Skip to content
domainspacesi

Set up email on a .si domain

Email on your own domain needs four kinds of DNS record: MX to receive, and SPF, DKIM and DMARC to prove your mail is yours. The domain ending does not change how any of this works. The examples use your-name-here.si as a placeholder.

Last updated: · 4 min read

What each record does

  • MX says which servers receive mail for your domain. Each has a priority; the lowest number is tried first.
  • SPF is a TXT record at the root that lists who may send mail for the domain. A domain must have only one SPF record, and evaluating it may cause at most 10 DNS lookups (RFC 7208).
  • DKIM signs outgoing mail. Your mail provider generates a key and gives you a record to publish at selector._domainkey, where the selector is a name the provider chooses (RFC 6376).
  • DMARC is a TXT record at _dmarc that tells receivers what to do with mail that fails SPF and DKIM and where to send reports (RFC 7489).

DomainSpace's DNS editor supports MX (with priority) and TXT records, which is everything these need. Records that a provider asks for as CNAME, such as the DKIM records of Microsoft 365, are supported too.

Does `.si` hurt deliverability?

We found no statement in Google's or Yahoo's sender guidelines that depends on the top-level domain. What they require is authentication. Google requires SPF or DKIM from all senders, and SPF, DKIM and DMARC from anyone sending more than 5,000 messages a day to Gmail (Google); Yahoo asks bulk senders for SPF, DKIM and a DMARC policy of at least p=none (Yahoo). A new domain still has no sending reputation, whatever its ending, so start with low volume.

Option 1: Google Workspace

Google's current instructions use a single MX record (Google: set up MX records). Older aspmx records from before 2023 still work but are no longer required.

  • MX@

    1 smtp.google.com

  • TXT@

    v=spf1 include:_spf.google.com ~all

For DKIM, generate the key in the Admin console (Apps, Google Workspace, Gmail, Authenticate email), publish the TXT record it gives you, usually at google._domainkey, then press Start authentication (Google: DKIM). Google suggests waiting until SPF or DKIM works before adding DMARC.

Option 2: Microsoft 365

Microsoft's admin centre shows the exact MX value and the DKIM targets for your domain, so copy them from there (Microsoft: DNS records at any host). The pattern is:

  • MX@

    0 (value shown in the admin centre)

  • TXT@

    v=spf1 include:spf.protection.outlook.com -all

  • CNAMEautodiscover

    (value shown in the admin centre)

Create the mailboxes before you switch the MX record, and remove old MX records or give them a higher priority number. If you already have an SPF record, merge the include into it rather than adding a second record.

Option 3: forward with Cloudflare Email Routing

If you only need hello@your-name-here.si to arrive in an inbox you already have, Cloudflare Email Routing forwards mail to an existing address (Cloudflare: enable Email Routing). It receives and forwards; it is not a mailbox and does not send mail on your behalf. Cloudflare asks you to verify each destination address, and a rule pointing at an unverified address stays disabled.

The records it adds are an MX for each of route1.mx.cloudflare.net, route2.mx.cloudflare.net and route3.mx.cloudflare.net, an SPF record, and a DKIM record whose key Cloudflare supplies:

  • MX@

    1 route1.mx.cloudflare.net

  • MX@

    2 route2.mx.cloudflare.net

  • MX@

    3 route3.mx.cloudflare.net

  • TXT@

    v=spf1 include:_spf.mx.cloudflare.net ~all

Cloudflare assigns the priorities itself, so use the numbers its dashboard shows; those above only illustrate the form. Its setup page says the domain must use Cloudflare DNS, so this is the documented path for a domain whose DNS lives in Cloudflare. DomainSpace's one-step Cloudflare setup moves your DNS there and copies your existing records (see the hosting guide).

Add DMARC, starting in monitoring mode

A first DMARC record can ask receivers only to report, not to reject. The DMARC overview shows this form (dmarc.org), and Google recommends starting with p=none before moving to quarantine or reject:

  • TXT_dmarc

    v=DMARC1; p=none; rua=mailto:dmarc-reports@your-name-here.si

Reports arrive as XML files from receivers. Read them for a few weeks to find legitimate senders you forgot to include (a newsletter tool, a billing system) and add them to SPF or DKIM before you tighten the policy.

Other providers

Zoho Mail and Proton Mail also work with any DNS host: they show the MX, SPF and DKIM values in their admin consoles, and Zoho's values differ by data-centre region (Zoho, Proton). Use the values their consoles show for your account.

A short checklist

  1. Create the mailboxes or forwarding rule at your mail provider.
  2. Add the MX records and remove any older MX records.
  3. Add one SPF record covering every service that sends as your domain.
  4. Publish the DKIM record and activate it in the provider's console.
  5. Add DMARC with p=none and watch the reports.
  6. Send a test message to an outside address and read its headers for SPF, DKIM and DMARC passing.

Ready to look for a name?

Search for a .si name. If it is free, registering takes a few steps and the price is shown upfront.

Tip: you can check up to 10 names at once, separated by spaces, commas or new lines.

Sources

DomainSpace is an independent reseller of .si domains. We are not affiliated with Register.si, ARNES or any AI company, and .si has no official connection to AI. This guide is general information, not legal advice.