The records, and what each one does
Issue Mint generates your records the moment you add a domain, and shows them in Settings, then Domain and DNS, as a table with a copy button on every value. This page explains what each one is for, so that adding them is not an act of faith.
You do not have to add any of them. A newsletter works on its
{slug}.issuemint.com address from the day you sign up, and it carries on working
whatever you skip here. Adding a domain moves both
your archive website and the sending onto it, which is why
there is one visit to your DNS provider rather than two.
Where to find them
Open Settings, then the Domain and DNS tab, and enter your domain without https://
and without www. Issue Mint generates the record set immediately and starts
checking for them. The records still to do are sorted to the top of the table, and
the count above it tells you how many are left.
Add them wherever your DNS lives, which is your registrar unless you have moved it
somewhere else. Every provider words things slightly differently: the Host column is
often called Name, and @ means the domain itself.
The records you get straight away
These seven are generated as soon as the domain is added.
| Record | Type | Host | Value | Why |
|---|---|---|---|---|
| Website (apex) | CNAME | @ | sites.issuemint.com | Points your domain at your newsletter website. |
| Website (www) | CNAME | www | sites.issuemint.com | Makes the www version work too. |
| Click tracking | CNAME | go | t.issuemint.com | Serves click-tracking links from your own domain instead of ours, which reads better and helps deliverability. |
| Certificate validation | CNAME | _acme-challenge | the value shown in your domain tab | Lets us keep the HTTPS certificate for this hostname renewed automatically. Add it once and you never hear about it again. |
| Certificate validation | CNAME | _acme-challenge.www | the value shown in your domain tab | Lets us keep the HTTPS certificate for this hostname renewed automatically. Add it once and you never hear about it again. |
| Certificate validation | CNAME | _acme-challenge.go | the value shown in your domain tab | Lets us keep the HTTPS certificate for this hostname renewed automatically. Add it once and you never hear about it again. |
| DMARC policy (optional) | TXT | _dmarc | v=DMARC1; p=none; | Tells mailboxes what to do with mail that fails the checks above. We suggest a monitor-only policy to start. |
The records that arrive later
Five more appear once your domain has been registered with Amazon SES, which happens on its own shortly after you add the domain. They are what let your issues come from your own address rather than ours.
| Record | Type | Host | Value | Why |
|---|---|---|---|---|
| DKIM signing | CNAME | the first token shown in your domain tab, then ._domainkey | the matching dkim.amazonses.com value | Lets mailboxes verify your issues really came from you. Without all three, expect the spam folder. |
| DKIM signing | CNAME | the second token, then ._domainkey | the matching dkim.amazonses.com value | Lets mailboxes verify your issues really came from you. Without all three, expect the spam folder. |
| DKIM signing | CNAME | the third token, then ._domainkey | the matching dkim.amazonses.com value | Lets mailboxes verify your issues really came from you. Without all three, expect the spam folder. |
| Custom MAIL FROM | MX priority 10 | send | feedback-smtp.eu-west-1.amazonses.com | Routes bounce notifications back to SES so we can clean your list automatically. |
| SPF for MAIL FROM | TXT | send | v=spf1 include:amazonses.com ~all | Authorises Amazon SES to send bounces for your domain. |
The DKIM records are the ones worth not putting off. Without all three, a good share of your issues will land in spam, because a mailbox that cannot verify a signature has nothing to go on but the reputation of the sending address. If a record refuses to go green, work down the list of things that usually turn out to be wrong rather than guessing.
DMARC is the exception on this list: it is a suggestion, not a requirement, and
Issue Mint never overwrites a policy you already have. If _dmarc already exists on
your domain, leave it alone. The suggested p=none is monitor-only, which is the
right place to start and does nothing to your mail on its own.
What happens while they are pending
Nothing breaks. The website records and the sending records verify independently of each other, and neither one holds the other up.
Until the website records verify, your site stays on its issuemint.com address.
Until the tracking record verifies, click tracking runs on our host instead of
go.yourdomain.com. Until the sending records verify, issues go out from our
address, and the moment they do verify your issues start coming from yours and we
email you to say so. You do not have to do anything to make that happen.
When a record verifies as something else
Three of these records may legitimately come back as an A record rather than the CNAME you entered, and Issue Mint accepts that: the two website records and the tracking record. Cloudflare in particular flattens CNAMEs at the root of a domain and answers with addresses instead, which is correct behaviour and verifies green.
The certificate and DKIM records must not be flattened. Cloudflare has to follow the first set itself in order to renew your certificate, and mailboxes read the second set directly, so in both cases something other than us needs to see a real CNAME.
If the bare domain will not point at us
Some registrars cannot put a CNAME at the root of a domain, and there is no way
round it from either end. When that happens, www verifies and the apex does not,
and Issue Mint offers www.yourdomain.com as your address instead. It is one click,
it is reversible, and the apex records stay in the table and keep being checked, so
if you later move to a registrar that supports it you can switch back.
Removing a domain
Removing a domain puts your website back on its issuemint.com address and moves
tracking links back to our host. Links in issues you have already sent, which point
at go.yourdomain.com, will stop working. Issue Mint asks you to type the hostname
to confirm, for that reason.
Questions
Do I have to add all of them?
No. The two website records are the only ones a working website needs. The certificate records are needed for HTTPS on each hostname, the DKIM and MAIL FROM records are what let issues send from your own address, and DMARC is a suggestion. Your newsletter keeps working on its issuemint.com address whatever you skip.
How long do they take to work?
Anything from a minute to a few hours, depending on your provider. Issue Mint rechecks a newly added domain every ten minutes for the first two days, then hourly, so you do not have to sit on the page waiting.
Why do some values say to look in the domain tab?
Those records carry identifiers that only exist inside your account. The certificate records include a per-zone identifier, and the DKIM records include tokens Amazon mints for your domain specifically. No documentation page can print them, so the domain tab shows yours with a copy button beside each one.
Can I use a subdomain instead of my whole domain?
Yes. Add the subdomain as the domain, for example links.example.com, and the record set is generated against that instead. This is worth doing if the apex of your domain is already pointing at a website you do not want to move.
Try it on your own list.
14 days, every feature, no card. Sending works from the moment you sign up.
Start your trial