Skip to content

Domains and deliverability

  1. Choose a domain in the connected Cloudflare account.
  2. Review Email Sending authorization and the proposed DNS changes.
  3. Verify SPF, DKIM and DMARC.
  4. Send a real message and inspect delivery events.
  • SPF and DKIM verification
  • DMARC policy and aggregate-report visibility
  • Bounce, complaint and suppression handling
  • Controlled warm-up budgets
  • Configuration drift and reputation diagnostics

No provider can guarantee inbox placement. CFsend exposes the configuration and delivery signals needed to identify preventable risk.

The console shows expected and observed DNS values. pending means the required record is absent or has not propagated; mismatch means a conflicting value exists; verified means the latest check found the required authorization. Do not add a second SPF record—merge authorized senders into one policy.

Use DKIM exactly as generated. Begin DMARC with reporting/monitoring when the domain has other senders, inspect aggregate reports, then move toward quarantine/reject only after alignment is understood. Bounce MX must continue pointing to the Runtime-owned handling path.

Send a real message, confirm delivered or an actionable rejection, and monitor hard bounce and complaint rates. Use warm-up controls for a new domain. A DNS check passing does not guarantee reputation or inbox placement; it proves configuration, while message events and DMARC reports provide operational evidence.