Domains and DNS records
Every organization starts with a free SingleSign subdomain — acme.singlesign.com — that works the moment the organization exists, with nothing to set up. Your own domain is optional: add one whenever you want addresses like name@acme.com. Bringing your own domain to SingleSign means adding five DNS records where you manage the domain — one to prove you own it, four to route and authenticate mail — and then letting the checks do the rest. There is no limit on the number of domains an organization can add; each gets its own checklist and its own DKIM key.
Everything here is also shown in the organization console under Domains, with a copy button beside every value. This page explains the free subdomain, what each record for your own domain does, how to enter it at the common registrars, and what every check and finding means.
Your free SingleSign subdomain
You choose it in the first step of setting up the organization ("Your free address", with a live check that the name is available — see Getting started as a business). The name is 3 to 40 characters of a–z, 0–9 and hyphens, with no hyphen at the start or the end, and some names are reserved.
- It works straight away. SingleSign runs its DNS, so there is nothing to verify and no record to add. Members get real mailboxes on it, such as
joe@acme.singlesign.com, and Mail, Chat, Calendar, Docs and Meetings work from the start. - It leads the Domains list, labelled "Included" and "SingleSign subdomain", with how many addresses use it: "Included with your organization — SingleSign runs its DNS, so there is nothing to verify or publish."
- It stays when you add your own domain. "Remove" is unavailable — with the reason beside it — while it's your organization's only verified domain, and while any address still uses it ("move them to your own domain first"). If you do remove it later, SingleSign deletes the DNS records it published, and the name stays reserved for your organization for a year — you can claim it again from Domains.
- It can't be parked, and no other domain can be parked onto it.
Organizations started before free addresses that have no verified domain of their own get a "Get a free acme.singlesign.com address" button — on the console's "Finish setting up this organization" banner, on the empty Domains card, and in the setup wizard. The name comes from the organization's name; if it's taken, a free variant such as acme-2 is used, and the confirmation names the address you got.
Before you start
The rest of this page is about your own domain.
- Domain names are plain ASCII hostnames for now (no accents), entered without
wwwor@. A subdomain (mail.acme.com) works too — its records simply go at that name. - Some domains can't be added:
singlesign.comitself, anything containinggmail, and a domain another organization already claimed ("That domain is already claimed by another organization."). - Moving from another mail provider? Add the ownership record, SPF, DKIM and DMARC first — none of them changes where your mail goes. Your existing mail keeps working until you change the MX record; switch that last, when you're ready.
Adding your own domain
Whenever you like — in the setup wizard's optional Domain step, or any time later in the console: Domains → "Add domain". The "Add a domain" dialog takes the domain and shows how it works — Verify ownership · Point mail here · Done. Adding needs the Manage domains permission (Owners, Admins and the Domains admin role); reading the page needs View domains — see Admin roles and permissions.
Step 1 — prove you own it
The new domain shows "Pending verification" and a "Verify ownership" panel with one TXT record:
| Type | Host | Value |
|---|---|---|
TXT | @ | singlesign-site-verification=… (a token unique to your domain) |
Add it, then do nothing. "We check automatically every few minutes and will email you the moment it's verified — you can close this page." The "Verify" button checks right now (people who can only view domains get "Check now"); if the record isn't visible yet you'll see "We could not find the record yet. Most providers publish within minutes, but it can take up to 72 hours."
The moment the record is found, verification completes on its own: we set the domain up on our mail edge, generate its DKIM key, create the system addresses every domain needs (postmaster@, abuse@, dmarc-reports@, …) and email the organization's admins — "now add the mail records". The card's chip changes to "Set up mail". The ownership record can stay in place afterwards; it's harmless.
Step 2 — the four mail records
| Record | Type | Host | Value | What it does |
|---|---|---|---|---|
| MX | MX | @ | 10 email.singlesign.com. | Delivers mail for the domain to SingleSign. |
| SPF | TXT | @ | v=spf1 include:_spf.singlesign.com ~all | Tells receivers that SingleSign may send for the domain. |
| DKIM | TXT | ss1._domainkey | v=DKIM1; k=rsa; p=… (your domain's public key, shown in the console) | Signs the mail you send so receivers can trust it. |
| DMARC | TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain | Tells receivers how to treat mail that fails the checks; the reports come to your organization. |
One plain line on each:
- MX —
10is the priority;email.singlesign.com.is our mail server, with a trailing dot if your registrar wants one (most add it for you). Some registrars split this into a Priority field (10) and a Points to field (email.singlesign.com). - SPF — a domain may have only one SPF record. If you already have one (for a marketing tool, say), add
include:_spf.singlesign.comto it instead of creating a second record. - DKIM —
ss1is the selector; the key is generated for your domain when it's verified and never changes on its own. Every domain has its own. - DMARC —
p=nonemeans "just report" while you set things up;dmarc-reports@yourdomainis a system address we run for you, so the reports land with us. Once Mail is live you can tighten the policy if you want to.
The automatic checks — and what "propagated" means
Each record row carries a status pill:
- Found — the record is published and the internet sees it.
- Missing — nothing at that host yet.
- Mismatch — a record exists but with a different value; the row shows "Found instead: …".
- Not checked yet — no check has run (or no resolver answered).
We ask two public resolvers (Cloudflare's 1.1.1.1 and Google's 8.8.8.8); a record is Found when either returns a match. When a record exists at your domain's own nameservers but the public resolvers don't see it yet, the row adds: "Published at your DNS host — waiting for the internet to see it (usually minutes, up to 72h)". That's what propagation means — nothing to fix, just wait. Under the MX row you'll also see "Reachable ✓" or "Not reachable — …": we connect to the mail server over SMTP and confirm it accepts postmaster@; no mail is sent by that probe.
When the checks run. A pending domain's ownership record is checked every 15 minutes for three days, then hourly — never abandoned. A verified domain gets a light check (ownership and MX) every hour and a full check once a day. "Check again" runs everything now, and the Domains page refreshes itself every minute while any domain is still on its way.
What counts as correct. MX ignores the priority number and tolerates a backup MX; SPF passes as long as the single SPF record includes _spf.singlesign.com (or our sending address directly); DMARC passes for any v=DMARC1 record with a policy — a stricter one is fine; DKIM compares the key ignoring spacing and line breaks.
Where to add the records — registrar walkthroughs
The exact menu names change now and then; the shape is the same everywhere. Copy every value from the console.
Cloudflare
DNS → Records → "Add record". Name is @ for the domain itself and ss1._domainkey or _dmarc for the others (Cloudflare adds .acme.com). Content holds the value; for MX, Mail server is email.singlesign.com and Priority is 10. TXT and MX records are never proxied, so the orange cloud doesn't apply. If Email Routing is switched on for the domain, it manages the MX records — turn it off (or delete its MX records) so ours are the only ones. Cloudflare usually publishes within a minute or two.
GoDaddy
My Products → your domain → DNS → "Add New Record". Name is @ or the bare label (ss1._domainkey, _dmarc) — GoDaddy appends the domain, so typing the full hostname produces ss1._domainkey.acme.com.acme.com (our "doubled host" finding, below). For MX, Value is email.singlesign.com and Priority 10; delete GoDaddy's default MX rows or a previous provider's so ours are the only ones. The default TTL is fine.
Namecheap
Domain List → "Manage" → Advanced DNS. Under Mail Settings choose Custom MX, then add the MX record: Host @, Value email.singlesign.com, Priority 10 — picking Custom MX also clears Namecheap's own email presets. Under Host Records → "Add New Record" add the TXT records with Host @, ss1._domainkey and _dmarc (Namecheap appends the domain).
Amazon Route 53
Hosted zones → your zone → "Create record". Leave Record name empty for the domain itself; use ss1._domainkey or _dmarc for the others. TXT values go in double quotes, and Route 53 allows one TXT record set per name — so the ownership record and SPF share the @ TXT record set, one quoted value per line. The MX value is 10 email.singlesign.com (priority and host together in the value). A TTL of 300 is fine; Route 53 publishes within about a minute.
Squarespace Domains
Domains → your domain → DNS → "Custom records" → "Add record". Host is @ for the domain, ss1._domainkey or _dmarc otherwise (Squarespace appends the domain). For MX, Priority 10 and Data email.singlesign.com. Domains that came over from Google Domains may still carry Google's mail presets (MX records pointing at google.com hosts) — remove them so ours are the only MX records.
Setup findings, in plain words
Under a record you may see a finding. Warnings are problems to fix; notes are informational.
| Finding | What it means | What to do |
|---|---|---|
| Another provider's MX | An MX record still points at another mail service (Google, Outlook, Zoho…). Mail would be split between providers or misdelivered. | Remove the other MX records once you're ready to receive at SingleSign. |
| MX priority | Ours is present, but a more-preferred MX (a lower number) points elsewhere, so mail goes there first. | Give ours the lowest number, or remove the others. |
| More than one SPF record | Two v=spf1 TXT records — that's invalid, and receivers treat it as no SPF at all. | Merge them into one record. |
| SPF lookup limit | Your SPF record needs more than 10 DNS lookups (include, a, mx, redirect, exists); receivers stop evaluating it. | Remove includes you no longer use. |
| SPF hard fail | Your record ends in -all (strict). Fine — just make sure our include is there before switching MX. | Nothing, unless you're seeing rejections. |
| DKIM record malformed | The record at ss1._domainkey has no v=DKIM1 or p= part. | Paste the value from the console exactly. |
| DKIM wrong key | A well-formed DKIM record is there, but with a different key — an old provider's, or another organization's. | Replace it with the key shown for this domain. |
| DMARC report address | Your DMARC record has no rua= tag, so nobody receives the reports. | Add rua=mailto:dmarc-reports@yourdomain. |
| DMARC too strict too early | The policy is quarantine or reject while SPF or DKIM is still missing — your own mail could be rejected. | Use p=none until Mail is live, then tighten. |
| Doubled host | The record exists at ss1._domainkey.acme.com.acme.com — the registrar appended your domain to a full hostname. | Set Host to @ or the bare label (ss1._domainkey, _dmarc). |
The signed test message and "Mail is live"
The first time all four mail records are Found, we send a signed test message from postmaster@acme.com to the admin who added the domain — subject "Your domain acme.com is ready". It goes out through your domain, comes back in through your MX record, and lands in the inbox (postmaster@ on your own domain is pre-approved in that admin's Screener). When it arrives, the Mail flow row reads "Mail flow verified · signed as acme.com", the card reads "Mail is live for acme.com", and the admins get an email.
Along the way the row says where things stand — "Waiting for all records", "Almost there" once every record is in, "Test message sent to … — waiting for it to arrive", or the bounce reason if it failed, with "Try again". "Send test message" re-runs the proof whenever you like, once every five minutes ("A test message went out just now — try again in a few minutes.").
Once mail is live, the card offers "Give yourself you@acme.com" — one click to create your own company mailbox on the domain if you don't have one yet.
If a record disappears later
The hourly and daily checks compare each record with the last result. A record that was Found and is now Missing or Mismatch flips the card to "Needs attention" — "A record needs attention" — and the admins get an email: one notice per record per day, no more. Nothing is switched off: mail keeps flowing as far as the remaining records allow, and a domain is never suspended automatically. Put the record back and the next check clears it.
Suspend, resume and remove
- "Suspend" (on a verified domain) — "Mail to @acme.com is held and nobody can send as it while the domain is suspended. Its addresses and DNS records are kept — resume to pick up where you left off." Held mail is never bounced back to senders. "Resume" turns it back on.
- "Remove" — the "Remove domain" confirmation explains what it means for the domain: mail to it stops arriving here and nobody can send as it. A domain can be removed only when no live company mailbox sits on it — a mailbox that is active, or suspended but not deleted, blocks the removal ("Delete or transfer them from the Mailboxes section first."). Mailboxes that are already deleted and still inside their 20-day restore window don't block; they are purged immediately when the domain goes, and the dialog says so before you click. "The DNS records stay at your provider — remove them there too, or point them elsewhere."
Every add, verify, suspend, resume and remove is written to the organization's audit log.
Addresses on your own domain
Verifying your domain changes nobody's address — the free subdomain keeps working, and every mailbox keeps the address it was created with. What changes is what admins can hand out:
- An extra address for someone who already has a mailbox. Open the member from Members, and under Addresses choose "Add an alias" —
joe@acme.combesidejoe@acme.singlesign.com. Both land in the same mailbox, and either can be picked as From. - The default From. "Make default" on the new address makes it the one their mail goes out from unless they pick another while composing. Members can change their own default under Settings → Your addresses.
- A new mailbox on your domain. Someone who doesn't have a company mailbox yet can be given one on your domain directly with "Give them a company address".
The details — aliases, the 30-address limit, suspend and remove — are in Company mailboxes.
Several domains
Add as many as you need — there's no limit. Each domain needs its own five records, gets its own DKIM key, and shows its own checklist. The address forms (the wizard's address step and "Give them a company address") show a domain picker — your free subdomain and every domain you've verified — so a member's address can be on any of them.
Parked domains
An extra domain doesn't have to carry addresses of its own. The .co you bought beside the .com, an old company name, the misspelling customers keep typing — verify it like any other domain, then park it onto your main one (your own domain — the free SingleSign subdomain can't take part in parking): "Park onto…" on its card. Every address of the primary domain — company mailboxes, aliases, forwarders and the system addresses — then also receives mail as @acme.co, the card wears a "Parked on acme.com" chip, and mail still goes out from the primary; nothing is ever sent as the parked domain. A parked domain still needs all five records — MX so its mail reaches us, SPF, DKIM and DMARC so bounces and reports for it authenticate — and keeps its own DKIM key and checklist. "Unpark" reverses it, and removing the primary domain unparks whatever was parked on it. How it works, and the rules, are in Forwarders and parked domains.
Related
Last updated: 2026-09-28
Related articles
- Help CenterFind answers about using SingleSign to sign in, manage your privacy, and secure your account.
- Getting started as a business, step by stepSet up SingleSign Business: start an organization with a free name.singlesign.com address, get your mailbox, invite people, add your own domain any time.
- free identity providerSingleSign pricing in one line: sign-in is free, with no monthly-active-user meter. See exactly what is included, and what SingleSign Mail costs for businesses.
- Identity provider alternativesIdentity provider alternatives, by the provider you are leaving: what actually has to change in your code, and what does not.
- Auth0 comparisonSingleSign vs Auth0 compared on the difference that matters: who owns the account. A side-by-side table, then the three cases where each one is the right call.
- Okta comparisonSingleSign vs Okta: Okta is built for workforce identity inside a company, SingleSign for consumer sign-in across applications.
- SingleSign vs Firebase AuthenticationSingleSign vs Firebase Authentication on lock-in, portability and consent, plus the cases where staying on Firebase is right.
- Google Sign-In alternativeSingleSign vs Google Sign-In: the same one-tap convenience, without an advertising business behind the identity.