
Want to use email in the format [email protected] instead of a personal Gmail or Hotmail? The essential first step is setting up an MX Record correctly in your domain's DNS. This article explains what an MX Record is, how to set one up in DirectAdmin, and how to add SPF, DKIM, and DMARC so your emails reach the inbox without going to spam.
What is an MX Record?
An MX Record (Mail Exchanger Record) is a type of DNS record that tells the internet which mail server is responsible for handling email for a domain. When someone sends an email to [email protected], the sender's mail server queries the DNS of example.com to find the MX Record, then delivers the email to the server listed there.
An MX Record must point to a Hostname (A Record) — not an IP address directly. Each MX Record also has a Priority value — a lower number means higher priority.
| Example MX Record | Priority | Meaning |
|---|---|---|
| mail.example.com | 10 | Primary server (tried first) |
| mail2.example.com | 20 | Backup server (used if primary fails) |
Why Do You Need an MX Record?
If your domain has no MX Record — or the record is configured incorrectly — incoming emails will have nowhere to go. The sender will receive an error such as 550 No such user here or MX lookup failed, which means your domain email simply cannot receive messages.
DNS Records That Work Together for Email
Several DNS record types work together to make a domain's email system function properly. MX Records handle where to deliver mail, while authentication records handle who is allowed to send and whether the message is genuine.
| Record | Type | Function | Required? |
|---|---|---|---|
| MX Record | MX | Points to the mail server that receives email | Mandatory |
| Mail server A Record | A | Resolves mail server hostname to IP | Mandatory |
| SPF | TXT | Authorizes IPs allowed to send on your behalf | Strongly recommended |
| DKIM | TXT | Digital signature verification for outgoing mail | Strongly recommended |
| DMARC | TXT | Policy for handling SPF/DKIM failures | Strongly recommended |
| PTR / Reverse DNS | PTR | Validates the sending IP's hostname | Optional but helpful |
Understanding MX Record Priority Values
Every MX Record has a Priority (also called Preference) value. When multiple MX Records exist for a domain, the sending mail server will always try the record with the lowest priority number first. If that server is unreachable or busy, it moves on to the next lowest value.
# Example MX Records with priority values
yourdomain.com. 3600 IN MX 10 mail.yourdomain.com. (Primary)
yourdomain.com. 3600 IN MX 20 mail2.yourdomain.com. (Secondary)
yourdomain.com. 3600 IN MX 30 mail3.backup.com. (Tertiary)For typical shared email hosting, a single MX Record with Priority 10 is sufficient. Having multiple MX Records pointing to different servers only helps if those servers share the same mail store — otherwise emails delivered to the secondary server will be invisible from the primary account.
Important: When using Google Workspace, Microsoft 365, or any third-party email provider, they will give you specific MX values and priority numbers. Use them exactly as provided. Changing the numbers can cause delivery failures or load-balancing issues within their infrastructure.
Troubleshooting Emails Going to Spam After MX Setup
After correctly setting an MX Record, emails may still land in spam. The MX Record only controls where incoming mail is delivered — spam filtering is driven by authentication records. Work through this checklist:
- SPF Failure — If your sending server's IP is not listed in your SPF record, receiving servers will soft-fail (
~all) or hard-fail (-all) the message. - DKIM Signature Invalid — The public key in DNS must match the private key on the mail server. A mismatch causes DKIM to fail, lowering the message's trust score.
- No PTR / Reverse DNS — Many mail servers check that the sending IP resolves back to the SMTP hostname. Missing PTR records are a common spam trigger.
- IP on a Blacklist — Use MXToolbox's Blacklist Check to see whether your server's IP is listed on any blocklists. New IP addresses can inherit a bad reputation from previous users.
- DMARC Reporting — Set
rua=mailto:[email protected]and Google/Outlook will send you aggregate reports within 24 hours showing exactly which messages passed or failed authentication.
⚠️ Common mistake: Setting SPF to +all (allow all IPs) removes all protection and means anyone on the internet can send email appearing to come from your domain. Always use ~all (soft fail) or -all (hard fail).
Setting Up MX Records in DirectAdmin
If your domain is with AsiaGB and you use DirectAdmin, follow these steps:
- Log in to DirectAdmin → DNS Management
- Select the domain you want to edit
- Find the MX Records section and remove any existing records (if present)
- Add a new MX Record using the values provided by your Email Hosting provider
- Set TTL to 3600 (1 hour), or follow your provider's recommendation
- Click Save
Example MX Record for Email Hosting on AsiaGB's own servers:
# In DirectAdmin DNS Management
Type: MX
Name: @ (or your domain name)
Value: mail.yourdomain.com
Priority: 10
TTL: 3600⚠️ Important: If you use Email Hosting from an external provider such as Google Workspace or Microsoft 365, you must enter the MX values they specify exactly — do not make up values, as every provider uses different records.
Verifying Your MX Record with dig / nslookup
After saving, wait a few minutes for DNS propagation, then verify using these commands:
# Using dig (Linux / macOS) dig MX yourdomain.com # Using nslookup (Windows) nslookup -type=MX yourdomain.com
A correct result will show the MX Record you just added, for example:
yourdomain.com. 3600 IN MX 10 mail.yourdomain.com.
You can also use the online tool MXToolbox (mxtoolbox.com) to check directly from your browser.
Setting Up SPF, DKIM, and DMARC to Prevent Spam
An MX Record alone is not enough. You should also configure Email Authentication Records to prevent your emails from being marked as spam or spoofed by attackers.
SPF Record (Sender Policy Framework)
Declares which mail server IP addresses are authorized to send email on behalf of your domain. Add as a TXT Record:
Type: TXT Name: @ (or your domain name) Value: "v=spf1 mx a ip4:YOUR_SERVER_IP ~all"
DKIM Record (DomainKeys Identified Mail)
Adds a digital signature to every outgoing email so the recipient's server can verify the message originated from an authorized source. Your Email Hosting provider will give you the DKIM key; it looks something like this:
Type: TXT Name: default._domainkey.yourdomain.com Value: "v=DKIM1; k=rsa; p=MIGfMA0GCS...<public key>"
DMARC Record
Defines the policy for emails that fail SPF/DKIM checks. Start with p=none to monitor, then move to quarantine or reject once you are confident:
Type: TXT Name: _dmarc.yourdomain.com Value: "v=DMARC1; p=none; rua=mailto:[email protected]"
Priority order: Set MX → SPF → DKIM → DMARC in that sequence. Completing all four dramatically improves your email deliverability.
How Long Does DNS Propagation Take?
After saving a DNS record, the change does not take effect immediately. DNS servers around the world need time to update their caches:
- Typically: 15 minutes to 1 hour
- With high TTL values: Up to 24–48 hours
- Pro tip: Lower your TTL to 300 seconds (5 minutes) before making changes to speed up propagation
During propagation, some emails may still go to the old server — this is completely normal.
Checklist: MX Record ✓ → SPF ✓ → DKIM ✓ → DMARC ✓ → Verify with MXToolbox ✓ — Once all four are in place, your domain email is fully ready for professional use.
Why a Domain Email Address Builds Business Credibility
Beyond the technical requirements, using an email address like [email protected] has a direct impact on how professional your business appears:
- Looks professional — Clients and business partners take domain-based email far more seriously than Gmail or Hotmail addresses for business correspondence.
- Consistent branding — The same domain name appears on your website and in every email, reinforcing brand recognition.
- You stay in control — Your email stays with your domain. When staff leave or a provider account closes, the address remains yours.
- Email aliases are easy — You can create
[email protected],[email protected], and[email protected]all delivered to one mailbox, with zero extra cost. - Required for Google Workspace / Microsoft 365 — If you plan to use either platform, a correctly configured MX Record is the mandatory first step before anything else works.
AsiaGB's hosting plans include Email Hosting with full Webmail, IMAP/POP3, and SMTP support. Domain registration, DNS management, and email hosting are all managed in one place through DirectAdmin — no external email provider needed unless you choose one.
MX Record TTL Strategy: Planning for Changes
TTL (Time-to-Live) is the value that tells DNS resolvers worldwide how long to cache your MX Record. Choosing the right TTL depends on your situation and whether you anticipate making changes soon. A poorly chosen TTL can mean waiting hours for changes to take effect globally.
| Scenario | Recommended TTL | Reason |
|---|---|---|
| Stable setup, no changes planned | 3600–86400 seconds | Reduces DNS query load globally |
| Upcoming mail server migration | 300 seconds (5 min) | Changes propagate quickly when needed |
| During active migration cutover | 60–300 seconds | Precise control over the cutover window |
Lower your TTL at least 24 hours before a planned migration. This ensures cached values across global DNS resolvers expire before you switch the MX Record, giving you a clean and predictable cutover.
Important: When using Google Workspace or Microsoft 365, use only the MX Records they provide. Adding extra MX Records pointing to other servers can cause some email to be delivered to the wrong place. Never mix records from different providers.
Testing and Monitoring Your Email Setup
After completing your MX Record and email authentication setup, thorough testing prevents embarrassing delivery failures once you start sending real business email. Problems discovered before go-live cost far less to fix than problems found by your customers.
Recommended Testing Tools
- MXToolbox Email Health (
mxtoolbox.com/emailhealth) — checks MX, SPF, DKIM, DMARC, PTR, and Blacklist status in a single report - Google Admin Toolbox (
toolbox.googleapps.com) — detailed DNS record checking, especially useful for Google Workspace users - Mail-Tester (
mail-tester.com) — send a test email and receive a deliverability score with specific remediation advice; a score of 10/10 confirms correct configuration - DMARC Analyzer — converts raw DMARC XML reports from Google and Microsoft into a readable dashboard
Ongoing Monitoring After Go-Live
- Blacklist status — check at least monthly, especially in the first weeks of a new IP address
- DMARC aggregate reports — review weekly to detect spoofing attempts using your domain
- DKIM key rotation — some providers require periodic key rotation; confirm the schedule with your email hosting provider
- SPF lookup limit — SPF allows a maximum of 10 DNS lookups per check; too many
include:statements cause SPF to fail. Use an SPF flattening tool if you hit this limit.
⚠️ After any server change: Always update your SPF Record to include the new server's IP address before switching. If the new IP is not listed in SPF, outgoing mail from the new server will be rejected or go straight to spam.
Common MX Record Problems and How to Fix Them
These are the most frequent issues reported when setting up domain email, along with systematic diagnostic steps to resolve each one efficiently.
Problem: Can send email but cannot receive
The most common cause is that the MX Record still points to the old server, or the TTL has not expired yet. Run dig MX yourdomain.com @8.8.8.8 to check whether Google's DNS resolver already sees the updated MX. If it still shows the old value, wait for the TTL to expire before investigating further.
Problem: Outgoing mail gets rejected with an SMTP error
Read the bounce message carefully. 550 5.7.1 SPF check failed means your sending server's IP is not in your SPF Record. 550 5.7.26 This message fails DMARC means DKIM or SPF failed and your DMARC policy is set to reject. Use these commands to inspect your current records:
# Check SPF Record dig TXT yourdomain.com | grep spf # Check DMARC Record dig TXT _dmarc.yourdomain.com # Check DKIM (replace "default" with your actual selector) dig TXT default._domainkey.yourdomain.com
Problem: Emails sent but no reply received for a long time
The destination server may be using greylisting — a spam prevention technique that temporarily rejects unknown senders and waits for a retry. A properly configured mail server retries automatically within 5–30 minutes. Check your mail server's outbound queue to confirm the message is scheduled for retry. If the queue is empty and the message never arrived, check whether your server's IP is blacklisted.
Migrating Email Hosting: A Step-by-Step MX Cutover Plan
Moving from one email hosting provider to another is one of the most delicate DNS operations. Email in transit during the switchover period can be permanently lost if the migration is not planned carefully. Follow this sequence for a smooth, low-disruption cutover:
- Lower MX TTL to 300 seconds at least 24 hours before migration day
- Configure and test the new mail server — confirm it can receive test email before touching any live DNS
- Export existing mailboxes using IMAP sync or PST/Mbox export as a backup
- Switch the MX Record to point to the new server during a low-traffic period (late evening recommended)
- Verify propagation with
dig MX @8.8.8.8anddig MX @1.1.1.1from two independent resolvers - Update SPF, DKIM, and DMARC to match the new server — do not skip this step
- Monitor inbound and outbound email for 48 hours after cutover
Migration tip: Keep the old mail server running for at least 48–72 hours after switching the MX Record. Some messages queued at remote servers before propagation completed will still attempt delivery to the old server. Shutting it down immediately risks losing those messages.
Register a Domain and Send Professional Email
Register a .com or .co.th domain and pair it with AsiaGB Hosting that includes Email Hosting at no extra cost. DNS Management included free.
Register Domain