Make sure your email arrives
Check the SPF, DKIM, DMARC and MTA-STS records that stop your email landing in spam, and fix the common causes when it does.
Receiving mail servers decide whether to trust your email by checking a few DNS records on your domain. lbreeze creates these for every domain you turn email on for. This article explains what they are, where to see them, and what to do if your DNS is hosted somewhere else.
The records your domain needs
| Record | What it does |
|---|---|
| SPF | Says which servers may send mail for your domain. |
| DKIM | A signing key. Every message your mailboxes send is signed, so a receiver can check it really came from you. |
| DMARC | Tells receivers what to do when a message fails the checks, and where to send reports. It is published in monitoring mode, so failing mail is reported rather than rejected. |
| MTA-STS | Tells other servers to use an encrypted connection when they deliver to you. It is published in reporting (testing) mode. |
If lbreeze hosts your domain's DNS, all of these are published for you, together with the MX record that makes mail arrive and the mail.yourdomain host. You do not need to type anything.
If your DNS is hosted somewhere else, you add them yourself:
- In your control panel, choose Mailboxes and click your domain.
- Open the DNS & security tab.
- Copy each row of the DNS records table (name, type and content) into a new record at your DNS provider.
- Also add an MX record for your domain pointing at
mail.yourdomain, and a record formail.yourdomainitself. Until that name points at the right server, the Certificate card on the same tab says which address it should point at.
Good to know: Hosting your DNS with lbreeze avoids all of this, and keeps the records correct when anything changes. See Point your domain at lbreeze.
Check that your domain is signing
On the Mailboxes page, the Authentication column shows signed when the domain has its DKIM signing key, and unsigned if the key is missing. The Health column shows Delivering when all is well.
On the DNS & security tab:
- DMARC alignment charts the daily reports that receiving providers send back. Reports go to
dmarc@yourdomain, which the platform reads for you; you do not need a mailbox for it. - TLS reports shows what other servers say about encrypted delivery to you, when they send reports.
Change the signing key
Click Rotate the signing key on the DNS & security tab to replace your DKIM key. The new key is published beside the old one, so mail already signed with the old key keeps checking out. Rotation happens only when you click it.
Good to know: If your DNS is not with lbreeze, add the new DKIM record at your DNS provider straight away, so mail signed with the new key can be checked.
Other services that send as you
If a newsletter tool, shop or helpdesk sends mail using your address, it must be named in your SPF record or its mail will fail the check.
- Open the Filtering & delivery tab and find the Mail delivery card.
- Under Who else may send as this domain, add the value the service gives you, one per line, for example
include:_spf.example.com. - Click Save delivery. The DNS records are updated to match.
Mailboxes kept with another provider
If your mailboxes are with Google Workspace, Microsoft 365 or another provider, set Who holds the mailboxes to the other provider and save. lbreeze then stops accepting mail for the domain, but keeps signing what your website sends. You still need to point your MX records at the other provider yourself.
Sending limits
Each domain has a sending rate, shown under Sending at the top of its page. If a domain sends far more than its limit, outbound mail is stopped to protect everyone's sending reputation and a Sending is stopped bar appears. Incoming mail still arrives. Once the cause is dealt with, click Resume sending.
Related
More in Email
- Create a mailbox and set up your mail apps
Add an email address on your own domain, then connect it to your phone, Outlook, Thunderbird or Apple Mail.
- Read your email in webmail
Sign in to webmail at mail.yourdomain to read and send email, and to keep a calendar and contacts, from any browser.
- Forwarders, aliases, catch-all and auto-replies
Send mail for one address somewhere else, give a mailbox extra addresses, catch mistyped addresses, and set an out-of-office reply.
- Spam filtering and mail rules
Choose how hard the spam filter works for a domain or one mailbox, allow or block senders, and file mail automatically with rules.

