Browse the documentation

A DNS record will not verify

Work down this list in order. It is sorted by how often each cause turns out to be the real one, and the first item accounts for more of these than everything below it put together. If you have not added the records yet, the records page is the place to start instead.

Is the record proxied through Cloudflare?

On Cloudflare, every record Issue Mint asks for must be set to DNS only, which is the grey cloud rather than the orange one.

A proxied record answers with Cloudflare’s own addresses rather than the value you typed. We cannot match a value we cannot see, so a record you entered perfectly reads as missing. Open the record in Cloudflare, click the cloud so it turns grey, save, and hit Verify now.

Has the change actually published?

DNS changes take anything from a minute to a few hours to spread, depending on your provider.

Issue Mint queries the public resolvers at 1.1.1.1 and 8.8.8.8 rather than asking your provider directly, so what it sees is what the rest of the internet sees. That is usually a few minutes behind the moment you pressed save, and occasionally a good deal more. If you have just added the record, give it an hour before treating it as a problem.

Does the table say what it found instead?

When a record resolves to the wrong value, Issue Mint shows what it found underneath what it expected. That line is the fastest diagnosis available, and it is worth reading before changing anything.

Two patterns come up repeatedly:

  • The domain has been appended twice. Some providers add the domain for you, so entering go.example.com in the Host field produces go.example.com.example.com. Enter just go and let the provider complete it. Others want the whole hostname. The found value tells you which kind you are dealing with.
  • The value has a trailing dot, or is missing one. Both forms are usually fine and neither is the problem, but a value wrapped in quotes in a CNAME field is.

Is there an old record still there?

Two records on the same host is the case that looks most like nothing happening.

If www already pointed somewhere before you added your newsletter, and the old record is still present alongside the new one, the resolver may answer with either. Delete the old one rather than editing around it. The same goes for a _dmarc or send record left over from a previous email provider.

Is it the bare domain that is failing?

If everything verifies except the apex, your registrar probably cannot put a CNAME at the root of a domain.

Not every provider can, and there is no way round it from either end. When Issue Mint detects this, the domain tab offers www.yourdomain.com as your address instead: one click, reversible, and the apex records stay in the table and keep being checked. If you later move to a registrar that supports it, you can switch back. Neither choice affects click tracking or your archive, which run on the canonical address either way.

Is it a certificate record?

The three _acme-challenge records are what keep your HTTPS certificate renewing, and they must not be proxied or flattened.

Cloudflare has to follow those CNAMEs itself in order to renew, so unlike the website records they cannot come back as addresses. If a hostname resolves but your browser shows a certificate warning, this is almost always why. The HTTPS card on the domain tab shows each hostname’s certificate state separately from the record’s own state, and it quotes Cloudflare’s error directly when there is one, because their wording is more specific than anything we would write.

Is it a DKIM record?

DKIM records carry tokens Amazon mints for your domain, and they are long enough that copying them by hand goes wrong.

Use the copy button beside each value rather than selecting the text. If your provider appends the domain automatically, the host is the token followed by ._domainkey and nothing more. Like the certificate records, these must be real CNAMEs: mailboxes read them directly.

Still stuck

Write to us with the domain name and we will look at what our resolvers are seeing. The one thing worth including is a screenshot of the record as your provider shows it, because the difference between what you meant to type and what the field contains is the thing neither of us can see from here.

Questions

How long should I wait before assuming something is wrong?

An hour is a reasonable point to start looking for a mistake. Most providers publish a change within minutes, but a few take a couple of hours, and Issue Mint keeps checking a newly added domain every ten minutes for the first two days regardless.

Does an unverified record stop my newsletter working?

No. Your website stays on its issuemint.com address and click tracking runs on our host until the records verify. Sending carries on from our address until the sending records verify, and then issues come from yours.

Last updated 21 August 2026.

Try it on your own list.

14 days, every feature, no card. Sending works from the moment you sign up.

Start your trial