Browse the documentation

The records, and what each one does

Issue Mint generates your records the moment you add a domain, and shows them in Settings, then Domain and DNS, as a table with a copy button on every value. This page explains what each one is for, so that adding them is not an act of faith.

You do not have to add any of them. A newsletter works on its {slug}.issuemint.com address from the day you sign up, and it carries on working whatever you skip here. Adding a domain moves both your archive website and the sending onto it, which is why there is one visit to your DNS provider rather than two.

Where to find them

Open Settings, then the Domain and DNS tab, and enter your domain without https:// and without www. Issue Mint generates the record set immediately and starts checking for them. The records still to do are sorted to the top of the table, and the count above it tells you how many are left.

Add them wherever your DNS lives, which is your registrar unless you have moved it somewhere else. Every provider words things slightly differently: the Host column is often called Name, and @ means the domain itself.

The records you get straight away

These seven are generated as soon as the domain is added.

The records generated when a domain is added
Record Type Host Value Why
Website (apex) CNAME @ sites.issuemint.com Points your domain at your newsletter website.
Website (www) CNAME www sites.issuemint.com Makes the www version work too.
Click tracking CNAME go t.issuemint.com Serves click-tracking links from your own domain instead of ours, which reads better and helps deliverability.
Certificate validation CNAME _acme-challenge the value shown in your domain tab Lets us keep the HTTPS certificate for this hostname renewed automatically. Add it once and you never hear about it again.
Certificate validation CNAME _acme-challenge.www the value shown in your domain tab Lets us keep the HTTPS certificate for this hostname renewed automatically. Add it once and you never hear about it again.
Certificate validation CNAME _acme-challenge.go the value shown in your domain tab Lets us keep the HTTPS certificate for this hostname renewed automatically. Add it once and you never hear about it again.
DMARC policy (optional) TXT _dmarc v=DMARC1; p=none; Tells mailboxes what to do with mail that fails the checks above. We suggest a monitor-only policy to start.

The records that arrive later

Five more appear once your domain has been registered with Amazon SES, which happens on its own shortly after you add the domain. They are what let your issues come from your own address rather than ours.

The records that authorise sending from your domain
Record Type Host Value Why
DKIM signing CNAME the first token shown in your domain tab, then ._domainkey the matching dkim.amazonses.com value Lets mailboxes verify your issues really came from you. Without all three, expect the spam folder.
DKIM signing CNAME the second token, then ._domainkey the matching dkim.amazonses.com value Lets mailboxes verify your issues really came from you. Without all three, expect the spam folder.
DKIM signing CNAME the third token, then ._domainkey the matching dkim.amazonses.com value Lets mailboxes verify your issues really came from you. Without all three, expect the spam folder.
Custom MAIL FROM MX priority 10 send feedback-smtp.eu-west-1.amazonses.com Routes bounce notifications back to SES so we can clean your list automatically.
SPF for MAIL FROM TXT send v=spf1 include:amazonses.com ~all Authorises Amazon SES to send bounces for your domain.

The DKIM records are the ones worth not putting off. Without all three, a good share of your issues will land in spam, because a mailbox that cannot verify a signature has nothing to go on but the reputation of the sending address. If a record refuses to go green, work down the list of things that usually turn out to be wrong rather than guessing.

DMARC is the exception on this list: it is a suggestion, not a requirement, and Issue Mint never overwrites a policy you already have. If _dmarc already exists on your domain, leave it alone. The suggested p=none is monitor-only, which is the right place to start and does nothing to your mail on its own.

What happens while they are pending

Nothing breaks. The website records and the sending records verify independently of each other, and neither one holds the other up.

Until the website records verify, your site stays on its issuemint.com address. Until the tracking record verifies, click tracking runs on our host instead of go.yourdomain.com. Until the sending records verify, issues go out from our address, and the moment they do verify your issues start coming from yours and we email you to say so. You do not have to do anything to make that happen.

When a record verifies as something else

Three of these records may legitimately come back as an A record rather than the CNAME you entered, and Issue Mint accepts that: the two website records and the tracking record. Cloudflare in particular flattens CNAMEs at the root of a domain and answers with addresses instead, which is correct behaviour and verifies green.

The certificate and DKIM records must not be flattened. Cloudflare has to follow the first set itself in order to renew your certificate, and mailboxes read the second set directly, so in both cases something other than us needs to see a real CNAME.

If the bare domain will not point at us

Some registrars cannot put a CNAME at the root of a domain, and there is no way round it from either end. When that happens, www verifies and the apex does not, and Issue Mint offers www.yourdomain.com as your address instead. It is one click, it is reversible, and the apex records stay in the table and keep being checked, so if you later move to a registrar that supports it you can switch back.

Removing a domain

Removing a domain puts your website back on its issuemint.com address and moves tracking links back to our host. Links in issues you have already sent, which point at go.yourdomain.com, will stop working. Issue Mint asks you to type the hostname to confirm, for that reason.

Questions

Do I have to add all of them?

No. The two website records are the only ones a working website needs. The certificate records are needed for HTTPS on each hostname, the DKIM and MAIL FROM records are what let issues send from your own address, and DMARC is a suggestion. Your newsletter keeps working on its issuemint.com address whatever you skip.

How long do they take to work?

Anything from a minute to a few hours, depending on your provider. Issue Mint rechecks a newly added domain every ten minutes for the first two days, then hourly, so you do not have to sit on the page waiting.

Why do some values say to look in the domain tab?

Those records carry identifiers that only exist inside your account. The certificate records include a per-zone identifier, and the DKIM records include tokens Amazon mints for your domain specifically. No documentation page can print them, so the domain tab shows yours with a copy button beside each one.

Can I use a subdomain instead of my whole domain?

Yes. Add the subdomain as the domain, for example links.example.com, and the record set is generated against that instead. This is worth doing if the apex of your domain is already pointing at a website you do not want to move.

On the product side: what the archive website gives you.

Last updated 21 August 2026.

Try it on your own list.

14 days, every feature, no card. Sending works from the moment you sign up.

Start your trial