MX records select the servers that receive email for a domain. TXT records can publish ownership-verification tokens and email-authentication information. Use the exact instructions supplied by the email or application provider; there is no universal value that works for every account.
- Identify the authoritative DNS provider and save the current records. If you are changing email providers, create the destination mailboxes and plan the mailbox-data move first.
- For MX changes, record every required server name and priority. Lower numerical priority is normally preferred. Do not leave the old provider's MX records in place unless your migration design specifically requires them.
- Enter the MX records using your editor's expected format. In the Control Center's DNS & SSL editor, enter priority and destination together, such as
10 mail.example.com–an illustration, not your service value. Other providers may use separate fields. In the registrar editor under Domains, check its existing representation or ask support. - For a verification TXT record, enter the exact name and token. DNS & SSL uses a relative name, such as
@or_dmarc, and plain-text values without surrounding quotes or backslashes. Avoid adding your domain twice. Setup-verification records use their own workflow. - Save, recheck the record, then return to the requesting service and run its verification check.
- For email routing, test incoming mail from another provider and outgoing mail to an external address. A correct MX lookup alone does not prove the mailbox exists.
Cloudflare's email DNS guide describes the separate roles of routing and authentication records.
When adding SPF: Do not create a second SPF policy for the same hostname. An existing policy may need to be updated to authorize all legitimate senders within the protocol's limits. Have your email provider or support review the combined policy. See the SPF standard.
When adding DKIM or DMARC: Use the sending provider's exact values and recommended rollout. Some account DNS records are protected from direct editing; ask support or use the authoritative provider's supported tool. Do not delete working authentication records merely to make a new verification check pass.
If you keep an external email provider: Preserve its MX and authentication records even when the website moves here. Copy the hosting setup's mail records only when using Lucid-hosted email. The website DNS check does not verify mail delivery.
If verification fails: Check the record's name, complete value, DNS provider, and elapsed cache time. A nameserver change may have left the token in the old zone.
Related: Find the DNS editor, Change nameservers, DNS propagation.


Leave a Reply