What the Autopilot handles
Mail on your own domain needs several DNS records so it arrives and recipients can spot forgeries. Domain Autopilot generates these records and keeps checking them. It is a core part of the service.
| Record | Purpose | What the Autopilot does |
|---|---|---|
| MX | Names the servers that accept mail for your domain. | Generates the records pointing to our mail servers and checks them. |
| SPF | Defines which servers may send for your domain. | Generates a record with an include: for our service. |
| DKIM | Publishes the key for verifying your mail's signature. | Generates CNAME records pointing to our selectors. The half-yearly key rotation then runs automatically. |
| DMARC | Tells recipients how to treat mail that matches your domain through neither SPF nor DKIM. | Guides you stepwise from none via quarantine to reject, where that suits the domain, and analyses aggregate reports. |
| MTA-STS (RFC 8461) | Requires TLS with a valid certificate for mail to your domain. | Generates the record and policy and monitors both. |
| TLS-RPT (RFC 8460) | Names an address for reports about TLS problems. | Generates the record, receives reports and analyses them. |
| DNSSEC | Signs your zone so forged answers are noticed. | Monitors whether the zone is validly signed. |
| DANE (RFC 7672) | Ties a mail server's certificate to signed DNS. | Monitors whether DANE for our mail servers also protects your domain. |
See SPF, DKIM and DMARC explained for how these records work together, and Security for transport protection.
Setup in three steps
- Verify. You show that you control the domain.
- Enter. A DNS assistant displays the records. You enter them at your DNS provider.
- Check. The Autopilot queries the records and shows each domain's state in a health dashboard.
Your address then works in your usual mail app.
Moving an existing domain
The import brings existing mail into the new mailbox over IMAP. A checklist covers switching the DNS records:
- Parallel operation. Old and new mailboxes run side by side for a while.
- Lower the TTL. Shorten the MX records' lifetime in advance so the change takes effect sooner.
- Switch MX. Only then do the MX records point to our servers.
Limits of the Autopilot
Your zone is hosted by your DNS provider. The Autopilot checks it from outside; it cannot change anything there.
- You enter the records yourself. The Autopilot flags later changes; it cannot fix them.
- Your provider enables DNSSEC. It signs the zone; the registrar submits the DS record. Without DNSSEC, DANE does not apply to your domain. MTA-STS works without it.
- Only you know your other senders. A newsletter tool or other service sending under your domain needs matching SPF or DKIM records too.
Plans with your own domain
Custom domains are part of the Pro and Team plans. Pro includes 3 domains with Autopilot and costs 4 euros a month billed yearly, otherwise 5 euros. Team includes unlimited domains (see For teams). The Personal plan includes no custom domain. All plans are under Pricing.
Questions about your own domain
Does my domain have to move to a different DNS provider?
No. If another DNS provider hosts your zone, the Autopilot checks it from outside. You enter the records there yourself; the Autopilot cannot change anything at an external provider.
Does the Autopilot set DMARC to reject straight away?
No. It moves the policy stepwise from none via quarantine to reject, where that suits the domain, and analyses the aggregate reports along the way.
Does DANE apply without DNSSEC?
No. Without DNSSEC, DANE does not apply to your domain. MTA-STS works without it.
Do I have to renew DKIM keys myself?
No. Your domain points to our selectors by CNAME; the half-yearly key rotation then runs automatically.
Does the Personal plan include custom domains?
No. Custom domains are part of the Pro and Team plans: 3 domains in Pro, an unlimited number in Team.