Deliverability•2 min read

Why is My Piisend Custom Domain Unverified? (SPF & DKIM Setup Guide)

Troubleshooting guide for unverified domain status in Piisend. Learn why custom email domains fail verification and how to correctly publish SPF, DKIM, and MX records.

Why is My Piisend Custom Domain Unverified? (SPF & DKIM Setup Guide)

When you add a custom sending domain or subdomain in the Piisend Dashboard to send transactional emails via our API, its status remains Unverified until your DNS provider publishes the required authentication records.

This troubleshooting guide explains why your domain is showing as Unverified in Piisend and how to add the exact DNS records needed to verify your domain.


1. Common Reasons Your Piisend Domain is Unverified

When user tries to send emails or complete onboarding in Piisend, a domain status of Unverified usually occurs due to one of the following:

  1. Missing DKIM CNAME Record: Piisend requires a DKIM selector record (k1._domainkey) pointing to dkim.piisend.com so recipient inboxes can verify message authenticity.
  2. Missing or Multiple SPF TXT Records: Either your domain lacks the include:piisend.com directive in SPF, or you have multiple separate SPF TXT records (which breaks email RFC standards).
  3. Cloudflare Proxy (Orange Cloud 🟠) Enabled: If you use Cloudflare DNS, setting DKIM or tracking CNAME records to Proxied instead of DNS Only prevents Piisend's DNS checkers from validating the record.
  4. DNS Propagation Time: Depending on your DNS provider (GoDaddy, Namecheap, Cloudflare, Route53, DigitalOcean), DNS TTL updates can take anywhere from 1 minute up to 24 hours to propagate globally.
  5. Subdomain vs. Root Domain Mismatch: If you registered mail.yourdomain.com in Piisend, the DNS host records must be added under mail (or k1._domainkey.mail), not directly on the root domain @.

2. Mandatory DNS Records to Add for Piisend Verification

To change your domain status from Unverified to Verified, log into your DNS host (Cloudflare, GoDaddy, Namecheap, AWS Route53, etc.) and add the following records:

1. DKIM Record (CNAME) — Mandatory

  • Type: CNAME
  • Name / Host: k1._domainkey (if using a subdomain like mail.domain.com, enter k1._domainkey.mail)
  • Target / Value: dkim.piisend.com
  • Proxy Status: DNS Only (Gray Cloud 🔘 in Cloudflare)

2. SPF Record (TXT) — Mandatory

  • Type: TXT
  • Name / Host: @ (or mail for subdomains)
  • Value: v=spf1 include:piisend.com ~all
  • Note: If an SPF TXT record already exists (e.g., v=spf1 include:_spf.google.com ~all), combine them into a single record: v=spf1 include:_spf.google.com include:piisend.com ~all.
  • Type: CNAME
  • Name / Host: email (or email.mail for subdomains)
  • Target / Value: track.piisend.com
  • Proxy Status: DNS Only (Gray Cloud 🔘)

3. Step-by-Step Verification Checklist

  1. Log into your DNS Provider dashboard.
  2. Add the DKIM CNAME and SPF TXT records specified in your Piisend Dashboard -> Domains tab.
  3. Ensure no trailing spaces or duplicate quotes exist in your TXT values.
  4. If using Cloudflare, turn OFF Proxy (Gray Cloud 🔘 / DNS Only) for CNAME records.
  5. Return to the Piisend Dashboard Domains Page and click Verify Domain.

Once verified, you can immediately send authenticated emails using your custom from_ address with full DKIM and SPF compliance!

Start sending

Ship transactional email in minutes

Create an API key, verify a domain, and send your first message with Piisend.