Skip to main content
A custom domain lets you receive alias mail on a domain you own, for example hello@yourcompany.com, instead of a shared Maski domain. You control the whole namespace, so any local part is available and reserved-name restrictions do not apply.
Custom domains are a Pro feature. Pro includes 3 custom domains. You also unlock send-from-alias and a brand logo on a verified custom domain.

Adding a domain

1

Claim the domain

Add your domain in the dashboard under Domains. Maski gives you an ownership token and the records to publish.
2

Publish the DNS records

Add the records below at your DNS provider. See the table for exact names and values. If your provider is Cloudflare, GoDaddy, or DigitalOcean, Maski can publish them for you instead. See one-click DNS setup.
3

Verify

Maski checks your DNS automatically every few minutes, or press Verify now to check immediately. A claim expires if it is not verified within 72 hours.

Let Maski publish the records

On Cloudflare, GoDaddy, and DigitalOcean you can authorize your provider and have Maski publish the whole record set for you. It shows you every change before writing anything, never overwrites an existing DMARC policy, and never keeps your credential.

How one-click setup works

What gets written, what is left alone, and what happens to your token.

Create a provider token

Step-by-step for Cloudflare, GoDaddy, and DigitalOcean.
The rest of this page is the manual route, which always works and is the fallback if automatic setup is not available for your provider.

DNS records

Publish these at your DNS host. Replace <domain> with your domain and <region> with the SES region shown in the dashboard. Maski shows the exact generated values, including your DKIM tokens, alongside each record.
The inbound MX is intentionally one permanent hostname. You will not need to edit this record when Maski adds receiving capacity: Maski can place multiple independent server IP addresses behind that hostname, and capable sending mail servers try those addresses if one cannot be reached.
DKIM records are issued only after ownership is verified, so you publish the ownership TXT record first, then the DKIM records once they appear. DMARC is advisory and never blocks activation.

Activation

A domain becomes active only when every required record is in place and mail signing is fully set up, both DKIM and the bounce sender domain. There is no partial activation. This is what guarantees Maski never forwards mail that is not properly signed and aligned.

Catch-all

A verified custom domain can run a catch-all, so any address on the domain that is not a specific alias still receives mail. Replies and forwards use the real recipient name that was addressed, not a literal wildcard.

Brand logo (BIMI)

A verified custom domain can publish a brand logo for mailbox providers to draw beside its mail. It needs DMARC at enforcement, a conforming SVG, one more DNS record, and — at Gmail and Apple Mail — a certificate you buy from a Certificate Authority. See brand logo (BIMI) for what each provider requires and what it costs.

Downgrading

If you move from Pro back to free, your custom domains are disabled and mail on them stops. Your aliases and data stay in place. If you upgrade again and the DNS records are still published, the domains re-verify automatically.