# Send client emails from your own domain (DKIM)

An access request that arrives from `access@youragency.com` looks like it comes from you, because it does. To let a
service send email in your name, you prove to the receiving mail servers that you allowed it. That takes two DNS
records at your domain and a few minutes.

## The two records

| Record | What it does | Needed |
|---|---|---|
| **DKIM** (TXT) | Signs every email with a key only you and the sending service know, so mail servers can check it really comes from your domain | Required |
| **Return-Path** (CNAME) | Lets bounces go to the sending service under your domain, which lines up with a strict DMARC policy | Recommended |

![The sender settings of Northlight Studio: access@northlight-studio.de, with the DKIM TXT record and the Return-Path CNAME to add, each with a copy button](/guides/images/own-sender-records.png "Two records to copy: DKIM and Return-Path.")

## Where to add them

Add both records where your domain's DNS is managed: often the registrar (Namecheap, IONOS, GoDaddy), or Cloudflare.

- **Host:** many providers want only the part before your domain. For `20260930pm._domainkey.youragency.com` enter
  `20260930pm._domainkey`; for `pm-bounces.youragency.com` enter `pm-bounces`.
- **Value:** paste it exactly. A DKIM key is long; do not add quotes or line breaks.
- **TTL:** automatic is fine.

## Check that it works

DNS changes usually show within minutes, sometimes a few hours. Then check the records; once DKIM is found, emails go
out from your address. Send yourself a test request and look at the sender in your inbox.

## Which address to use

Use an address at your domain that someone reads, or that forwards to a real inbox, like `access@` or `hello@`.
Clients sometimes answer the invitation; with Agency Client Onboarding replies go to the colleague who sent the
request anyway.

## If you already use DMARC

DKIM on your own domain is what DMARC checks, so a strict policy (`p=quarantine` or `p=reject`) keeps working. Nothing
changes for your other email: the new DKIM key has its own name and sits next to the ones you already have.


## Frequently asked questions

### Do I need to change my SPF record?

No. With the Return-Path record the sending service handles SPF under its own subdomain of your domain.

### Can I use a Gmail or Outlook.com address?

No. Only an address at a domain you control works, because you have to add DNS records to it.

## With Agency Client Onboarding

Your own sender address is in early access: ask for it in Agency settings. We register your domain, show both records
with a copy button, and check them for you.

See it with the demo agency Northlight Studio in the [live demo](/demo): your client's side and the agency's view, side by side.
