Editorial illustration of verifying a sending domain with an envelope and three authentication seals

Your first email is ready, but domain authentication is holding things up. What do all those abbreviations actually mean?

Authentication lets receiving email services check that Omnisend is allowed to send using your domain. The process is: choose a domain, update its DNS records, verify it, and confirm which emails will use it.

This guide uses official documentation checked on September 8, 2026, with suggested worksheets and checks to help you keep your existing support email working. We haven't changed a merchant's DNS or tested a live sending account.

Authentication doesn't create an email inbox

Owning an email address and authorizing a marketing platform to send email are different jobs.

Your sender address, inbox, and domain authentication
ItemWhat it doesWhat to check
Sender addressIdentifies the sender your customer seesA recognizable store name and address
Inbox and reply-toReceive customer responsesSomeone can read and answer replies
Domain authenticationLets receiving services check the sending domainVerification status and actual domain usage

Adding a domain to Omnisend doesn't create a standalone mailbox. Keep your existing email service. If you don't set a separate reply-to address, Omnisend uses your sender address for replies. Omnisend's sender and reply-to guide

Still choosing an email platform? Our Omnisend overview explains its features and uses. If you're already using it, continue with the setup preparation below.

Gather the right access before changing anything

DNS holds settings for your domain. Your domain registrar and your active DNS provider may be different companies, so first establish which dashboard controls the live records.

Have these four things ready:

  1. Access to the correct store in Omnisend.
  2. Access to its active DNS settings, or the person who manages them.
  3. Your intended branded sender address and a way to receive its verification email.
  4. A record of your existing email providers, sending platforms, and DNS settings.

If someone else manages your DNS, ask them to add the authentication records generated by Omnisend for your domain using their own account.

Where each step happens: an EC AI Lab planning diagram
  1. OmnisendChoose the domain and review its generated records.
  2. Your DNS providerCompare existing settings and apply the required changes.
  3. Back in OmnisendCheck verification and which emails will use the domain.
  4. A receiving inboxCheck the sender, authentication results, and reply destination.

Understand SPF, DKIM, and DMARC

You don't need to memorize the acronyms. It helps to know what each setting is responsible for.

What the three authentication methods do
NamePurposeSetup reminder
SPFIdentifies servers authorized to sendDon't create duplicate SPF records at the same name
DKIMUses a digital signature to check the sender and message integrityUse the name, type, and value generated for your setup
DMARCChecks alignment with the visible sender domain and defines how authentication failures should be handledReview the policy already in use before changing it

These are short explanations, not replacement settings. Use Omnisend's authentication guide alongside the values shown in your own account.

Another store's DKIM value or a generic SPF example isn't a ready-to-paste configuration for your store. The right records depend on your domain and existing services.

Get the records for your domain

In Omnisend, open Store settings → Domains → Add domain → Email. Choose your DNS provider and sending domain, then compare the generated records with your current DNS. Official domain setup steps

Use a small worksheet to keep the work clear. This filled example contains planning notes, not DNS values.

A sample handoff between the store owner and DNS administrator
ItemExample entry
GoalSend the welcome email using the store's branded sender
ScopeRecord the selected Omnisend store and sending domain
DNS ownerThe website maintainer also checks the existing email setup
Record of changesPrevious settings; required record types, names, and values; change time
Domain usageAutomations for this setup; review active emails first
Completion checksVerification, usage, sender details, and incoming replies

A subdomain is another option, but creating a new name doesn't automatically give it a working inbox. Agree on how to separate marketing and existing email with your DNS administrator before choosing it.

Update DNS without disrupting existing email

DNS providers differ in whether their Name field expects a full domain name or only its first part. Check the saved record name so your domain hasn't been appended twice.

Keep authentication records separate in your mind from MX records, which route incoming email. Starting Omnisend authentication isn't a reason to delete your existing MX records, website records, or another service's DKIM settings.

If SPF already exists at that name, check whether it needs to be combined with the new sending authorization. Don't just add a second SPF record. Preserve the services you still use. SPF also has a DNS lookup limit; counting visible lines isn't enough to check it. If the setup is complicated, give your administrator the existing value and the exact error. Omnisend's SPF troubleshooting guide

Likewise, don't weaken an existing DMARC reject or quarantine policy simply to match a setup example. Review how a change would affect other senders first.

Verify the domain and check where it's used

After saving DNS changes, select Finish verification in Omnisend. The current setup lets you choose Campaigns and Automations; the domain is applied automatically after verification. Selecting Automations also affects active automation and scheduled emails, so review those first.

Verified means authenticated; domain usage still needs checking. If you skipped the usage choices, assign the domain under Domains → Domain usage. Allow time for DNS changes: the official guide says verification can take up to 48 hours. Verification and domain usage

Then check Store settings → Email addresses. Add and verify your branded sender address if needed. If replies should go elsewhere, check that setting too. Sender address setup

A test email doesn't prove your custom domain is being used

Omnisend's regular test emails use its shared domain. They're useful for reviewing the design, but receiving one doesn't confirm your custom sending domain. The test-email limitation

For that check, arrange a small real send addressed only to inboxes your team controls. Review subscription status, audience selection, and sending allowances; check the audience again before sending. Inspect the delivered message's sender and authentication results, then reply to confirm the response reaches the right inbox.

Troubleshoot the symptom before adding more records

What to check when setup doesn't look right
SymptomCheck firstNext step
Not Found remainsActive DNS provider, name, value, and propagation timeReview the exact failing item with your DNS administrator
Duplicate SPF recordsSPF entries at the same name and services still sendingAgree on a combined configuration that preserves those senders
Verified, but unavailableDomain usage and the sender address's domainCheck assignment to that campaign or automation
Missing customer repliesReply-to setting, receiving inbox, and responsible personSend a reply from a controlled inbox and trace it

Review every record requested by your verification screen. Don't ignore a failed item because another one passed. If the issue isn't clear, send Omnisend support the domain and the error details.

Authentication doesn't guarantee inbox placement. Avoid suddenly increasing volume; review Omnisend's domain warm-up guidance before expanding sends to engaged subscribers.

Once the sender, reply destination, and responsible person are clear, move on to your first welcome email. Our pricing guide explains how to think about sending allowances.

See whether Omnisend fits your businessFree plan500 emails a month, up to 250 contactsNo credit card requiredTry Omnisend's free plan