Skip to content

Scan your domain with 35 DNS and email security checks at zerohook.org.

For your provider

SparkPost

SparkPost's Sending Domains API documentation recommends DKIM on the sending domain and a bounce CNAME on a subdomain. Verification uses dkim_verify or cname_verify against the DNS records SparkPost returns.

SparkPost's API text says DNS records authenticate messages for the domain in the From header. Generated DKIM keys may produce TXT records longer than 255 characters, which RFC 7208 discusses splitting into multiple strings in DNS.

Bounce domain

SparkPost's sending-domain guide pairs the From domain with a bounce domain CNAME so recipient servers can authenticate mail and route bounces separately from the organizational domain's other uses.

Operators create the domain through the API or app, publish the returned DKIM TXT and CNAME targets, then call verify so SparkPost queries DNS before mail sends from that domain.

Verify API

SparkPost verifies with dkim_verify or cname_verify against the DNS records returned for that sending domain.

Long DKIM public keys may require multiple TXT strings in DNS as RFC 7208 illustrates for long SPF strings.

Bounce subdomains separate return-path handling from the organizational domain's other DNS uses.

SparkPost's API returns dns attributes during verify calls when a record is missing or malformed.