Skip to content

Move DNS without losing email

Email breaks quietly. A missing DKIM key or a mangled SPF record doesn't bounce anything at first; messages just start landing in spam.

Last updated September 24, 2026

The records email depends on

  • MX at the apex: where mail for the domain is delivered.
  • SPF, a TXT record at the apex starting with v=spf1. The old SPF record type is obsolete; store it as TXT.
  • DKIM keys at selector._domainkey names, as TXT or CNAME records.
  • DMARC, a TXT record at _dmarc.
  • MTA-STS (_mta-sts TXT plus an mta-sts host) and TLS reporting (_smtp._tls TXT), if you use them.
  • Microsoft 365 extras: autodiscover CNAME and SRV records for Teams and Skype, if you still need them.
  • BIMI at default._bimi, if you publish a logo.

Why DKIM gets lost

DKIM records live under selector names you chose (or your email service did), and there's no public way to list them. Common selectors include google, selector1 and selector2 for Microsoft 365, k1 for Mailchimp, and s1 and s2 for SendGrid, but yours may differ. Take them from a full zone export.

DKIM keys are often longer than 255 characters, so they're stored as several strings. Some dashboards join or split them incorrectly. Compare the key byte for byte after the move.

Moving to Cloudflare

Cloudflare can't proxy mail. Hosts your MX records point at must be DNS-only (grey cloud), or mail delivery fails.

Check before and after

  1. Before switching, query the new nameservers for MX, the apex TXT, each DKIM selector and _dmarc, and compare with the old ones.
  2. After switching, send test messages to and from an external mailbox and check the authentication results in the headers.
  3. Watch your DMARC aggregate reports for a few days for unexpected failures.