# Connect your email domain

> Send Airhug email from reception@yourdomain.com. The exact DNS records to add (three DKIM CNAMEs and one SPF TXT), the forwarding rule for incoming mail, and how to verify.

Source: https://docs.airhug.ai/channels/email-domain
Last updated: 2026-09-29

With your own domain connected, customers see email from `reception@yourdomain.com` instead of a shared Airhug address. Your domain's reputation is separate from every other business's, so someone else's spam complaints cannot hurt your delivery.

Sending and receiving are two separate things:

- **Sending** is what you connect in Airhug. You add DNS records at your domain host. Airhug then sends as `reception@yourdomain.com`.
- **Receiving** stays a plain forwarding rule you set up in your own mail provider. Your existing mail keeps working. Airhug never asks you to change MX records.

> [!WARNING]
> **Never change your domain's MX records for Airhug.** Changing MX redirects every mailbox on your domain and can take your email offline. No step on this page asks for it. If someone tells you to change MX, stop.

## Before you start

- You can edit DNS for the domain at its host (GoDaddy, Cloudflare, Namecheap, Google Domains, Squarespace and so on).
- You know which mail provider runs your mailboxes (Google Workspace, Microsoft 365 and so on), to set the forwarding rule.
- The domain is yours. Each domain can be connected to one Airhug workspace only.

## Steps

1. Open **Settings → Channels → Email** (or the **Email** channel in setup).
2. Under **Practice domain**, enter the sending domain only. No `www`, no `https://`. For example `clinic.com`.
3. Choose **Get DNS records**. The page lists the records to add.
4. At your DNS host, add every record exactly as shown.
5. Choose **Refresh verification**. The status moves from **DNS pending** to **Ready**. This can take from a few minutes to a few hours while DNS propagates.
6. Set up incoming mail. Copy the **Forward incoming mail to** address shown on the page. In your own mail provider, create a rule that forwards `reception@yourdomain.com` to that address. It has the form `frontdesk-<your-workspace>@…`.
7. Run **Test the email channel**. Email the forwarding address from your own mailbox and ask something a customer would ask. Choose **Check for received email**. Open **Inbox → Emails** and read the reply.

## The DNS records

Airhug shows the exact values. They are always these four:

| Type | Name | Value |
| --- | --- | --- |
| CNAME | `<token1>._domainkey.yourdomain.com` | `<token1>.dkim.amazonses.com` |
| CNAME | `<token2>._domainkey.yourdomain.com` | `<token2>.dkim.amazonses.com` |
| CNAME | `<token3>._domainkey.yourdomain.com` | `<token3>.dkim.amazonses.com` |
| TXT | `yourdomain.com` | `v=spf1 include:amazonses.com ~all` |

The three CNAMEs prove you own the domain and sign the mail. The TXT record authorizes Airhug's mail service to send for your domain. The tokens are unique to your domain: copy them from the app, never from this page.

> [!IMPORTANT]
> **You can have only one SPF record.** If a TXT record starting with `v=spf1` already exists on your domain, do not add a second. Add `include:amazonses.com` to the existing record instead. Two SPF records break mail delivery for your whole domain, not just Airhug's.

Some DNS hosts add your domain to the end of the name for you. If a record's name then shows your domain twice (`token._domainkey.yourdomain.com.yourdomain.com`), remove the trailing domain from what you typed.

## Statuses

| Status | Meaning | What to do |
| --- | --- | --- |
| **DNS pending** | Records not found yet | Wait, then refresh. Check every record is present and exact. |
| **Ready** | Verified. Airhug sends as `reception@yourdomain.com`. | Nothing |
| **Needs attention** | The provider rejected a record | Compare the values with your DNS host. Look for typos, missing records, or a doubled domain name. |

Airhug fails closed. Until every record is confirmed, it does not send from your domain, because mail from a domain with unpublished DKIM lands in spam or is rejected. Replies use the Airhug fallback address until you are verified.

## Remove the domain

Choose **Remove domain**. Replies return to the Airhug fallback address. Your DNS records are left alone: delete them at your host if you want them gone.

## Email and health information

Email may contain health information. The email channel runs on AWS mail services covered by AWS's Business Associate Agreement, and it is available to HIPAA workspaces. Your own security and privacy obligations still apply.

## Checks

- Status shows **Ready**.
- A test email to the forwarding address gets a reply from `reception@yourdomain.com`.
- Open the reply's headers in your mail client. SPF and DKIM should both show **pass**.

Problems? See [troubleshooting](https://docs.airhug.ai/help/troubleshooting.md).
