Home / Support Guides / Email, SMS & Marketing / Email Domain Authentication & Email Deliverability Best Practices
Email, SMS & Marketing

Email Domain Authentication & Email Deliverability Best Practices

Email Domain Authentication & Best Practices

Email domain authentication is an important part of setting up reliable business email in Shape.

Shape typically completes email authentication during onboarding so your account is properly configured before you begin sending email at scale. The process requires a domain your organization controls and access to that domain’s DNS settings.

For example, Shape can authenticate a business domain such as yourcompany.com or a dedicated sending subdomain such as email.yourcompany.com.

A standard consumer email address such as yourcompany@gmail.com cannot be authenticated in the same way because your organization does not control the gmail.com domain or its DNS.

Once configured, domain authentication helps receiving email providers verify that Shape is authorized to send email on behalf of your organization. It also provides an important technical foundation for email deliverability, sender reputation, and domain protection.

What Is Email Domain Authentication?

When Shape sends email using your organization’s domain, receiving mail providers need a way to verify that the sending system is authorized to use that domain.

Email authentication uses records published in your domain’s DNS to establish that relationship.

Common email authentication technologies include:

  • SPF
  • DKIM
  • DMARC

These standards help receiving mail systems evaluate the identity and authenticity of messages associated with your domain.

Why Email Authentication Matters

Authentication does not guarantee that every email will land in an inbox, but it is an important part of a healthy sending setup.

Establishes Sender Identity

Authentication helps demonstrate that Shape is an authorized sender for your organization’s domain.

Receiving email systems can use this information when evaluating whether a message legitimately originated from the domain shown in the sender information.

Supports Email Deliverability

Email providers increasingly rely on authentication and sender reputation when evaluating incoming messages.

Proper authentication gives your emails a stronger technical foundation and can help reduce the likelihood that legitimate mail is treated as suspicious.

Overall deliverability is still influenced by several additional factors, including:

  • Bounce rate
  • Spam complaints
  • Recipient engagement
  • Sending reputation
  • List quality
  • Message content
  • Sending volume and behavior

Helps Protect Your Domain

Authentication can make it more difficult for unauthorized senders to impersonate your organization’s domain.

DKIM and DMARC in particular provide mechanisms for validating messages and identifying unauthorized use of a domain.

Supports Long-Term Sender Reputation

Consistently sending authenticated email from a well-maintained domain gives receiving providers more reliable identity and reputation signals over time.

This becomes especially important for organizations using:

  • Bulk Email Campaigns
  • Drip Campaigns
  • Automated emails
  • Marketing campaigns
  • Large customer databases
  • High-volume customer communication

Email Authentication During Shape Onboarding

Shape generally handles domain authentication as part of the onboarding process.

You do not need to independently configure Shape’s sending infrastructure.

Our team coordinates the setup, provides the required DNS records, verifies that they have been added correctly, and completes the remaining configuration.

What You Need Before We Can Authenticate Your Domain

There are two primary requirements.

1. A Domain Your Organization Controls

You need a business domain that your organization owns or otherwise controls. Examples include yourcompany.com, yourbrand.com, or companyname.net.

Shape may authenticate an appropriate subdomain, such as email.yourcompany.com, or another subdomain selected during setup.

2. Access to the Domain’s DNS

Someone needs access to the DNS settings for the domain. This may be:

  • Your internal IT team
  • Your website administrator
  • Your managed IT provider
  • Your domain administrator
  • Your hosting provider
  • Another person or company that manages your DNS

Shape can provide the required DNS records, but someone with access to the authoritative DNS for your domain needs to add them.

Can Shape Authenticate Gmail or Outlook Addresses?

There is an important distinction between where your email is hosted and who owns the domain.

Google Workspace or Microsoft 365 Business Email

An address such as jane@yourcompany.com may use Google Workspace or Microsoft 365 for email hosting.

That is completely normal.

Your organization still controls yourcompany.com, so the domain can generally be authenticated as long as you have access to its DNS.

Consumer Gmail Addresses

An address such as yourcompany@gmail.com cannot be authenticated as your business sending domain because Google owns gmail.com.

Your organization cannot publish Shape’s DNS records on the gmail.com domain.

The same principle applies to other public consumer domains your organization does not control.

If you currently use a consumer email address and want authenticated business email through Shape, you will need a domain your organization controls.

How the Authentication Process Works

Shape helps coordinate the authentication process during onboarding.

Step 1: Confirm the Sending Domain or Subdomain

Shape will confirm which business domain or sending subdomain should be used.

In many cases, a dedicated sending subdomain is used, such as email.yourcompany.com.

Using a subdomain can help keep Shape email sending organized separately from other systems associated with your primary domain.

Step 2: Shape Provides the DNS Records

Shape prepares the DNS records required for the sending configuration.

These may include records used for:

  • DKIM
  • SPF
  • Tracking
  • Routing
  • Other applicable authentication settings

The exact records depend on your configuration.

Step 3: Add the DNS Records

Your domain administrator or IT team adds the records to the DNS provider.

The exact interface varies by provider, but the general process is:

  1. Open your domain’s DNS management.
  2. Add the record type provided by Shape.
  3. Enter the Host or Name exactly as provided.
  4. Enter the corresponding Value.
  5. Save the record.

Enter the records exactly as provided. A small difference in the record name or value can prevent verification.

Step 4: Notify Shape

Once the DNS records have been added, let your Shape onboarding or support contact know.

Step 5: Shape Verifies the DNS Records

Shape checks that the records are publicly resolving and match the expected configuration.

Step 6: Shape Finalizes the Setup

Once the records have been verified, our team completes the remaining configuration and QA so the authenticated sending setup can go live.

The current Shape guide follows this same general flow of selecting a subdomain, providing it to Shape, adding the supplied DNS records, notifying Shape, and completing final verification.

DNS Changes Can Take Time

DNS changes are not always visible immediately.

Some changes become available quickly, while others can take longer depending on the DNS provider and existing record configuration.

For example, GoDaddy notes that DNS changes often update within an hour but can take up to 48 hours to propagate globally.

If Shape cannot immediately verify a newly added record, it does not necessarily mean the record was entered incorrectly.

What Are SPF, DKIM, and DMARC?

You do not need to be a DNS expert to complete onboarding, but these terms may come up during setup.

SPF

SPF, or Sender Policy Framework, allows a domain to publish information about which mail systems are authorized to send email on its behalf.

Receiving mail providers can use this as one signal when evaluating the source of a message.

DKIM

DKIM, or DomainKeys Identified Mail, adds a cryptographic signature to an outgoing email.

The receiving system can validate that signature against a DNS record associated with the domain.

DMARC

DMARC, or Domain-based Message Authentication, Reporting & Conformance, builds on SPF and DKIM.

It allows a domain owner to publish a policy describing how receiving systems should treat messages that fail authentication and can also provide reporting about authentication activity.

If your organization already has DMARC configured, do not make unrelated changes to the policy just to complete Shape authentication unless the change has been reviewed by the appropriate person managing your email security.

Authentication Does Not Guarantee Inbox Placement

Domain authentication is important, but it is not the only factor used to determine whether an email reaches the inbox.

Even authenticated email can be filtered when other sending signals are poor.

Factors that can affect deliverability include:

  • Bounce rate
  • Spam complaints
  • Unsubscribes
  • Engagement
  • List quality
  • Sending reputation
  • Message content
  • Sending volume
  • Sending patterns

Authentication should be treated as the technical foundation of the sending setup, not as a guarantee of inbox placement.

Email List Management Best Practices

Healthy email sending starts with healthy data.

The current Shape guide emphasizes regular list maintenance, bounce handling, segmentation, opt-in practices, and unsubscribe management, and those are still important parts of maintaining email performance.

Regularly Clean Your Lists

Review your email audience periodically and pay attention to addresses that:

  • Consistently bounce
  • Are invalid
  • Are outdated
  • Have unsubscribed
  • Have not engaged for a long period
  • Come from questionable or old data sources

Repeatedly sending to known bad addresses can negatively affect sender reputation.

Consider Email Validation

Shape’s Email Validation tools can help identify whether an email address appears deliverable before you send to it.

Email Validation can be particularly useful when:

  • Importing an older database
  • Preparing a large bulk campaign
  • Receiving third-party lead data
  • Re-engaging older contacts
  • Working with records of uncertain quality

Consider Confirmed or Double Opt-In Workflows

For organizations that want an additional confirmation step, confirmed or double opt-in workflows can help verify that the recipient controls the email address being submitted.

Shape Lead Engine forms and other configured workflows can be used as part of an organization’s consent and lead-capture strategy.

Your organization should determine the appropriate opt-in process for its own business.

Segment Your Audience

Sending one message to an entire CRM database is not always the most effective strategy.

Shape allows users to segment audiences using information such as:

  • Status
  • Source
  • User
  • Tags
  • Dates
  • Custom fields
  • Engagement
  • Other CRM information

Segmentation can make messaging more relevant and reduce unnecessary email volume.

For example, rather than sending to every record in the system, you might target Past Customers + Specific Product, Active Leads + Selected Source, or Records Created Within a Specific Timeframe.

Provide an Easy Unsubscribe Option

Shape automatically includes an unsubscribe option on applicable marketing and bulk emails.

When a recipient unsubscribes, Shape updates the applicable Email Unsubscribe preference and prevents future eligible email communication.

This helps maintain unsubscribe information directly within the CRM.

Content Optimization Best Practices

The way an email is written and formatted can also affect engagement.

Use Clear Subject Lines

Subject lines should accurately represent the content of the email.

Avoid unnecessary:

  • ALL CAPS
  • Excessive punctuation
  • Misleading statements
  • Artificial urgency

Personalize When Appropriate

Using relevant customer information can make communication feel more useful and specific.

Shape templates and merge fields can be used to personalize applicable email content.

Balance Text and Images

Avoid relying entirely on images.

Some email clients may block or delay image loading, so recipients should still understand the message even if an image does not display.

Where supported, descriptive alt text can also help provide context when images are unavailable.

Use Clear Calls to Action

If you want the recipient to do something, make that action easy to understand.

Examples include:

  • Apply Now
  • Schedule an Appointment
  • View Your Account
  • Learn More
  • Complete Your Application

Avoid overwhelming the recipient with too many unrelated actions.

Design for Mobile

Many recipients read email from mobile devices.

Use:

  • Shorter paragraphs
  • Readable font sizes
  • Simple layouts
  • Clear spacing
  • Mobile-friendly buttons

Test and Analyze Your Email Performance

Shape provides email reporting that can help you understand how messages are performing.

Depending on the email or campaign, you may be able to review:

  • Sent
  • Delivered
  • Failed
  • Bounced
  • Opens
  • Clicks
  • Unsubscribes
  • Complaints
  • Other engagement information

Shape also provides record-level metrics such as Total Opened Emails and Total Clicked Emails where available.

Use this information to identify trends and adjust your email strategy over time.

Understanding Bounce Rates

A bounce occurs when an email cannot be successfully delivered to the intended email address.

Bounces can occur for several reasons.

Some are permanent, such as an invalid or nonexistent email address.

Others can be temporary, such as a recipient mail server temporarily rejecting a message.

Bounce rate is one of the important signals involved in email reputation and deliverability.

Bounce Rate Policies

Shape, like other platforms that provide shared email infrastructure and sending services, requires customers to maintain reasonable bounce rates.

This is important for protecting the reliability and reputation of Shape’s email delivery environment.

The current Shape policy states that Shape monitors bounce rates and other email metrics and may issue alerts or take action when bounce rates exceed acceptable thresholds.

Why Shape Monitors Bounce Rates

High bounce rates can indicate issues such as:

  • Invalid email addresses
  • Old or poorly maintained contact databases
  • Low-quality imported data
  • Poor lead-provider data
  • Sending to contacts that have not been properly maintained
  • Other list-quality problems

High bounce activity can affect sending reputation and potentially impact the broader email delivery environment.

For that reason, Shape monitors email sending behavior and may take steps to protect the platform’s sending infrastructure.

Bounce Management

Shape automatically receives applicable bounce information and provides email reporting that can help users identify affected addresses.

Users can then take corrective action, such as:

  • Correcting an inaccurate address
  • Validating questionable email addresses
  • Removing invalid addresses from future audiences
  • Applying Email Unsubscribe when appropriate for the organization’s workflow
  • Excluding problematic records from campaigns
  • Using automation to flag bounced addresses for review

Monitoring and Alerts

Shape monitors bounce rates and other important email metrics.

If a customer’s bounce rate exceeds acceptable thresholds, Shape may:

  • Notify the customer
  • Request that the sending audience or data be reviewed
  • Recommend corrective action
  • Limit or pause applicable email sending when necessary to protect sending reputation and platform reliability

This is why list maintenance and Email Validation are particularly important before sending to older, imported, purchased, or otherwise uncertain databases.

List Segmentation Helps Reduce Risk

Segmenting email audiences allows users to send to more relevant and better-qualified contacts rather than indiscriminately sending to every address in the CRM.

This can help reduce:

  • Bounces
  • Complaints
  • Unsubscribes
  • Low engagement

and can improve overall audience quality.

Large and Older Email Lists

Take additional care when sending to databases that have not been contacted recently.

A large list may contain:

  • Old email addresses
  • Closed accounts
  • Abandoned mailboxes
  • Incorrectly entered addresses
  • Contacts who no longer recognize your organization

Before sending at scale, consider:

  1. Reviewing the age and source of the data.
  2. Segmenting the audience.
  3. Running Email Validation when appropriate.
  4. Starting with more recent or engaged records.
  5. Monitoring bounce and complaint rates.
  6. Expanding the audience only after reviewing the results.

This is especially important when importing historical data into Shape.

Benefits of Domain Authentication

Helps Reduce Domain Spoofing

Authentication makes it more difficult for unauthorized systems to successfully impersonate your domain.

Supports Deliverability

Authenticated mail gives receiving providers more reliable information when evaluating your messages.

Helps Protect Brand Reputation

Maintaining consistent authenticated sending helps establish clearer identity and reputation signals around your organization’s domain.

Supports Sending Reputation

Authentication is one piece of maintaining a healthy sending reputation alongside bounce rates, complaints, engagement, and list quality.

Improves Email Security

SPF, DKIM, and DMARC provide different layers of sender verification and domain protection.

Provides Additional Visibility

DMARC reporting can provide domain owners with information about how their domain is being used for email and whether messages are passing authentication checks.

Helpful DNS Articles for Common Domain Providers

The following common domain and DNS providers publish support resources that can help your team locate the DNS settings needed to add the records Shape provides during authentication.

GoDaddy

GoDaddy provides current support resources for adding a subdomain and managing DNS records.

Bluehost

Bluehost provides a help article for adding, editing, and deleting DNS records in cPanel.

HostGator

HostGator provides a support resource for making DNS changes to a domain purchased through HostGator.

DreamHost

DreamHost provides an article covering how to add custom DNS records through its DNS settings.

If you cannot locate the applicable article for your provider, your domain registrar or DNS host can point you to their current DNS management documentation.

Not Sure Where Your DNS Is Managed?

The company where your domain was purchased is not always the same company currently managing its DNS.

If you are unsure where to add the records, check with:

  • Your internal IT team
  • Your website administrator
  • Your managed service provider
  • Your web developer
  • Your domain registrar

The records need to be added wherever the domain’s authoritative DNS is currently managed.

Once the records have been added, let your Shape onboarding or support contact know so our team can verify the configuration.

Troubleshooting Domain Authentication

Shape Cannot Verify the DNS Records

Check the following:

  • The correct domain was updated.
  • The Host or Name matches the value Shape provided.
  • The correct record type was selected.
  • The record value was copied exactly.
  • The record was saved.
  • Enough time has passed for the DNS change to propagate.

If the records appear correct but verification still fails, contact Shape Support.

I Do Not Have DNS Access

Contact the person or company that manages your domain.

Shape can provide the necessary records, but DNS changes must be made by someone with the appropriate domain access.

We Use Google Workspace

That is fine.

An email such as user@yourcompany.com can still be authenticated if your organization controls yourcompany.com, even when Google Workspace hosts the inboxes.

We Use Microsoft 365

That is also fine.

The important requirement is control of the business domain and its DNS, not which provider hosts your email.

We Only Use Gmail.com

A consumer @gmail.com address cannot be authenticated as your organization’s sending domain because your organization does not control the gmail.com DNS.

You will need a business domain you control for domain authentication.

Our Authentication Was Previously Working but Is Now Unverified

DNS records can be changed or removed after initial setup.

If your domain was previously verified and Shape later reports an authentication problem, review whether:

  • DNS records were edited
  • Your DNS provider changed
  • Nameservers changed
  • The domain was transferred
  • An IT or website migration occurred
  • Existing authentication records were removed

Contact Shape Support if you need help identifying the missing or invalid record.

Frequently Asked Questions

Does Shape handle email domain authentication during onboarding?+

Yes. Domain authentication is normally part of the onboarding process for organizations sending email through Shape.

What do I need for domain authentication?+

You need a domain your organization controls and access to its DNS settings.

Do I need a separate domain for Shape?+

Not necessarily. Shape can typically authenticate an appropriate subdomain of your existing business domain.

Why might Shape use a subdomain?+

A sending subdomain can help keep Shape email infrastructure organized separately from other systems associated with your main domain.

Can Shape authenticate a Gmail.com email address?+

No. Your organization does not control the gmail.com domain or its DNS.

Can Shape authenticate an email hosted by Google Workspace?+

Yes, provided the address uses a domain your organization controls.

Can Shape authenticate Microsoft 365 email?+

Yes, provided your organization controls the underlying domain and DNS.

Who needs to make the DNS changes?+

Anyone with appropriate DNS access can add the records, including your IT administrator, domain administrator, website administrator, or managed service provider.

Does Shape make the DNS changes for us?+

Shape provides the required DNS records and verifies the configuration. If Shape does not manage your domain, someone with DNS access needs to add those records.

How long does domain authentication take?+

Once the DNS records are entered correctly, timing depends partly on DNS propagation. Shape can finalize the configuration after the required records are publicly visible.

Does domain authentication guarantee inbox placement?+

No. Authentication is an important part of deliverability, but inbox placement also depends on sending reputation, bounce rate, complaints, engagement, list quality, content, and other factors.

Why does Shape care about my bounce rate?+

Bounce rates affect sender reputation and the reliability of email delivery infrastructure. Shape monitors bounce rates to help protect the quality and reputation of its sending environment.

What happens if my bounce rate is too high?+

Shape may contact you, request corrective action, recommend that your audience or data be reviewed, or limit applicable email sending if necessary to protect sending reputation and platform reliability.

How can I reduce my bounce rate?+

Common steps include:

  • Cleaning outdated data
  • Correcting invalid email addresses
  • Running Email Validation
  • Segmenting audiences
  • Avoiding large sends to old or unverified lists
  • Monitoring bounce reporting
  • Reviewing data received from third-party sources
Should I use Email Validation before a large campaign?+

It can be particularly helpful when sending to older, imported, third-party, or otherwise uncertain email data.

Does Shape provide email reporting?+

Yes. Shape includes reporting for email delivery, bounces, opens, clicks, unsubscribes, bulk campaigns, and other applicable email activity.

Does Shape automatically handle email unsubscribes?+

Shape automatically includes an unsubscribe option on applicable marketing and bulk emails and updates the corresponding email preference when the recipient unsubscribes.

What happens if we change domains?+

Contact Shape before using a new domain for email. The new domain or sending subdomain needs to be authenticated before it is used for applicable Shape sending.

Build a Healthy Email Sending Foundation

Domain authentication is one of the first steps Shape takes when preparing an organization to send email through the platform.

The technical setup itself is usually straightforward: use a domain your organization controls, provide access to the appropriate DNS administrator, add the records supplied by Shape, and allow our team to verify the configuration.

But authentication is only the beginning.

Healthy email performance also depends on the quality of the audience being contacted.

Maintain your lists, validate questionable addresses, monitor bounce rates, respect unsubscribes, segment campaigns, review engagement, and pay close attention when sending to older or imported data.

Shape monitors bounce activity because poor-quality sending can affect more than one campaign. Maintaining reasonable bounce rates helps protect your own sender reputation as well as the reliability of the email infrastructure used to deliver Shape communications.

Dani Dunn

Senior Project Manager, Shape Software

Dani Dunn leads enterprise client management at Shape Software, where her team supports some of the platform's largest customers. She has been with Shape for over a decade, giving her deep hands-on expertise in CRM implementation and workflows.