Pointing a Porkbun domain at your newsletter
Porkbun holds every record Issue Mint asks for, including the one on the root of the domain. Porkbun offers an ALIAS record type, which resolves the target and answers with its addresses, and Issue Mint accepts that for the website and click tracking records.
None of this is needed to start. A newsletter publishes and sends from the day you sign
up, on its {slug}.issuemint.com address, and adding a domain moves the website and
the sending onto yours.
Where the DNS records screen is
Porkbun keeps DNS on the domain’s own page. Sign in, open Domain Management, and follow the DNS link beside the domain, or open its details and scroll to DNS records. The form at the top adds a record and the list underneath is what the domain already has.
The form asks for Type, Host, Answer and TTL, with a Priority box appearing for MX.
Porkbun shows your domain beside the Host field and appends it, so Host takes the
prefix on its own: www, go, send, _dmarc, _acme-challenge.go. An empty Host
field means the domain itself.
What Porkbun calls each field
Issue Mint’s Value column is Porkbun’s Answer field, and Issue Mint’s Host column is Porkbun’s Host field. Type is the same word in both places.
The MX record on send is the only row with a fourth thing to enter: 10 goes in
Priority and the target goes in Answer. TTL can stay at Porkbun’s default, because
Issue Mint queries public resolvers and reads whatever they currently hold.
The records to add
Seven records exist the moment you add the domain.
| Record | Type | Host | Value |
|---|---|---|---|
| Website (apex) | CNAME | @ | sites.issuemint.com |
| Website (www) | CNAME | www | sites.issuemint.com |
| Click tracking | CNAME | go | t.issuemint.com |
| Certificate validation | CNAME | _acme-challenge | the value shown in your domain tab |
| Certificate validation | CNAME | _acme-challenge.www | the value shown in your domain tab |
| Certificate validation | CNAME | _acme-challenge.go | the value shown in your domain tab |
| DMARC policy (optional) | TXT | _dmarc | v=DMARC1; p=none; |
Copy the values from Settings, then Domain and DNS, rather than from this page. The
three _acme-challenge records carry an identifier unique to your account, so no
documentation page can print them, and every value in the domain tab has a copy button
beside it. The record on go is what serves
click tracking links from your own domain instead of ours,
and what each record is for covers the rest, including which
ones are optional.
The record on the bare domain
Enter the root record as an ALIAS with the Host field empty and the target Issue Mint shows for it in the Answer field.
Issue Mint lists that record as a CNAME and accepts an ALIAS, because the two say the
same thing. A CNAME may not sit at the root of a zone beside its NS and SOA records, so
every provider that supports the root at all resolves the target itself and answers
with addresses instead. Issue Mint compares those addresses against the target’s own
and verifies the record. The www and go records work either way at Porkbun, so a
plain CNAME is fine for both.
The three certificate records are the exception and must stay real CNAMEs. Cloudflare follows them itself to renew your certificate, so a flattened one is genuinely broken rather than an acceptable substitute.
The sending records, which arrive later
Five more records appear once Amazon has handed back your DKIM tokens, which happens on its own shortly after the domain is added.
| Record | Type | Host | Value |
|---|---|---|---|
| DKIM signing | CNAME | the first token shown in your domain tab, then ._domainkey | the matching dkim.amazonses.com value |
| DKIM signing | CNAME | the second token, then ._domainkey | the matching dkim.amazonses.com value |
| DKIM signing | CNAME | the third token, then ._domainkey | the matching dkim.amazonses.com value |
| Custom MAIL FROM | MX priority 10 | send | feedback-smtp.eu-west-1.amazonses.com |
| SPF for MAIL FROM | TXT | send | v=spf1 include:amazonses.com ~all |
Each DKIM host is a long token followed by ._domainkey, and Porkbun appends the
domain, so the Host field takes the token and ._domainkey and nothing else. Use the
copy button rather than reading the token off the screen. Until all three verify, issues
go out from our address; after they do, they come from yours, which is what
sending from your own domain means in practice.
The MX and TXT records both sit on send, a subdomain, so mail addressed to your domain
itself is unaffected by all of this. Whatever mailbox provider you use on the root can
stay exactly as it is.
After you save
Porkbun usually publishes a change within a minute or two. Issue Mint checks a newly added domain every ten minutes for its first two days and hourly after that, and Verify now forces a check immediately.
Certificates issue on their own once the _acme-challenge records resolve, and the
HTTPS card on the domain tab tracks each hostname separately. If a record you are sure
about will not verify,
the order to check things in starts with
the cause that turns out to be the real one most often.
Questions
Should the root record be an ALIAS or a CNAME?
An ALIAS. Porkbun offers both, and a CNAME on an empty Host is refused because a CNAME may not sit at the root of a zone. Issue Mint lists the record as a CNAME because that is what it means, and accepts the addresses an ALIAS answers with.
Does Porkbun's default TTL of 600 cause any problem?
No. Issue Mint reads public DNS and does not mind what the TTL is. A short TTL only means a change you make later spreads sooner, which is mildly useful while you are still editing records.
Try it on your own list.
14 days, every feature, no card. Sending works from the moment you sign up.
Start your trial