// Engineering Log

DNS Setup for Email and Website: Part 3 — How to Set Up and Verify

Published on 2026-09-21

// Fast route

This article belongs to the topic Networking and routing.

Where to configure DNS records

DNS records are edited in the control panel of the service that manages the domain’s DNS. Most often this is the registrar where the domain is registered, but DNS can also be delegated to a third-party service, for example Cloudflare. Which service is responsible for the domain is visible from its NS records.

  1. Open the records management section. It may be called “DNS”, “Zone management”, “DNS records” or something similar.
  2. Add or modify records. For each record (A, MX, SPF, DKIM, DMARC) specify the type, name (for the root domain — @ or an empty field, depending on the control panel), value (IP address, mail server name, record text) and TTL — the time the record is cached by other servers. Typical values are 300 or 3600 seconds.
  3. Save the changes. In some control panels records are applied only after a separate confirmation.

Common mistakes

A single typo can make a website unavailable or stop mail delivery. The most common issues are:

  • typos in IP addresses and server names;
  • incorrect MX record priorities;
  • missing necessary records: without SPF and DKIM, emails often go to spam;
  • record on the wrong name: for example, the SPF record must be on the domain from which mail is sent, and DKIM on a name like selector._domainkey.example.ru;
  • an extra dot at the end or, conversely, its absence: some panels append the domain name themselves, others do not, resulting in a record like mail.example.ru.example.ru;
  • two SPF records on one domain instead of a single combined one.

When changes take effect

New values do not become visible immediately: servers that have already requested the record continue to use the old value until its TTL expires. Therefore, before a planned change of records it is reasonable to reduce the TTL in advance. Changing the domain’s name servers (NS records) takes the longest to apply: this can take up to a day.

How to check the configuration

The following online services help ensure records are published and set correctly:

  • MXToolbox — checks MX, SPF, DKIM and DMARC, shows current values and detected errors;
  • DNS Checker — shows what value DNS servers in different countries see for a record; useful to understand whether a change has propagated;
  • mail-tester.com — checks a real email: to the address provided by the service you send a message from your mailbox and receive an assessment of SPF, DKIM, DMARC and the message content.

You can also check records from the command line:

dig example.ru A
dig example.ru MX
dig example.ru TXT
dig _dmarc.example.ru TXT

On Windows, nslookup is used instead of dig, for example nslookup -type=MX example.ru.

You should repeat checks after each change to the records and after changing mail or hosting providers.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Networking and routing

MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.

Typical tasks behind this topic

  • Set up VPN and secure access to office or cloud
  • Fix routing, DNS, or unstable connectivity
  • Configure MikroTik, firewall, and external links

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply