DNS automation

SPF, DKIM, DMARC — provisioned and verified automatically.

Every domain in CogniLead's managed sending pool is registered, delegated to Cloudflare, and provisioned with a hard-fail SPF record, its SES DKIM keys, and a DMARC policy set to reject — before the domain ever sends a single message. No DNS panel, no hand-typed TXT records, no guessing whether a selector is right.

yourdomain.comDNSSPFv=spf1 include:_spf... ~allNot yet verifiedSPFv=spf1 include:_spf... ~allProvisioned + verifiedDKIMv=DKIM1; k=rsa; p=MIGfMA0...Not yet verifiedDKIMv=DKIM1; k=rsa; p=MIGfMA0...Provisioned + verifiedDMARCv=DMARC1; p=reject; pct=100Not yet verifiedDMARCv=DMARC1; p=reject; pct=100Provisioned + verifiedEvery pooled domain provisions and verifies its own SPF, DKIM, and DMARC records automatically

The problem

DNS authentication has no margin for a quiet mistake.

[ 01 ]

Manual DNS setup is easy to get subtly wrong

The SPF ten-DNS-lookup limit, DMARC policy and alignment tags, and which record goes on the apex versus the subdomain are all easy to misconfigure without any error telling you so.

[ 02 ]

One wrong DKIM selector breaks delivery — silently

A DKIM CNAME that doesn’t match its issuer’s target exactly doesn’t throw an error. It just fails signature alignment, and mail starts sliding toward spam with no obvious cause.

[ 03 ]

Nothing flags a record that changes later

A TXT record edited, deleted, or overwritten by a registrar-panel change after the fact looks identical to one that was never wrong in the first place — until deliverability drops.

[ 04 ]

Propagation delays catch people off guard

Nameserver delegation and DNS propagation take real time — minutes to hours, outside anyone’s control. Sending before that finishes means authentication silently isn’t live yet.

How it works

Registered, delegated, and authenticated — in one pass.

Every domain in the managed pool moves through the same automated sequence, from purchase to a fully authenticated sender — the only step that isn't automatic is real DNS propagation time.

[ 01 ]

Domain registered, zone created, nameservers delegated

Buying the domain, creating its Cloudflare zone, and pointing the registrar’s nameservers at that zone all happen in the same automated pass.

yourdomain.comZONEZONENS1NS1NS2NS2Purchase, zone, and delegation — one automated pass

[ 02 ]

Nameservers propagate

The zone stays pending until the new nameservers are visible to resolvers, then flips to active — real wall-clock time this pipeline waits on rather than skips.

NS1NS2PENDINGACTIVE

[ 03 ]

SPF, DKIM, and DMARC written through Cloudflare

Once the zone is active, a hard-fail SPF record, the domain’s SES DKIM keys, and a reject-policy DMARC record are generated and pushed as DNS through the Cloudflare API — the registrar’s own DNS panel is no longer authoritative by this point.

yourdomain.comSPFSPFDKIMDKIMDMARCDMARCProvisioned automatically on every pooled domain

[ 04 ]

SES verifies, domain enters warming

SES verifies the domain automatically once the records above are visible, and the domain moves into the pool’s warming state — no manual re-check required.

WARM POOLVerifying…Entering warm pool

The record set, illustrated

What actually gets written.

An illustrative example of the exact record shapes this pipeline writes through Cloudflare for one pooled sending domain — real TYPE/NAME/VALUE structure, illustrative domain and tokens.

outbound.brightloop.example — DNS recordsIllustrative
TypeNameValueStatus
TXToutbound.brightloop.examplev=spf1 include:amazonses.com -allVerified
CNAMEk7h2m9._domainkey.outbound.brightloop.example (+ 2 more)k7h2m9.dkim.amazonses.comVerified
TXT_dmarc.outbound.brightloop.examplev=DMARC1; p=reject; sp=reject; rua=mailto:dmarc-reports@cognilead.ai; aspf=s; adkim=s; pct=100; fo=1Propagating

[ 01 ]

-all (hard fail)

SPF policy

[ 02 ]

p=reject, pct=100

DMARC policy

[ 03 ]

3 CNAMEs (SES Easy DKIM)

DKIM records per domain

Authenticated by default

Every domain in the pool authenticates itself.

Registered, delegated to Cloudflare, and provisioned with SPF, DKIM, and DMARC before it ever sends — no DNS panel, no hand-typed record, no selector to get wrong.

SPF policy
-all (hard fail)
DMARC policy
p=reject, pct=100
DKIM records
3 CNAMEs per domain
yourdomain.comSPFSPFDKIMDKIMDMARCDMARCProvisioned automatically on every pooled domain

FAQ

Questions about DNS automation.

Not for domains in the managed pool — registration, Cloudflare delegation, and every authentication record are provisioned automatically before a domain ever sends. If you send from a domain outside the pool, you’re still responsible for its DNS; use the free /tools/spf-checker and /tools/dmarc-checker to grade it.

A hard-fail SPF record (v=spf1 include:amazonses.com -all), the exact DKIM CNAME records SES issues for that domain, and a DMARC policy set to p=reject at 100% enforcement — written through Cloudflare’s API once the domain’s zone is active, not through the registrar’s own DNS panel, which stops being authoritative at that point.

No. Nameserver delegation and DNS propagation still take real time — minutes to hours, and outside anyone’s control. Record provisioning starts the moment a domain’s Cloudflare zone reports active, not before.

No — it’s necessary but not sufficient. Authentication is the floor, not the whole story; ongoing warmup and reputation monitoring matter just as much. See /features/warmed-sender-pool and /features/reputation-circuit-breaker.

DNS authentication is the floor — the warmed sender pool and the reputation circuit-breaker protect what happens after it.

Your leads deserve to reach an inbox.

Every email you send without protection is a gamble on whether it reaches the inbox at all. Bring your leads — CogniLead handles the warmup, the safety checks, and the cleanup, so you don't have to think about deliverability again.

100 sends a month, free forever · no credit card · cancel any time

DNS automation (SPF/DKIM/DMARC) — CogniLead