CloudrawSetup guides
Download PDF
Integrations · For IT admins

Send Cloudraw e-mails from your own domain

Send alerts, invitations and sign-in codes from an address such as alerts@yourcompany.com, with SPF and DKIM set up so they reach the inbox.

Last updated 7 October 2026 · Download this guide as PDF

Overview

By default, Cloudraw e-mails come from the Cloudraw sender address. You can send them from an address on your own domain instead, for example Acme IT <alerts@acme.com>. People recognise the sender, and fewer messages land in spam.

Cloudraw sends these e-mails from your address once it is active:

  • Alert e-mails and the confirmation e-mails for alert recipients
  • Invitations to new people
  • Sign-in codes and other sign-in e-mails
  • Confirmations for access requests
  • "New device added" notices

The mail still goes out through the Cloudraw mail service. You publish a few DNS records that allow it to send for your domain. The setup takes about 15 minutes, plus the time your DNS needs to update.

You need

  • The Owner or Security admin role in the Cloudraw admin console.
  • Access to the DNS of your domain (for example in Cloudflare, GoDaddy, Route 53 or Azure DNS), or someone who can add records for you.
  • A domain you own. Public mail domains such as gmail.com or outlook.com cannot be used.
Tip

You can use a subdomain, for example alerts@notify.acme.com. The records then go on notify.acme.com and do not touch the SPF record of your main domain.

Step 1. Add your sender address

  1. Open E-mail senderIn the Cloudraw admin console go to Settings→E-mail sender.
  2. Enter the addressFill in the fields in the table below and click Save.
  3. Wait a few secondsCloudraw registers your domain with the Cloudraw mail service and creates its signing key. This can take 10 to 20 seconds. Then the console shows the DNS records to publish.
Cloudraw fieldValueRequired
From addressAn address on your own domain, for example alerts@acme.com. It does not need a real mailbox, but a mailbox helps if people reply.Yes
From nameThe name people see, up to 60 characters. Default: your workspace name.No

Later changes:

  • Changing only the part before the @, or the From name, keeps your records and verification.
  • Changing to a new domain starts over, with a new key and new records.
  • Removing the sender sends all e-mail from the Cloudraw sender again.

Step 2. Publish the DNS records

The console shows a table with Type, Host and Value for each record. Copy every value from the console. The values below show the format only. Parts in angle brackets are different for every workspace.

RecordTypeHostValueRequired
OwnershipTXT_cloudraw-verify.acme.comcloudraw-verify=<32-character token>Yes
SPFTXTacme.comv=spf1 include:<mail service SPF host> ~allYes
DKIMTXT<selector>._domainkey.acme.comv=DKIM1; k=rsa; p=<long public key>Yes
Return pathCNAMEpsrp.acme.com<mail service return-path host>Yes
DMARCTXT_dmarc.acme.comv=DMARC1; p=none; adkim=r; aspf=rRecommended

What each record does

  • Ownership proves that you control the domain.
  • SPF allows the Cloudraw mail service to send for your domain.
  • DKIM is the signing key. Receivers use it to check that a message really comes from your domain and was not changed.
  • Return path sends bounces back to the Cloudraw mail service. It also makes SPF line up with your domain for DMARC.
  • DMARC tells receivers what to do with mail that fails the checks. It is optional. If you already have a DMARC record, keep it.

If your domain already has an SPF record

A domain may have only one SPF record. Two SPF records make receivers reject both. If your domain already has one, Cloudraw shows a merged record that keeps everything you have and adds the Cloudraw include before the all part. For example:

Before: v=spf1 include:spf.protection.outlook.com -all
After:  v=spf1 include:spf.protection.outlook.com include:<mail service SPF host> -all

Edit your existing record and replace its value with the merged one. Do not add a second record.

Important

SPF allows at most 10 DNS lookups. Every include: counts, including the ones inside it. If your record already has many includes, check it with an SPF checker after the change, or use a subdomain for Cloudraw.

Tips for common DNS panels

  • Host names. Many DNS panels add your domain to the host for you. Then enter only _cloudraw-verify, psrp, _dmarc or <selector>._domainkey. For SPF, enter @ or leave the host empty. If you enter the full name, some panels create _cloudraw-verify.acme.com.acme.com.
  • Long DKIM value. Paste the whole value as one record. Most panels split long values into 255-character parts on their own. Do not add quotes or line breaks.
  • Cloudflare. Set the psrp CNAME to DNS only (grey cloud), not Proxied. A proxied CNAME does not verify.
  • Public DNS. Cloudraw checks the records on public DNS. Records that exist only on your internal DNS do not count.

Step 3. Verify

  1. Check nowWhen the records are in place, click Verify now in Settings→E-mail sender. Each record shows a status. You can check up to 30 times per hour.
  2. Or come back laterYou do not have to keep clicking. Cloudraw checks again on its own every 10 minutes for the first 3 days.
  3. Wait for ActiveWhen all required records are correct, Cloudraw activates the sender with the Cloudraw mail service. The status then moves to Active.

Record status

StatusMeaning
okThe record is correct.
missingCloudraw cannot find the record yet. DNS changes can take from a few minutes to a few hours.
wrongA record exists but the value is different. The console shows what it found and a hint.
dns errorThe DNS lookup failed. Try again in a minute.
uncheckedNot checked yet.

Sender status

StatusWhat happens to your e-mail
Waiting for DNSE-mail is sent from the Cloudraw sender.
DNS verified — activating at the mail relayYour records are correct. The Cloudraw mail service runs its own check. E-mail is still sent from the Cloudraw sender.
ActiveE-mail is sent from your address. The console shows "E-mails now go out from <your address>."
DNS brokenA record that was correct no longer verifies. E-mail falls back to the Cloudraw sender until you fix it.

Each change of status also appears as a console notification in the System category. You can send those to Slack, Telegram or e-mail too. See Alert categories and defaults.

After the sender is active, Cloudraw checks the records once a day. Keep them in place for as long as you use the sender.

Note

Your e-mail is never lost because of the sender. If the Cloudraw mail service refuses a message from your address, Cloudraw sends it again from the Cloudraw sender.

To test, send an alert test to a confirmed e-mail recipient (see Send a test alert). Check the sender, and in the message headers check that SPF, DKIM and DMARC show pass.

Troubleshooting

Message or symptomCause and fix
"a valid address on your own domain, e.g. alerts@yourcompany.com"The From address has a typo or is not a full address.
"this domain cannot be used as a sender (public mail provider or a Cloudraw domain)"You entered a public mail domain such as gmail.com, outlook.com, hotmail.com, yahoo.com, icloud.com or proton.me, or a Cloudraw domain. Use a domain your organisation owns.
SPF: "More than one SPF record: merge them into one (receivers treat two as an error)."Your domain has two records that start with v=spf1. Delete the extra one and put the merged value in the one you keep.
SPF: "Your SPF record does not include <mail service SPF host>."You have an SPF record, but without the Cloudraw include. Replace its value with the merged value from the console.
DKIM: "The DKIM value differs — paste it again as ONE record (long values are split into 255-character parts automatically by most DNS panels)."The key was cut off or changed while pasting. Delete the record and paste the full value again. Check that the host matches the console exactly.
DMARC: "You already have a DMARC policy — kept as is."Nothing to do. Cloudraw uses your existing DMARC record.
"DNS lookup failed right now — try again in a minute."A temporary DNS problem. Click Verify now again later.
Ownership shows wrongThe TXT value must be exactly cloudraw-verify=<token>, with nothing before or after it. If you changed to a new domain, the token changed too. Copy it again.
Return path shows missing but the record existsThe CNAME is proxied (Cloudflare) or was created as a TXT or A record. It must be a plain CNAME.
"too many checks" / "at most 30 checks per hour"Wait for the next hour, or let the automatic check run.
Still Waiting for DNS after 3 daysAutomatic checks stop after 3 days. Fix the records and click Verify now.
Status stays at DNS verified — activating at the mail relayThe Cloudraw mail service has not confirmed the records yet. It can take a little while for your DNS to reach it. Click Verify now again later. If it does not change within a day, contact support.
Notification: "DNS for <domain> no longer verifies — e-mails fall back to the Cloudraw sender until it is fixed."Someone changed or removed a record. Open Settings→E-mail sender, see which record fails, and fix it.