DNS records

These are the records on a domain card. Replace example.com with the hostname you added.

Type Host Value
TXT _pigeon.example.com pigeon-verify=pgv_your_token Proves you control the domain. Pigeon generates the token when you add the domain and shows it on that card. The value has to match exactly, including the pigeon-verify= prefix.
TXT example.com v=spf1 include:amazonses.com ~all Lets Amazon SES send for this hostname. If a v=spf1 TXT already exists, add include:amazonses.com to it. A second SPF record makes both of them fail.
TXT _dmarc.example.com v=DMARC1; p=none; Asks receivers to check SPF and DKIM and to report the results. p=none does not reject mail. Tighten it after you have seen the reports.
CNAME <token>._domainkey.example.com <token>.dkim.amazonses.com Publish all three DKIM rows from the card. The token in the host and the token in the target are the same. With SES connected, those tokens come from Amazon. Without it, Pigeon still shows three stable tokens for the domain.

How panels want the host

  • Cloudflare, Route 53, and Google Cloud DNS accept the full name or the label under the zone. Turn the Cloudflare proxy off for the DKIM CNAMEs so they stay DNS-only.
  • If you added mail.example.com, ownership is _pigeon.mail.example.com, SPF is on mail.example.com, DMARC is _dmarc.mail.example.com, and each DKIM host ends in ._domainkey.mail.example.com.
  • Publish the records on the same hostname you will use in From. Records on the parent domain do not verify a subdomain you added separately.

What Verify reads

Verify looks up the _pigeon TXT and compares it to pigeon-verify= and the token stored for that domain. When SES credentials are set, it also asks SES whether the identity is verified for sending. A mismatch shows DNS is not verified yet. Fix the row that differs from the card and try again.

Back to the verification steps

© 2026 Pigeon. Email on your Amazon SES account.