Domains and deliverability
Free-trial and Free accounts send from (and receive on) a shared Mailgentic domain. From Developer up, bring your own: mail then carries your brand, your DKIM signature and your reputation.
Register a sending domain
curl -X POST "$API/v1/tenants/$TENANT_ID/domains" \
-H "Authorization: Bearer $ADMIN_KEY" \
-H "Content-Type: application/json" \
-d '{"name": "mail.acme.com"}'
Mailgentic generates a DKIM key pair and returns the DNS records to publish:
{
"domain": { "id": "DOMAIN_ID", "name": "mail.acme.com", "status": "pending", "inbound_enabled": false },
"dns": [
{ "type": "TXT", "name": "mail.acme.com", "value": "v=spf1 include:spf.mailgentic.ai -all" },
{ "type": "TXT", "name": "mg1._domainkey.mail.acme.com", "value": "v=DKIM1; k=rsa; p=MIIBIjANBg…" },
{ "type": "TXT", "name": "_dmarc.mail.acme.com", "value": "v=DMARC1; p=quarantine; rua=mailto:dmarc@mail.acme.com" },
{ "type": "CNAME", "name": "bounce.mail.acme.com", "value": "bounce.mailgentic.ai" }
]
}
| Record | Why |
|---|---|
| SPF | Authorises Mailgentic’s sending IPs for your domain |
| DKIM | Signs every message with a key only Mailgentic holds; the public half lives in DNS |
| DMARC | Tells receivers what to do when SPF/DKIM fail and where to send reports. Start at p=none if you are migrating, tighten to quarantine/reject once aligned |
| Return-path CNAME | Lets bounces come back through Mailgentic so they are processed and the suppression list stays accurate, while staying aligned with your domain |
Then verify:
curl -X POST "$API/v1/domains/$DOMAIN_ID/verify" -H "Authorization: Bearer $ADMIN_KEY"
The response reports each record as pass or fail. A domain must be verified before it can appear in from. Use a subdomain (mail.acme.com, agents.acme.com) rather than your apex so your corporate mail’s DMARC policy is unaffected.
| Method | Path | Purpose |
|---|---|---|
GET |
/v1/domains |
List domains and verification state |
POST |
/v1/domains/{id}/verify |
Re-check DNS |
DELETE |
/v1/domains/{id} |
Remove |
Receiving mail on your domain
To host inboxes on your domain, add an MX record and enable inbound:
agents.acme.com. MX 10 mx.mailgentic.ai.
curl -X POST "$API/v1/domains/$DOMAIN_ID/inbound" -H "Authorization: Bearer $ADMIN_KEY" \
-H "Content-Type: application/json" -d '{"enabled": true}'
Inbound enablement is refused until the MX record resolves to Mailgentic. Once enabled, every inbox you create on that domain receives mail immediately.
Reputation and IP addresses
Mailbox providers judge you on the sending IP, the signing domain, and the behaviour of everything that shares them. Mailgentic separates these per tenant:
- Shared pools (Free, Developer): tenants send from Mailgentic-operated IPs. The Guardian pauses any tenant whose bounces or complaints spike, so a bad neighbour is benched within a minute rather than dragging the pool down.
- Dedicated pools (Startup, Enterprise): a tenant is assigned its own IP addresses. Reputation is entirely yours. New addresses are warmed up automatically on a volume schedule, with overflow routed to a shared pool so delivery is never stalled.
- Blocklist monitoring: all addresses are checked against major DNSBLs continuously; a listed address is rotated out of service and an alert is raised.
- Postmaster signals: Google Postmaster Tools and Microsoft SNDS data are polled and folded into the reputation view.
curl "$API/v1/ip-pools" -H "Authorization: Bearer $KEY" # pools available to your account
curl "$API/v1/reputation?tenant_id=$TENANT_ID" -H "Authorization: Bearer $KEY"
/v1/reputation returns bounce and complaint rates, authentication pass rates and the pool assignment for a tenant and its domains. Dedicated pools are provisioned by Mailgentic; ask through the console or your account contact.
Good practice
- Keep transactional and bulk traffic on separate tenants (or at least separate tags) so they can be paused independently.
- Honour the suppression list; do not clear entries just because a customer insists the address is valid.
- Watch
complainedevents. One complaint per thousand messages is the ceiling most providers tolerate. - Publish DMARC reporting (
rua=) and read it: it tells you whether anyone else is sending as your domain.