Overview
By default, Cloudraw e-mails come from the Cloudraw sender address. You can send them from an address on your own domain instead, for example Acme IT <alerts@acme.com>. People recognise the sender, and fewer messages land in spam.
Cloudraw sends these e-mails from your address once it is active:
- Alert e-mails and the confirmation e-mails for alert recipients
- Invitations to new people
- Sign-in codes and other sign-in e-mails
- Confirmations for access requests
- "New device added" notices
The mail still goes out through the Cloudraw mail service. You publish a few DNS records that allow it to send for your domain. The setup takes about 15 minutes, plus the time your DNS needs to update.
You need
- The Owner or Security admin role in the Cloudraw admin console.
- Access to the DNS of your domain (for example in Cloudflare, GoDaddy, Route 53 or Azure DNS), or someone who can add records for you.
- A domain you own. Public mail domains such as gmail.com or outlook.com cannot be used.
You can use a subdomain, for example alerts@notify.acme.com. The records then go on notify.acme.com and do not touch the SPF record of your main domain.
Step 1. Add your sender address
- Open E-mail senderIn the Cloudraw admin console go to Settings→E-mail sender.
- Enter the addressFill in the fields in the table below and click Save.
- Wait a few secondsCloudraw registers your domain with the Cloudraw mail service and creates its signing key. This can take 10 to 20 seconds. Then the console shows the DNS records to publish.
| Cloudraw field | Value | Required |
|---|---|---|
| From address | An address on your own domain, for example alerts@acme.com. It does not need a real mailbox, but a mailbox helps if people reply. | Yes |
| From name | The name people see, up to 60 characters. Default: your workspace name. | No |
Later changes:
- Changing only the part before the
@, or the From name, keeps your records and verification. - Changing to a new domain starts over, with a new key and new records.
- Removing the sender sends all e-mail from the Cloudraw sender again.
Step 2. Publish the DNS records
The console shows a table with Type, Host and Value for each record. Copy every value from the console. The values below show the format only. Parts in angle brackets are different for every workspace.
| Record | Type | Host | Value | Required |
|---|---|---|---|---|
| Ownership | TXT | _cloudraw-verify.acme.com | cloudraw-verify=<32-character token> | Yes |
| SPF | TXT | acme.com | v=spf1 include:<mail service SPF host> ~all | Yes |
| DKIM | TXT | <selector>._domainkey.acme.com | v=DKIM1; k=rsa; p=<long public key> | Yes |
| Return path | CNAME | psrp.acme.com | <mail service return-path host> | Yes |
| DMARC | TXT | _dmarc.acme.com | v=DMARC1; p=none; adkim=r; aspf=r | Recommended |
What each record does
- Ownership proves that you control the domain.
- SPF allows the Cloudraw mail service to send for your domain.
- DKIM is the signing key. Receivers use it to check that a message really comes from your domain and was not changed.
- Return path sends bounces back to the Cloudraw mail service. It also makes SPF line up with your domain for DMARC.
- DMARC tells receivers what to do with mail that fails the checks. It is optional. If you already have a DMARC record, keep it.
If your domain already has an SPF record
A domain may have only one SPF record. Two SPF records make receivers reject both. If your domain already has one, Cloudraw shows a merged record that keeps everything you have and adds the Cloudraw include before the all part. For example:
After: v=spf1 include:spf.protection.outlook.com include:<mail service SPF host> -all
Edit your existing record and replace its value with the merged one. Do not add a second record.
SPF allows at most 10 DNS lookups. Every include: counts, including the ones inside it. If your record already has many includes, check it with an SPF checker after the change, or use a subdomain for Cloudraw.
Tips for common DNS panels
- Host names. Many DNS panels add your domain to the host for you. Then enter only
_cloudraw-verify,psrp,_dmarcor<selector>._domainkey. For SPF, enter@or leave the host empty. If you enter the full name, some panels create_cloudraw-verify.acme.com.acme.com. - Long DKIM value. Paste the whole value as one record. Most panels split long values into 255-character parts on their own. Do not add quotes or line breaks.
- Cloudflare. Set the
psrpCNAME to DNS only (grey cloud), not Proxied. A proxied CNAME does not verify. - Public DNS. Cloudraw checks the records on public DNS. Records that exist only on your internal DNS do not count.
Step 3. Verify
- Check nowWhen the records are in place, click Verify now in Settings→E-mail sender. Each record shows a status. You can check up to 30 times per hour.
- Or come back laterYou do not have to keep clicking. Cloudraw checks again on its own every 10 minutes for the first 3 days.
- Wait for ActiveWhen all required records are correct, Cloudraw activates the sender with the Cloudraw mail service. The status then moves to Active.
Record status
| Status | Meaning |
|---|---|
| ok | The record is correct. |
| missing | Cloudraw cannot find the record yet. DNS changes can take from a few minutes to a few hours. |
| wrong | A record exists but the value is different. The console shows what it found and a hint. |
| dns error | The DNS lookup failed. Try again in a minute. |
| unchecked | Not checked yet. |
Sender status
| Status | What happens to your e-mail |
|---|---|
| Waiting for DNS | E-mail is sent from the Cloudraw sender. |
| DNS verified — activating at the mail relay | Your records are correct. The Cloudraw mail service runs its own check. E-mail is still sent from the Cloudraw sender. |
| Active | E-mail is sent from your address. The console shows "E-mails now go out from <your address>." |
| DNS broken | A record that was correct no longer verifies. E-mail falls back to the Cloudraw sender until you fix it. |
Each change of status also appears as a console notification in the System category. You can send those to Slack, Telegram or e-mail too. See Alert categories and defaults.
After the sender is active, Cloudraw checks the records once a day. Keep them in place for as long as you use the sender.
Your e-mail is never lost because of the sender. If the Cloudraw mail service refuses a message from your address, Cloudraw sends it again from the Cloudraw sender.
To test, send an alert test to a confirmed e-mail recipient (see Send a test alert). Check the sender, and in the message headers check that SPF, DKIM and DMARC show pass.
Troubleshooting
| Message or symptom | Cause and fix |
|---|---|
| "a valid address on your own domain, e.g. alerts@yourcompany.com" | The From address has a typo or is not a full address. |
| "this domain cannot be used as a sender (public mail provider or a Cloudraw domain)" | You entered a public mail domain such as gmail.com, outlook.com, hotmail.com, yahoo.com, icloud.com or proton.me, or a Cloudraw domain. Use a domain your organisation owns. |
| SPF: "More than one SPF record: merge them into one (receivers treat two as an error)." | Your domain has two records that start with v=spf1. Delete the extra one and put the merged value in the one you keep. |
| SPF: "Your SPF record does not include <mail service SPF host>." | You have an SPF record, but without the Cloudraw include. Replace its value with the merged value from the console. |
| DKIM: "The DKIM value differs — paste it again as ONE record (long values are split into 255-character parts automatically by most DNS panels)." | The key was cut off or changed while pasting. Delete the record and paste the full value again. Check that the host matches the console exactly. |
| DMARC: "You already have a DMARC policy — kept as is." | Nothing to do. Cloudraw uses your existing DMARC record. |
| "DNS lookup failed right now — try again in a minute." | A temporary DNS problem. Click Verify now again later. |
| Ownership shows wrong | The TXT value must be exactly cloudraw-verify=<token>, with nothing before or after it. If you changed to a new domain, the token changed too. Copy it again. |
| Return path shows missing but the record exists | The CNAME is proxied (Cloudflare) or was created as a TXT or A record. It must be a plain CNAME. |
| "too many checks" / "at most 30 checks per hour" | Wait for the next hour, or let the automatic check run. |
| Still Waiting for DNS after 3 days | Automatic checks stop after 3 days. Fix the records and click Verify now. |
| Status stays at DNS verified — activating at the mail relay | The Cloudraw mail service has not confirmed the records yet. It can take a little while for your DNS to reach it. Click Verify now again later. If it does not change within a day, contact support. |
| Notification: "DNS for <domain> no longer verifies — e-mails fall back to the Cloudraw sender until it is fixed." | Someone changed or removed a record. Open Settings→E-mail sender, see which record fails, and fix it. |