Ontiscal
Resend Email Infrastructure Guide

Authenticate your sending domain in Resend with the correct DNS setup

This guide explains how to connect and verify a custom sending domain in Resend by adding the DNS records generated in your dashboard. A correctly configured domain helps you send email with a branded identity and a more reliable technical setup.

Why domain verification matters

A verified custom domain helps align your email infrastructure with your brand and confirms that the sending environment is properly authorized through DNS. It also creates a cleaner foundation for transactional email, newsletters, and outbound campaign setups.

Branded sender identity

A verified custom domain lets you send from addresses aligned with your brand instead of relying on a generic sender setup. This supports a more professional presentation across marketing and transactional email.

Stronger authentication

A correct Resend setup usually includes DNS records for SPF, DKIM, and related routing or bounce handling. These records help mailbox providers validate the sending source.

Cleaner separation

Many senders prefer using a dedicated sending subdomain so that their main website identity and their campaign infrastructure stay clearly separated and easier to manage.

Typical DNS records used in Resend

Resend shows the exact live values inside your own dashboard, and those values can vary by region or account configuration. The examples below show the common structure, but the production values should always be copied from your account.

Record Type Purpose Host / Name Value Format
TXT SPF authorization on sending subdomain send.yourdomain.com v=spf1 include:amazonses.com ~all
TXT or CNAME DKIM signing configuration resend._domainkey.send.yourdomain.com provider-generated DKIM value
MX or CNAME Return-Path or bounce handling send.yourdomain.com or custom path provider-generated target
TXT DMARC policy _dmarc.yourdomain.com v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
v=spf1 include:amazonses.com ~all
Always copy the DNS values exactly from the Resend dashboard. Small hostname or formatting errors can prevent verification from succeeding.

Step-by-step setup

The usual workflow is simple: add the domain in Resend, copy the generated DNS records, publish them in your DNS provider, then wait for verification to complete before sending live email.

1

Open the Domains page in Resend

Log into your Resend account and go to the area where custom sending domains are managed.

2

Enter the domain or sending subdomain

Add the domain you want to use for your email operations. Many senders choose a dedicated subdomain for better organization and brand separation.

3

Copy the generated DNS records

Open the records section for the new domain and copy each DNS value exactly as shown in your account.

4

Publish the records in your DNS provider

Add the SPF, DKIM, and any routing or bounce-related records in the DNS panel where your domain is managed.

5

Add a DMARC record

A DMARC policy helps strengthen your email authentication setup and supports better domain protection.

6

Wait for verification and test

After the records propagate, return to Resend and complete the verification process before starting your campaigns or transactional sends.

Important practical tips

Use a dedicated sending subdomain

This keeps your main brand domain separate from campaign infrastructure and makes long-term email operations easier to manage.

Match records exactly

DNS authentication works only when the record names and values are entered correctly, so copying and pasting directly is safer than manual typing.

Allow time for propagation

Some domains verify quickly, while others take longer depending on the DNS provider and global propagation timing.

Check your public DNS

If verification is delayed, inspect the public DNS results to confirm that all records are visible and published exactly as expected.

Common host examples:
send
resend._domainkey.send
_dmarc
The safest workflow is to add the domain in Resend, paste the exact DNS values into your DNS manager, wait for propagation, verify the domain, and only then start live email sending.

Common mistakes to avoid

Using guessed DNS values

Example records are useful for learning, but real production values should come from the live platform dashboard.

Misplacing the sending subdomain

Some DNS panels automatically append the root domain, so it is important to review the saved hostname carefully after each record is added.

Skipping DMARC

A complete email authentication setup is stronger when DMARC is included together with SPF and DKIM.

Testing too early

Verification may fail temporarily even when the records are correct, simply because DNS propagation is still in progress.

Frequently asked questions

Can I use a subdomain instead of my main domain?

Yes. A dedicated sending subdomain is often a practical choice for cleaner email infrastructure and better operational separation.

How long does verification usually take?

It can be quick, but it may also take longer depending on DNS propagation and your provider’s refresh timing.

What records do I normally need?

A typical setup includes SPF, DKIM, DMARC, and sometimes routing or bounce-related records depending on the sending configuration.

What should I do if the domain does not verify?

Double-check every host and value, confirm the records are visible publicly, and retry after allowing more time for propagation.

Contact

Contact ontiscal.com if you want to rent quality and aged domain names configured through custom DNS records working for email platforms like Resend or Brevo.