Skip to content
Docs menuCurrent page: Domains and DNS

Guides

Domains and DNS

Five DNS records prove the domain is yours and authenticate your mail; an MX record adds receiving if you want it. Verify them once; Letterpier keeps checking.

Tested with resend@6.30.0

Last reviewed

On this page (9)

The records

When you add a domain, Letterpier creates its records: a unique ownership token and a new 2048-bit DKIM key among them. Five are needed to send: ownership, DKIM, SPF, return path and DMARC. The sixth, MX, is only needed if the domain also receives mail. Publish them at your DNS provider, exactly as shown in the dashboard. Any TTL works.

The records for notify.yourproduct.example
RecordTypeNameValue
OwnershipTXT_letterpier-verification.notify.yourproduct.exampleletterpier-verification=…
DKIMTXTlp-…._domainkey.notify.yourproduct.examplev=DKIM1; t=s; h=sha256; p=…
SPFTXTnotify.yourproduct.examplev=spf1 include:spf.letterpier.com -all
Return pathCNAMEpsrp.notify.yourproduct.examplerp.letterpier.com
ReceivingOptionalMXnotify.yourproduct.examplemail.letterpier.com priority 10
DMARCTXT_dmarc.notify.yourproduct.examplev=DMARC1; p=none;

The records for notify.yourproduct.example

  • Ownership
    Type
    TXT
    Name
    _letterpier-verification.notify.yourproduct.example
    Value
    letterpier-verification=…
  • DKIM
    Type
    TXT
    Name
    lp-…._domainkey.notify.yourproduct.example
    Value
    v=DKIM1; t=s; h=sha256; p=…
  • SPF
    Type
    TXT
    Name
    notify.yourproduct.example
    Value
    v=spf1 include:spf.letterpier.com -all
  • Return path
    Type
    CNAME
    Name
    psrp.notify.yourproduct.example
    Value
    rp.letterpier.com
  • ReceivingOptional
    Type
    MX
    Name
    notify.yourproduct.example
    Value
    mail.letterpier.com priority 10
  • DMARC
    Type
    TXT
    Name
    _dmarc.notify.yourproduct.example
    Value
    v=DMARC1; p=none;
  • Ownership proves the domain is yours. A domain belongs to one project, across all of Letterpier.
  • DKIM signs every message. The private key never leaves Letterpier and its mail server.
  • SPF and the return path let receiving servers check where the mail came from, and send bounces back to Letterpier.
  • MX routes mail for the domain to Letterpier. Publish it only if you turn receiving on; see Receiving is optional.
  • DMARC tells receiving servers what to do with mail that fails those checks.

Receiving is optional

A new domain sends only. Turn on catch-all receiving when you add the domain, or later on the domain’s page in the dashboard, and turn it off the same way. While it is on, the MX record is required and mail to any address on the domain arrives in its project. While it is off, no mail for the domain reaches the project, and the domain needs no MX record.

MX moves all incoming mail for the name

The MX record never holds up sending. capabilities.receiving in the domain’s response is disabled while receiving is off, pending until the domain is verified and MX matches, and enabled after that; receiving_enabled shows the setting itself. Through the API, pass receiving: true when you create the domain. The SDK’s domains.create doesn’t send that field, so use a plain HTTP request:

Request
POST /domains HTTP/1.1Host: app.letterpier.comAuthorization: Bearer lp_live_…Content-Type: application/json{ "name": "notify.yourproduct.example", "receiving": true }

To change the setting later, use the switch on the domain’s page. The dashboard sends PATCH /api/control/projects/:projectId/domains/:id with { "receiving": true } or false and gets the updated domain back. That control API takes a signed-in dashboard session, not an API key; the Resend-compatible API has no update route for domains yet.

How receiving works

Verification and freshness

While records are missing, the domain’s page in the dashboard checks them every 30 seconds on its own. To check straight away, select Check now or call mail.domains.verify(id). Letterpier looks up all the records at once. When the five sending records match, the domain is verified and sending is turned on. If receiving is on, it starts as soon as MX matches too.

Live sending needs a check under 24 hours old

Per project, you can add up to 5 domains per minute and run up to 10 verifications per minute.

domains.ts
// Full-access key. Creates a sending-only domain.const { data: domain } = await mail.domains.create({  name: 'notify.yourproduct.example',});domain?.records; // MX is required only with receiving onawait mail.domains.verify(domain!.id); // Checks the records nowconst { data: checked } = await mail.domains.get(domain!.id);checked?.status; // 'verified' once the sending records match
Differs from Resend

Periodic re-checks

You don’t have to verify again by hand. While a new domain waits for its records, Letterpier’s worker checks it about every 2 minutes for its first 7 days, so it verifies soon after your DNS changes appear. Every other domain is re-checked once its last check is 6 hours old, so a healthy domain stays inside the 24-hour window on its own. If a sending record stops matching, the domain shows Needs attention (or Waiting for DNS when the record is gone), and sending and receiving on it pause until you fix the record and a check finds it again. If only MX stops matching, sending carries on and receiving shows as pending.

SPF

A name can have only one SPF record. If yours already has one, for another provider, don’t add a second: add Letterpier’s include to the existing one, before its all term.

SPF record with two senders
v=spf1 include:_spf.otherprovider.example include:spf.letterpier.com -all
  • Letterpier accepts the record when it has exactly one SPF policy with include:spf.letterpier.com before the all term, and doesn’t allow everyone (+all, or a bare all).
  • SPF allows at most 10 DNS lookups per check. Letterpier’s include uses one; count the others before you add it.

DMARC

If the domain has no DMARC policy, publish v=DMARC1; p=none;: it asks receiving servers to report without changing delivery. Once every service that sends as your domain passes SPF or DKIM, raise it to p=quarantine or p=reject.

If a policy already exists, keep it. Letterpier accepts any single DMARC record with p=none, p=quarantine or p=reject. For a subdomain without its own record, it accepts the policy of the registered domain above it.

Reverse DNS

Reverse DNS belongs to the sending IP address, not to your domain. Letterpier’s IP has one PTR record for mail.letterpier.com, with a matching forward record, and every project’s domains share it. There is nothing to publish per domain.

Subdomains

A subdomain such as notify.yourproduct.example is often the better choice: its SPF record stays apart from the main domain’s, and if you turn receiving on, its MX record doesn’t touch mail for the main domain. Add it to Letterpier as its own domain: the sender address of a live message must use a verified domain exactly, so hello@notify.yourproduct.example needs notify.yourproduct.example itself to be verified.

Record statuses

Each record shows its status after every check, with a short detail from the API.

DNS record statuses
StatusMeaningDetail from the API
Not checkedThis record hasn’t been checked yet.None yet. The domain page checks on its own, or select Check now.
Not found yetRecord not found yet. Check the DNS name and allow time for propagation.“Record not found yet. Check the DNS name and allow time for propagation.”
VerifiedThe published record matches the expected value.“DNS record verified.”, or for DMARC “Using the existing organizational policy at _dmarc.…”
Doesn’t matchThe published record doesn’t match the expected value.“Record does not match the expected value.”, or that several SPF or DMARC records were found. The values found are listed.
Lookup failedDNS lookup temporarily failed. Retry verification.“DNS lookup temporarily failed. Retry verification.”

DNS record statuses

  • Not checked
    Meaning
    This record hasn’t been checked yet.
    Detail from the API
    None yet. The domain page checks on its own, or select Check now.
  • Not found yet
    Meaning
    Record not found yet. Check the DNS name and allow time for propagation.
    Detail from the API
    “Record not found yet. Check the DNS name and allow time for propagation.”
  • Verified
    Meaning
    The published record matches the expected value.
    Detail from the API
    “DNS record verified.”, or for DMARC “Using the existing organizational policy at _dmarc.…”
  • Doesn’t match
    Meaning
    The published record doesn’t match the expected value.
    Detail from the API
    “Record does not match the expected value.”, or that several SPF or DMARC records were found. The values found are listed.
  • Lookup failed
    Meaning
    DNS lookup temporarily failed. Retry verification.
    Detail from the API
    “DNS lookup temporarily failed. Retry verification.”

The domain’s own status sums them up:

Domain statuses
StatusMeaning
VerifiedEvery sending record matched at the last check, which is under 24 hours old.
Re-check neededThe records matched, but the last successful check is 24 hours old or older. Live sending pauses until a check succeeds.
Needs attentionAt least one required record doesn’t match, or its lookup failed. Fix it at your DNS provider; Letterpier checks again automatically.
Waiting for DNSSome records haven’t been found yet. DNS changes can take a while to appear. Allow time for propagation.
Not checkedLetterpier hasn’t checked this domain’s records yet. Publish the records; Letterpier checks them.

Domain statuses

  • Verified
    Meaning
    Every sending record matched at the last check, which is under 24 hours old.
  • Re-check needed
    Meaning
    The records matched, but the last successful check is 24 hours old or older. Live sending pauses until a check succeeds.
  • Needs attention
    Meaning
    At least one required record doesn’t match, or its lookup failed. Fix it at your DNS provider; Letterpier checks again automatically.
  • Waiting for DNS
    Meaning
    Some records haven’t been found yet. DNS changes can take a while to appear. Allow time for propagation.
  • Not checked
    Meaning
    Letterpier hasn’t checked this domain’s records yet. Publish the records; Letterpier checks them.