Wondering why CallHub asks you to add DKIM and Return-Path records before you can send email from your own domain? This article explains what each record does, what you get out of setting them up, and where to go when you're ready to add them. It's for campaign managers setting up Email Campaigns, and for whoever manages your domain's DNS.
Before you start
- Who this is for: anyone about to verify a sender domain for Email Campaigns. You don't need a technical background to read this.
- Where the setup lives: the actual DNS steps are in How to set up a DKIM and Return Path record for my email domain.
Why these records matter for your campaigns
Email is the one CallHub channel where a machine decides whether your message is seen. Before a contact ever reads your subject line, the receiving mail server asks a simple question: did this email really come from the domain it claims to come from? DKIM is how you answer yes.
Set up both records and here's what you can expect:
- More of your emails reach the inbox. Authenticated mail is far less likely to be filtered into spam, so the list you worked to build actually hears from you.
- Your domain earns its own sending reputation. Emails go out under your name rather than a shared address, and the delivery history builds up against your domain.
- Bounce reports stay out of your way. A custom Return-Path address collects failure notices separately, so they never land in the inbox where supporters, donors, or volunteers are replying to you.
- Your list stays clean. Because bounces are collected in one place, you can spot undeliverable addresses and stop wasting sends on them.
- Your campaigns look legitimate to recipients too. Emails arriving from your verified domain are easier for contacts to trust and act on.
What DKIM does
DKIM stands for DomainKeys Identified Mail. It links a domain name with an email, so the recipient's mail server can verify that the sender is authentic.
Think of it as a tamper-proof seal. You publish a public key in your domain's DNS. Every email you send carries a signature created with the matching private key. If the two line up, the receiving server knows the email genuinely came from your domain and wasn't spoofed by someone else.
How DKIM works
- You send an email from your webmail.
- Your SMTP server, which is authorized to send emails for your domain, adds a DKIM signature header and sends the email to the recipient's mail server.
- The recipient's server finds the DKIM signature and checks your domain's public key through DNS to validate it.
- If the signature matches, the email is considered legitimate.
ⓘ NOTE: DKIM improves your odds, it doesn't guarantee inbox placement. Why: mail servers weigh other factors in the spam score too, including spam trigger words, weak subject lines, and missing unsubscribe links.
What a Return-Path address does
The Return-Path is the email address where mail servers send bounce reports. When an email fails to deliver, the report goes to the address set in the hidden Return-Path header, not to the address your contacts see.
By default, that means bounce notices mix in with the rest of your mail. Setting up a custom Return-Path changes that, and for organizations sending at volume it's the better option:
- Bounce reports are managed separately.
- They don't mix with real emails from your contacts.
- Your email communication stays organized and reliable.
DKIM vs Return-Path at a glance
| DKIM | Return-Path | |
|---|---|---|
| What it is | A signature that proves the email came from your domain | The address that receives bounce reports |
| What it's for | Authentication and deliverability | Handling and separating undeliverable mail |
| Who reads it | The recipient's mail server | Your team, when reviewing bounces |
| Where it lives | A record in your domain's DNS, plus a header on every email | A record in your domain's DNS, plus a hidden header on every email |
⚠ WARNING: DKIM and Return-Path records are changes to your domain's DNS, which controls where all mail for your domain goes. Why: a mistyped or replaced record can disrupt email for your whole domain, so add these alongside your existing records rather than overwriting anything, and have whoever manages your DNS review the change.
FAQs
Do I have to set these up to send an Email Campaign?
You need a verified sender domain to send from your own address, and that verification depends on these records. See Setting up a Sender domain and profile for your Email Campaign for the full sequence.
Will DKIM stop my emails from going to spam?
It improves your chances, but it's one signal among several. Mail servers also weigh spam trigger words, weak subject lines, and missing unsubscribe links when scoring your email.
Why do I need a custom Return-Path if bounces already come back to me?
Without one, bounce reports mix in with genuine replies from your contacts. A custom Return-Path keeps them separate, so your inbox stays organized and bounces are easier to act on.
Where do I get my DKIM and Return-Path values?
Once you have added your domain to the CallHub account Click on "Authenticate" to get your DKIM and Return-Path values.
Comments
0 comments
Please sign in to leave a comment.