Skip to main content
Every outbound email is DKIM-signed. SPF and DMARC records are configured automatically when you add a custom domain. On the shared domain, all three are pre-configured.

DKIM (DomainKeys Identified Mail)

DKIM adds a cryptographic signature to every outbound email, proving it was sent by an authorized server and wasn’t modified in transit. How it works:
  1. Commune generates a public/private key pair for your domain
  2. The public key is published as a DNS CNAME record
  3. Every outbound email is signed with the private key
  4. The recipient’s mail server verifies the signature against the public key
What you do: Add the DKIM CNAME record returned by the domains API to your DNS.
On shared domain: DKIM is already configured — no action needed.

SPF (Sender Policy Framework)

SPF tells receiving mail servers which IP addresses are authorized to send email for your domain. How it works:
  1. You publish a TXT record listing authorized senders
  2. When your email arrives, the recipient server checks if the sending IP is in your SPF record
  3. Emails from unauthorized IPs fail SPF and may be rejected
What you do: Add the SPF TXT record to your DNS:
The include:amazonses.com authorizes Commune’s email delivery infrastructure to send on your behalf. The ~all soft-fails all other senders. On shared domain: SPF is already configured.

DMARC (Domain-based Message Authentication, Reporting & Conformance)

DMARC ties DKIM and SPF together with a policy that tells receiving servers what to do when authentication fails. How it works:
  1. You publish a DMARC TXT record with your policy
  2. Receiving servers check both DKIM and SPF
  3. If both fail, the DMARC policy determines the action (none, quarantine, reject)
  4. Aggregate reports are sent to your reporting address
Recommended DNS record:
Start with p=none (monitor only), then move to p=quarantine or p=reject once you’ve verified all legitimate emails pass. DMARC reporting: Commune can ingest and analyze DMARC aggregate reports:

Verification status

After adding DNS records, verify your domain:
Commune checks all three records (DKIM, SPF, DMARC) during verification. The domain status becomes verified when all required records are confirmed.

Authentication flow diagram

Impact on deliverability

Custom domains require all three records for verification. The shared domain (agents.commune.email) has all authentication pre-configured.

What’s next?

Domains

Add a custom domain and retrieve the DNS records to configure.

Delivery Monitoring

Monitor bounce rates and sender reputation after configuring auth.

Spam Prevention

Complement authentication with inbound spam scoring and content validation.

Security Overview

Full picture of Commune’s security architecture.
Last modified on March 19, 2026