Adding your records at Cloudflare
Every record Issue Mint asks for works at Cloudflare, and every one of them has to be set to DNS only, which is the grey cloud rather than the orange one. Nothing else about Cloudflare is unusual: the record set is the same set every provider gets, and what each record does is the same wherever you add it.
Your newsletter is already live on its issuemint.com address while you do this, and it stays there until the records verify. Adding a domain is what moves the website and archive you get onto your own.
Open the DNS records screen
Sign in to Cloudflare, choose the site for your domain, then open DNS followed by Records. Cloudflare calls a record’s host Name and a CNAME’s destination Target, and it shows you the full hostname a Name will become as you type.
Add record is the button. Type, Name, Target, Proxy status and TTL are the fields, and TTL can stay on Auto for all of these.
Add the website and tracking records
Add the first three rows as CNAME records. In the Name field, @ means the domain
itself, and www and go are typed as bare labels because Cloudflare completes them
with your domain.
| Record | Type | Host | Value |
|---|---|---|---|
| Website (apex) | CNAME | @ | sites.issuemint.com |
| Website (www) | CNAME | www | sites.issuemint.com |
| Click tracking | CNAME | go | t.issuemint.com |
The go record is the one that puts click tracking on
your own domain instead of ours.
Set every record to DNS only
Click the cloud icon beside each record so it turns grey and reads DNS only, then save. Cloudflare offers that toggle on the records it is able to proxy and leaves it off the rest, so a TXT or MX record has nothing to set.
Add the certificate and DMARC records
The three certificate records are CNAMEs on _acme-challenge hosts, and their values
carry an identifier that only exists inside your account, so copy each one from the
domain tab rather than typing it. They are what keeps the HTTPS certificate for each
hostname renewing without anybody thinking about it.
| Record | Type | Host | Value |
|---|---|---|---|
| Certificate validation | CNAME | _acme-challenge | the value shown in your domain tab |
| Certificate validation | CNAME | _acme-challenge.www | the value shown in your domain tab |
| Certificate validation | CNAME | _acme-challenge.go | the value shown in your domain tab |
| DMARC policy (optional) | TXT | _dmarc | v=DMARC1; p=none; |
DMARC is a suggestion rather than a requirement. If _dmarc already exists on your
domain, leave it as it is.
Add the sending records when they appear
Five more records turn up in the domain tab a little after you add the domain, once Amazon has minted your DKIM tokens. They are what let issues come from your own address rather than ours.
| Record | Type | Host | Value |
|---|---|---|---|
| DKIM signing | CNAME | the first token shown in your domain tab, then ._domainkey | the matching dkim.amazonses.com value |
| DKIM signing | CNAME | the second token, then ._domainkey | the matching dkim.amazonses.com value |
| DKIM signing | CNAME | the third token, then ._domainkey | the matching dkim.amazonses.com value |
| Custom MAIL FROM | MX priority 10 | send | feedback-smtp.eu-west-1.amazonses.com |
| SPF for MAIL FROM | TXT | send | v=spf1 include:amazonses.com ~all |
Use the copy button beside each DKIM value: they are long, they belong to your domain alone, and copying one by hand goes wrong. Cloudflare must not proxy or flatten these, because mailboxes read them directly. What changes when they pass is covered in sending from your own domain.
Does the bare domain work at Cloudflare?
Yes. Cloudflare flattens a CNAME at the root of a domain and answers with addresses instead, which is correct behaviour, and Issue Mint accepts it for the website and tracking records.
Leave CNAME flattening on its default, which flattens at the root only. Flattening
every CNAME in the zone would flatten the _acme-challenge records too, and those
have to stay real CNAMEs for your certificate to renew.
What happens after you save
Issue Mint rechecks a newly added domain every ten minutes for its first two days and
hourly after that, reading the public resolvers at 1.1.1.1 and 8.8.8.8 rather than
asking Cloudflare directly. Verify now, at the top of the domain tab, checks
immediately if you would rather not wait.
Questions
Do I need a Cloudflare account to use my own domain?
No. Issue Mint works with whatever provider already answers for your domain, and the record set is identical everywhere. Cloudflare has a page of its own because its proxy setting changes what a record answers with, which no other provider does.
Can I leave my other records proxied?
Yes. Only the records Issue Mint checks have to be on DNS only. Everything else in the zone, including a proxied website on another hostname, stays exactly as you have it.
Try it on your own list.
14 days, every feature, no card. Sending works from the moment you sign up.
Start your trial