k=rsa; p=<key from Mailgun>The selector and key are shown in Mailgun’s DNS records for the domain. With Automatic Sender Security these are CNAMEs instead. |
mg | MX | 10 mxa.mailgun.orgEU region: mxa.eu.mailgun.org and mxb.eu.mailgun.org. |
mg | MX | 10 mxb.mailgun.org |
email.mg | CNAME | mailgun.orgFor open, click and unsubscribe tracking. EU region: eu.mailgun.org. |
_dmarc | TXT | v=DMARC1; p=none; rua=mailto:<your report address>On your root domain. Subdomains inherit it. |
Set up SPF for Mailgun
Mailgun asks for v=spf1 include:mailgun.org ~all on the sending domain. Mailgun uses the sending domain (for example mg.example.com) as the envelope sender, so that’s where receivers check SPF. If you send from a subdomain, that record lives on its own name and doesn’t touch your root domain’s SPF record or its lookup budget.
As of September 2026, include:mailgun.org costs five DNS lookups, because it nests Mailgun’s US and EU ranges. That’s half the limit of ten, which is another reason to keep Mailgun on a subdomain. If you do send from your root domain, merge the include into your one SPF record:
v=spf1 include:_spf.google.com include:mailgun.org ~allEU accounts use the same include:mailgun.org. If you manage your root SPF through DMARC Dojo’s hosted SPF, you add Mailgun in the dashboard instead of editing DNS, and it refuses changes that would go past the 10-lookup limit.
Set up DKIM
- In the Mailgun control panel, add a new domain. Enter the subdomain you’ll send from, such as
mg.example.com, choose the US or EU region, and pick a DKIM key length: 2048-bit (recommended) or 1024-bit. - Open the domain’s DNS records. Copy the DKIM record exactly: its host is
<selector>._domainkey.mg.example.com(enter<selector>._domainkey.mgat hosts that append the domain), and its value starts withk=rsa; p=. - Add the SPF, DKIM, MX and tracking records at your DNS host.
- Click Verify DNS settings, or wait for automatic verification. The domain shows a green Verified badge when the records are found. DNS changes can take 24 to 48 hours to spread.
Automatic Sender Security hands key management to Mailgun: you publish two CNAMEs (Mailgun’s example is pdk1._domainkey.mg.example.com pointing to a target under dkim1.mailgun.com, plus pdk2) and Mailgun rotates 2048-bit keys, every 120 days by default. You can also create extra keys or import your own from the domain’s DNS records tab.
To confirm signing, send a test and look for dkim=pass with header.d=mg.example.com in the Authentication-Results header.
Make it pass DMARC (alignment)
Mailgun signs with the sending domain and uses it for the Return-Path (addresses like bounce+…@mg.example.com). So:
- If you send From the sending domain itself (
you@mg.example.com), SPF and DKIM align exactly. - If you send From the root domain (
you@example.com) throughmg.example.com, both align under relaxed alignment, the DMARC default, because they share the organizational domain. - Strict alignment breaks this. With
adkim=soraspf=s,mg.example.comno longer matchesexample.com. Keep alignment relaxed, or addexample.comitself as a Mailgun domain.
Read DMARC alignment for the full rules.
Add a DMARC record
v=DMARC1; p=none; rua=mailto:<your report address>One record on the root domain covers mg.example.com too, unless you publish a separate one there. DMARC Dojo recognizes Mailgun in DMARC reports, so you can see Mailgun traffic on its own and confirm it passes with alignment before you move to quarantine and reject.
Check your domain after Mailgun setup
Enter your root domain to see its DMARC policy, SPF lookup count and DKIM results, with a score and the fixes to make.
Troubleshooting
- Records don’t verify. The DNS host appended the domain twice, creating names like
mg.example.com.example.com. Enter the part before your root domain only. - SPF permerror on the root domain. Adding
include:mailgun.org(five lookups) pushed the record over ten. Move Mailgun to a subdomain or remove unused includes; the SPF checker shows the count. - DKIM fails for some messages. The DKIM TXT value was cut off at 255 characters. Re-enter it as split strings.
- Tracking links break or show certificate errors. The tracking CNAME points at the wrong region’s target, or it’s proxied through Cloudflare. Use
mailgun.org(US) oreu.mailgun.org(EU) and set it to DNS only. - DMARC fails with strict alignment. See above: relaxed alignment is needed when the From domain and the Mailgun domain differ.
Frequently asked questions
Should I use a subdomain like mg.example.com with Mailgun?
Mailgun recommends it. It keeps Mailgun’s five-lookup SPF include off your root record, separates the reputation of app mail from your staff mail, and still aligns with your root domain under relaxed DMARC.
Do I need the Mailgun MX records?
Yes, if you want Mailgun to receive mail for the sending domain (bounces, replies and inbound routes). Put them on the sending subdomain, never on a root domain whose mail is handled elsewhere.
Does the tracking CNAME affect DMARC?
No. It only serves open, click and unsubscribe links on your own subdomain. DMARC depends on SPF and DKIM.
Are EU and US Mailgun records different?
The MX records and the tracking CNAME are: EU domains use mxa.eu.mailgun.org, mxb.eu.mailgun.org and eu.mailgun.org. The SPF include (mailgun.org) is the same, and the DKIM record is specific to your domain either way.