Branded DKIM/return-path CNAMEs via sovrn.at (double CNAME to SMTP2GO)
openScheme
Customer DNS (SMTP2GO still assigns the labels):
s<N>._domainkey.<domain> CNAME dkim.sovrn.at
em<N>.<domain> CNAME return.sovrn.at
sovrn.at zone:
dkim.sovrn.at CNAME dkim.smtp2go.net
return.sovrn.at CNAME return.smtp2go.net
Fixed shared names, not per-domain ones. With SMTP2GO as the only relay, every domain uses the same targets, so per-domain names would add cost (a stored ID, a wildcard, an opaque hash in customer DNS) and buy nothing.
Deciding check (do first): put test.kilimanjaro.io in an SMTP2GO subaccount and confirm the CNAME targets it asks for are still the shared dkim.smtp2go.net / return.smtp2go.net. If subaccounts get their own targets, revisit per-domain names before shipping.
Work
- [ ] Subaccount target check (above).
- [ ] Add
dkim.sovrn.atandreturn.sovrn.atto the sovrn.at zone. - [ ] Show the sovrn.at targets in
mapSMTP2GODomain(internal/relay/smtp2go.go), the DNS table and DESIGN.md. - [ ] Live check: send to Gmail and Fastmail and confirm
dkim=pass,spf=passanddmarc=passinAuthentication-Results. - [ ] Existing domains: migrate or grandfather.
1 Comment
Live check passed at Fastmail (2026-10-08): [email protected] submitted on mx99 (staging cell, NixOS) -> SMTP2GO (a4i773.smtp2go.com) -> [email protected]. Authentication-Results: dkim=pass header.d=test.kilimanjaro.io header.s=s931828 (rsa 2048); spf=pass smtp.mailfrom=bounce…@em931828.test.kilimanjaro.io (include:spf.smtp2go.com); dmarc=pass (p=none, header.from=test.kilimanjaro.io); iprev=pass. Gmail not checked yet.