Practical guide

MailerLite domain authentication: a careful SPF, DKIM, and verification workflow

Add the records supplied by MailerLite, avoid duplicate SPF records, verify DNS ownership, understand propagation, and document the sending setup.

Quick answerUse the exact records shown in your MailerLite account and edit DNS only at the authoritative host. Preserve existing SPF mechanisms instead of publishing a second SPF record.
Practical detail

Find the authoritative DNS host

The website host, domain registrar, and DNS provider may be different companies. Identify the service whose nameservers currently answer for the domain, then open the MailerLite Domains area and use the automatic path where supported or the exact manually supplied records.

Do not copy values from a generic tutorial when the account displays different names or targets. Keep the MailerLite instructions and DNS editor open side by side.

Practical detail

Add verification, DKIM, and SPF carefully

Current official guidance describes a domain-verification TXT record, a DKIM CNAME, and an SPF TXT value. DNS interfaces may append the domain automatically or expect the root as blank or @. Enter the record exactly as the account and provider require.

A domain should have one SPF record. If another service already appears, merge approved mechanisms into the existing policy rather than publishing a second SPF TXT record. Respect SPF length and lookup limits and remove providers no longer authorized to send.

Practical detail

Verify and allow propagation

Return to MailerLite and check the records. Some changes appear quickly; others take longer to propagate. If approval fails, compare names and values character by character, confirm the edit occurred at the authoritative provider, and inspect whether the interface changed the host or target.

Avoid repeatedly deleting and re-adding correct records during normal propagation. Record the change time and previous values so an unrelated mail problem can be diagnosed.

Practical detail

Add DMARC and ongoing ownership

Authentication is not a one-time checkbox. Review DMARC guidance, align sending domains, remove obsolete services, keep account recovery current, and monitor failures or unexpected senders. Large-volume sender requirements from mailbox providers can change, so check current official policies.

Assign an owner for DNS and email infrastructure. Document every authorized sender and the business message it sends.

Continue when useful

Next: DNS troubleshooting

Work through incorrect hosts, changed values, duplicate SPF records, lookup limits, propagation, and edits made at the wrong DNS provider.

Open DNS troubleshooting →

Sources used for this page

These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.

  1. MailerLite domain authentication guidance — MERCHANT · checked 2026-08-23
  2. MailerLite domain authentication troubleshooting — MERCHANT · checked 2026-08-23
  3. Google email sender guidelines — PLATFORM · checked 2026-08-23