Skip to main content
A custom domain lets you receive alias mail on a domain you own, for example hello@yourcompany.com, instead of a shared Maski domain. You control the whole namespace, so any local part is available and reserved-name restrictions do not apply.
Custom domains are a Pro feature. Pro includes 3 custom domains. You also unlock send-from-alias on a verified custom domain.

Adding a domain

1

Claim the domain

Add your domain in the dashboard under Domains. Maski gives you an ownership token and the records to publish.
2

Publish the DNS records

Add the records below at your DNS provider. See the table for exact names and values.
3

Verify

Maski checks your DNS automatically every few minutes, or press Verify now to check immediately. A claim expires if it is not verified within 72 hours.

DNS records

Publish these at your DNS host. Replace <domain> with your domain and <region> with the SES region shown in the dashboard. Maski shows the exact generated values, including your DKIM tokens, alongside each record.
DKIM records are issued only after ownership is verified, so you publish the ownership TXT record first, then the DKIM records once they appear. DMARC is advisory and never blocks activation.

Activation

A domain becomes active only when every required record is in place and mail signing is fully set up, both DKIM and the bounce sender domain. There is no partial activation. This is what guarantees Maski never forwards mail that is not properly signed and aligned.

Catch-all

A verified custom domain can run a catch-all, so any address on the domain that is not a specific alias still receives mail. Replies and forwards use the real recipient name that was addressed, not a literal wildcard.

Downgrading

If you move from Pro back to free, your custom domains are disabled and mail on them stops. Your aliases and data stay in place. If you upgrade again and the DNS records are still published, the domains re-verify automatically.