Verify a domain
Pigeon accepts mail only from a domain you added and verified. The table on the domain card is the list to publish.
1. Add the domain
Open Domains and add the hostname you will put in the From address. That can be the apex, example.com, or a subdomain such as mail.example.com. Pigeon then shows one row per DNS record. Copy those rows. The samples in this guide use example.com. The ownership token and the three DKIM tokens are different for every domain.
2. Publish the records
Create the records at the company that hosts DNS for that domain. That is whoever answers the domain's nameservers. If the panel adds the zone for you, enter the host relative to the zone: _pigeon.example.com becomes _pigeon.
- Add a TXT record on _pigeon.yourdomain. The value is pigeon-verify= plus the token on the domain card. The token starts with pgv_.
- Add a TXT record on the domain itself: v=spf1 include:amazonses.com ~all. If an SPF record already exists, add include:amazonses.com inside it. A domain can have only one SPF TXT.
- Add a TXT record on _dmarc.yourdomain: v=DMARC1; p=none;
- Add each DKIM CNAME from the domain card. The host is token._domainkey.yourdomain and the target is token.dkim.amazonses.com. There are three. If the DNS host offers a proxy, leave it off.
3. Wait, then press Verify
New records are usually visible within a few minutes. A previous long TTL can make an update slower. 300 seconds is a good TTL for these records. Then press Verify on the domain card.
When Amazon SES is configured, Verify succeeds after SES reports the identity is ready to send. SES needs the ownership TXT, the SPF record, DMARC, and the three DKIM CNAMEs.
Without AWS credentials, Verify succeeds when the _pigeon TXT matches the token on the card. Delivery stays in the local mailbox until SES is connected. Publish SPF, DMARC, and the DKIM CNAMEs anyway so the same records work once SES is on.
4. Send
After the domain is verified, the From address has to use that hostname, for example Ada <ada@example.com>. A different domain, or a subdomain you did not add, is rejected.
See each record with example hosts and values