Knowledge Hub

38.3.6 Email Masking – Verification Process


Overview #

Once you’ve added your DNS records, the final step is verification. This confirms that your domain is correctly configured to send email through our platform.

All verification is handled entirely by Amazon SES (Simple Email Service) – we do not perform any record checks ourselves. Our system simply submits your domain to SES and displays the status Amazon reports back.


How Domain Verification Works #

Hereโ€™s what happens after you add a domain:

  1. You enter your masked sender address in our CMS (e.g. [email protected])
  2. We generate the required DNS records and display them to you
  3. Once youโ€™ve added the records in your DNS provider, you click Check Validity
  4. Our system forwards your domain to Amazon SES, which:
    • Looks for the records on your domain
    • Verifies if everything matches the expected values
    • Approves or rejects the domain for sending

We do not validate your DNS records ourselves. Amazon SES does all the checking. This means:

  • If verification is delayed, it’s due to SES processing time or DNS propagation
  • We have no ability to speed up or override the process
  • Our CMS simply displays the current status provided by Amazon

How Long Does It Take? #

  • Most domains verify within 1 to 12 hours
  • In some cases it can take up to 72 hours, depending on your DNS provider and Amazon SES queue times
  • You can return to the CMS at any time and click Check Validity to refresh the current status

How to Check Your DNS Records #

Before resubmitting your domain for verification, you can manually confirm whether your DNS records are publicly visible. This helps ensure everything is set up correctly before AWS attempts another check.

ToolUse it to check…Link
๐Ÿ” MXToolboxAny TXT, MX, or CNAME recordhttp://mxtoolbox.com
๐Ÿ” Google Admin ToolboxDeep DNS checks from Google’s perspectivehttp://toolbox.googleapps.com
๐Ÿ” DNSCheckerGlobal DNS propagation across multiple locationshttp://dnschecker.org

To check:

  • Paste your full record name (e.g. mail.yourdomain.com or somekey._domainkey.yourdomain.com)
  • Select the correct record type (CNAME, TXT, or MX)
  • Verify that the value shown matches exactly what we provided

If a record doesnโ€™t show up, it means either:

  • It was added incorrectly (wrong name or value)
  • It hasnโ€™t propagated yet (try again later)

Why a Domain Might Fail Verification #

Even small issues in your DNS setup can prevent Amazon SES from verifying your domain. Common reasons include:

IssueExplanation
โŒ Missing recordOne or more required records wasnโ€™t added, or was added in the wrong place
โŒ Incorrect valuesA record’s value doesnโ€™t match exactly what SES expects
โš ๏ธ Cloudflare proxyingCNAME records must be set to DNS only, not proxied through the orange cloud
โŒ› DNS propagation delaySome providers take longer to make your changes visible to Amazon SES
๐Ÿ•’ Stale or repeated failuresDomains that fail several times or sit idle unverified may be deprioritised by Amazonโ€™s internal systems

What to Do If Verification Fails #

If verification doesnโ€™t go through, follow these steps:

  1. Double-check your DNS entries – Use the tools above to confirm everything is visible and correct
  2. Fix any mistakes – Remove incorrect records and re-add them if needed
  3. In the CMS, click Check Validity to pull the latest verification status
  4. If SES has marked the domain as failed, a Resubmit for Verification button will appear – click this to reinitiate the process

You can retry as often as needed, but avoid doing so until your records are fully correct to prevent unnecessary delays.


Why SES May Delay Rechecking #

Amazon automatically deprioritises domains that:

  • Have failed multiple verification attempts
  • Have been left unverified for an extended time
  • Are using invalid or inconsistent DNS settings

This doesnโ€™t mean your domain wonโ€™t be verified – it just means SES may take longer to check it again. Thatโ€™s why we recommend getting your records exactly right before submitting for the first time.


Summary #

StepWhat to Know
โœ… We submit domains to SESWe donโ€™t do any DNS validation ourselves
๐Ÿ” SES performs the checkAll approval or failure decisions come directly from Amazon
โณ Timing is out of our controlSome verifications are instant, others take up to 72 hours
๐Ÿ”ง Use external toolsConfirm records are publicly visible before resubmitting
๐Ÿ” Fix before retryingDonโ€™t resubmit until youโ€™re confident all records are correct

Once SES verifies your domain, masked emails will begin sending automatically using your domain name. You’ll see the verified status reflected in your CMS and sending will activate immediately.

Updated on July 25, 2025
Was this helpful?

Get in touch