Browse the documentation

Adding your records at Cloudflare

Every record Issue Mint asks for works at Cloudflare, and every one of them has to be set to DNS only, which is the grey cloud rather than the orange one. Nothing else about Cloudflare is unusual: the record set is the same set every provider gets, and what each record does is the same wherever you add it.

Your newsletter is already live on its issuemint.com address while you do this, and it stays there until the records verify. Adding a domain is what moves the website and archive you get onto your own.

Open the DNS records screen

Sign in to Cloudflare, choose the site for your domain, then open DNS followed by Records. Cloudflare calls a record’s host Name and a CNAME’s destination Target, and it shows you the full hostname a Name will become as you type.

Add record is the button. Type, Name, Target, Proxy status and TTL are the fields, and TTL can stay on Auto for all of these.

Add the website and tracking records

Add the first three rows as CNAME records. In the Name field, @ means the domain itself, and www and go are typed as bare labels because Cloudflare completes them with your domain.

The website and tracking records
Record Type Host Value
Website (apex) CNAME @ sites.issuemint.com
Website (www) CNAME www sites.issuemint.com
Click tracking CNAME go t.issuemint.com

The go record is the one that puts click tracking on your own domain instead of ours.

Set every record to DNS only

Click the cloud icon beside each record so it turns grey and reads DNS only, then save. Cloudflare offers that toggle on the records it is able to proxy and leaves it off the rest, so a TXT or MX record has nothing to set.

Add the certificate and DMARC records

The three certificate records are CNAMEs on _acme-challenge hosts, and their values carry an identifier that only exists inside your account, so copy each one from the domain tab rather than typing it. They are what keeps the HTTPS certificate for each hostname renewing without anybody thinking about it.

Certificate validation and DMARC
Record Type Host Value
Certificate validation CNAME _acme-challenge the value shown in your domain tab
Certificate validation CNAME _acme-challenge.www the value shown in your domain tab
Certificate validation CNAME _acme-challenge.go the value shown in your domain tab
DMARC policy (optional) TXT _dmarc v=DMARC1; p=none;

DMARC is a suggestion rather than a requirement. If _dmarc already exists on your domain, leave it as it is.

Add the sending records when they appear

Five more records turn up in the domain tab a little after you add the domain, once Amazon has minted your DKIM tokens. They are what let issues come from your own address rather than ours.

The records that authorise sending from your domain
Record Type Host Value
DKIM signing CNAME the first token shown in your domain tab, then ._domainkey the matching dkim.amazonses.com value
DKIM signing CNAME the second token, then ._domainkey the matching dkim.amazonses.com value
DKIM signing CNAME the third token, then ._domainkey the matching dkim.amazonses.com value
Custom MAIL FROM MX priority 10 send feedback-smtp.eu-west-1.amazonses.com
SPF for MAIL FROM TXT send v=spf1 include:amazonses.com ~all

Use the copy button beside each DKIM value: they are long, they belong to your domain alone, and copying one by hand goes wrong. Cloudflare must not proxy or flatten these, because mailboxes read them directly. What changes when they pass is covered in sending from your own domain.

Does the bare domain work at Cloudflare?

Yes. Cloudflare flattens a CNAME at the root of a domain and answers with addresses instead, which is correct behaviour, and Issue Mint accepts it for the website and tracking records.

Leave CNAME flattening on its default, which flattens at the root only. Flattening every CNAME in the zone would flatten the _acme-challenge records too, and those have to stay real CNAMEs for your certificate to renew.

What happens after you save

Issue Mint rechecks a newly added domain every ten minutes for its first two days and hourly after that, reading the public resolvers at 1.1.1.1 and 8.8.8.8 rather than asking Cloudflare directly. Verify now, at the top of the domain tab, checks immediately if you would rather not wait.

Questions

Do I need a Cloudflare account to use my own domain?

No. Issue Mint works with whatever provider already answers for your domain, and the record set is identical everywhere. Cloudflare has a page of its own because its proxy setting changes what a record answers with, which no other provider does.

Can I leave my other records proxied?

Yes. Only the records Issue Mint checks have to be on DNS only. Everything else in the zone, including a proxied website on another hostname, stays exactly as you have it.

On the product side: what the archive website gives you.

Last updated 21 August 2026.

Try it on your own list.

14 days, every feature, no card. Sending works from the moment you sign up.

Start your trial