Skip to main content
Confirm your published DNS records so the domain can send.
Before you start: publish the five records from the domain’s DNS Records tab. DNS records explains each one and how to publish it at the common DNS providers.

What verification checks

Brudcast looks up each record in public DNS and compares the answer with the expected value. Letter case and a trailing dot are ignored.
  • The domain’s status depends on one record: the SPF delegation CNAME at brd.spf.<your domain>. When it matches, the domain becomes Verified and can send. When it doesn’t, the domain shows Failed.
  • DKIM, DMARC and tracking are checked and shown separately. They don’t change the domain’s status, but mail without published DKIM records fails DKIM at receiving servers. Get all four green.

Run the check

1

Wait for DNS to update

2

Open the domain

Go to Channels > Email, open the Domains tab, and select the domain.
3

Select Verify DNS

Verify DNS is at the top right of the domain page. The check runs in the background, and the results appear on the page as they come in.
4

Read the results

The strip under the domain name shows DKIM, SPF, DMARC and Tracking, each marked Verified or Not yet verified. The DNS Records tab marks each record Verified or Unconfigured. If any of SPF, DKIM or DMARC is missing, a “Complete your domain setup” banner names them.
You can run the check as often as you like. There’s no penalty for a failed check. The first time a domain verifies or fails, the person who created the organization is emailed the result.

What each failure means

Here’s what a red result points at. The full answer for each one, with the ranked causes and the provider traps behind them, is in Email troubleshooting.
Why: the lookup of brd.spf.<your domain> didn’t return the expected target, usually a doubled name, a record in the wrong zone, or a Cloudflare record left proxied. Fix: The domain shows Failed after you run Verify DNS.
Why: one or both of brd1._domainkey and brd2._domainkey is missing, proxied, or points somewhere else. The domain still verifies, but your mail fails DKIM. Fix: DKIM stays “Not yet verified”.
Why: the _dmarc TXT record is missing, or a different DMARC record is there, and Brudcast compares the whole value. Fix: DMARC stays “Not yet verified”.
Why: the tracking CNAME is missing, or you changed the tracking hostname and haven’t published the new record yet. Fix: Tracking stays “Not yet verified”.
Why: your machine or a resolver in between may still be holding a cached answer. Fix: dig shows the right value but the check still fails.

After verification

Keep the records published

Treat the Brudcast records as permanent parts of your zone. If you remove or change one, receiving servers stop being able to authenticate your mail straight away. The dashboard only shows the change the next time you run Verify DNS.

Check DKIM from the API

The platform API can check the live DKIM record on its own, without rerunning every check: GET /api/v1/user/sending-domains/{id}/dkims/verify, with the domains:read scope. It returns propagated (the expected key is published) and mismatch (a different key is published). See the API reference.

Send your first email

Your domain can send. Use it from a campaign, the API or SMTP.

DNS records

What each record does.

DNS by provider

Fix a record at Cloudflare, Route 53, Namecheap, GoDaddy and others.

Email troubleshooting

Verification failures and sending errors.