Agency Client Onboardingby kitchn.io

White label

Send client emails from your own domain (DKIM)

How an agency sends access requests and reminders from its own address: the DKIM and Return-Path records to add, where to add them, and how to check that they work.

By the kitchn.io team · Updated · 3 min read

Send client emails from your own domain (DKIM)
On this page
  1. The two records
  2. Where to add them
  3. Check that it works
  4. Which address to use
  5. If you already use DMARC
  6. With Agency Client Onboarding

An access request that arrives from access@youragency.com looks like it comes from you, because it does. To let a service send email in your name, you prove to the receiving mail servers that you allowed it. That takes two DNS records at your domain and a few minutes.

The two records

Record What it does Needed
DKIM (TXT) Signs every email with a key only you and the sending service know, so mail servers can check it really comes from your domain Required
Return-Path (CNAME) Lets bounces go to the sending service under your domain, which lines up with a strict DMARC policy Recommended
The sender settings of Northlight Studio: access@northlight-studio.de, with the DKIM TXT record and the Return-Path CNAME to add, each with a copy button
Two records to copy: DKIM and Return-Path.

Where to add them

Add both records where your domain’s DNS is managed: often the registrar (Namecheap, IONOS, GoDaddy), or Cloudflare.

  • Host: many providers want only the part before your domain. For 20260930pm._domainkey.youragency.com enter 20260930pm._domainkey; for pm-bounces.youragency.com enter pm-bounces.
  • Value: paste it exactly. A DKIM key is long; do not add quotes or line breaks.
  • TTL: automatic is fine.

Check that it works

DNS changes usually show within minutes, sometimes a few hours. Then check the records; once DKIM is found, emails go out from your address. Send yourself a test request and look at the sender in your inbox.

Which address to use

Use an address at your domain that someone reads, or that forwards to a real inbox, like access@ or hello@. Clients sometimes answer the invitation; with Agency Client Onboarding replies go to the colleague who sent the request anyway.

If you already use DMARC

DKIM on your own domain is what DMARC checks, so a strict policy (p=quarantine or p=reject) keeps working. Nothing changes for your other email: the new DKIM key has its own name and sits next to the ones you already have.

Frequently asked questions

Do I need to change my SPF record?

No. With the Return-Path record the sending service handles SPF under its own subdomain of your domain.

Can I use a Gmail or Outlook.com address?

No. Only an address at a domain you control works, because you have to add DNS records to it.

With Agency Client Onboarding

Your own sender address is in early access: ask for it in Agency settings. We register your domain, show both records with a copy button, and check them for you.

See it with the demo agency Northlight Studio in the live demo: your client’s side and the agency’s view, side by side.

Next read