sahdsimone.com DNS guide
Gmail mail from @sahdsimone.com bounces at Hotmail, Outlook and Live, and Intercom cannot send as operations@ yet. The fix is 3 new records in GoDaddy, the Google DKIM key and one DMARC edit. Nothing that delivers mail today is deleted.
Order on the call
- Sah signs in at admin.google.com and generates the DKIM key (Google DKIM, steps 1 to 5).
- Domen adds records 1, 2, 3 and the DKIM TXT in GoDaddy with Add More Records, then Save All Records once. Sah confirms.
- With Domen's yes: the _dmarc edit for Valimail. Sah confirms again.
- We check every record on public DNS.
- Sah clicks Start Authentication in the Admin console. Domen clicks Validate authentication in Intercom.
One Save All for 4 records should mean one confirmation. GoDaddy help names Save All Records. It does not say how often a protected domain asks for the code.
Access
Checked 6 Oct, 14:22. Domen can edit the DNS of sahdsimone.com in GoDaddy (Domain Portfolio, sahdsimone.com, DNS). Sah confirms each save. The name servers are ns21 and ns22.domaincontrol.com, so the GoDaddy zone is the live one.
Record 1 of 3: Intercom DKIM
Lets Intercom sign mail from operations@sahdsimone.com. Click Add New Record.
Type
Name
Value
TTL
Record 2 of 3: Intercom return path
Lets Intercom mail pass SPF for sahdsimone.com. Click Add More Records.
Type
Name
Value
TTL
Record 3 of 3: SPF for Gmail
Stops the Hotmail and Outlook bounces of Gmail mail from @sahdsimone.com. Click Add More Records.
Type
Name
Value
TTL
A new 5th TXT record at the root. The 4 TXT records there now (facebook, 2 google-site, klaviyo) stay as they are. Do not paste the SPF into one of them.
Readback
After the save, we check each record on Google (8.8.8.8), Cloudflare (1.1.1.1) and the GoDaddy name server. The GoDaddy server shows it first. The public resolvers can take up to 1 hour.
When records 1 and 2 read back: Intercom, Settings, Channels, Email, Domains and addresses, sahdsimone.com, Validate authentication.
DMARC reports to Valimail
Valimail is free and covers sahdsimone.com. It gets reports only when the existing _dmarc record names it. Only the rua part changes: the Kajabi address stays.
- In GoDaddy DNS, find the TXT row named _dmarc and click its pencil.
- Replace the value, then Save.
- In Valimail, Configure Domain with sahdsimone.com. Skip any offer to change DNS for you.
Now
New
Never add a second _dmarc record. With two records, receivers apply no DMARC at all (RFC 7489, 6.6.3).
Google DKIM
- A super administrator signs in at admin.google.com.
- Menu, Apps, Google Workspace, Gmail, Authenticate email.
- Selected domain: sahdsimone.com. Click Generate New Record.
- Key length 2048, prefix selector google. Click Generate.
- Copy the DNS Host name and the TXT record value. Do not click Start Authentication yet.
- In GoDaddy, Add New Record: Type TXT, Name google._domainkey, Value the copied text, TTL 1 Hour.
- When the record shows on public DNS, click Start Authentication.
The Admin console can show "You must update the DNS records for this domain" for up to 48 hours. Google says to ignore it when the record is in place.
help.sahmethod.com
sahmethod.com is on Cloudflare, not GoDaddy. Cloudflare, sahmethod.com, DNS, Records, Add record.
Type
Name
Target
Proxy
Then we set the domain in the Intercom Help Center settings and check that the old intercom.help links still answer.
Do not touch
Records that deliver mail now
- The 5 MX records at the root: Gmail delivery.
- The 4 verification TXT records at the root.
- The TXT and MX records of kjbm: Kajabi mail.
- The _dmarc record, except in the Valimail step.
Traps
- Type the Name without the domain. GoDaddy adds sahdsimone.com itself.
- Save waits for Sah's confirmation.
- If GoDaddy says a name is in use, stop and tell Domen. Do not delete the other record.