Status: The mail service is in development. Domain Autopilot is planned and not yet available; this page describes our plans.
What the Autopilot should handle
Mail on your own domain needs several DNS records so it arrives and recipients can spot forgeries. Domain Autopilot, planned as a core part of the service, is meant to generate these records and keep checking them.
| Record | Purpose | What the Autopilot should do |
|---|---|---|
| MX | Names the servers that accept mail for your domain. | Generate and check records pointing to our mail servers. |
| SPF | Defines which servers may send for your domain. | Generate a record with an include: for our service. |
| DKIM | Publishes the key for verifying your mail's signature. | Generate CNAME records pointing to our selectors. The half-yearly key rotation should then run automatically. |
| DMARC | Tells recipients how to treat mail that matches your domain through neither SPF nor DKIM. | Move the policy stepwise from none via quarantine to reject, where that suits the domain; analyse aggregate reports. |
| MTA-STS (RFC 8461) | Requires TLS with a valid certificate for mail to your domain. | Set up and monitor the record and policy. |
| TLS-RPT (RFC 8460) | Names an address for reports about TLS problems. | Generate the record; receive and analyse reports. |
| DNSSEC | Signs your zone so forged answers are noticed. | Monitor whether the zone is validly signed. |
| DANE (RFC 7672) | Ties a mail server's certificate to signed DNS. | Monitor whether DANE for our mail servers also protects your domain. |
See SPF, DKIM and DMARC explained for how these records work together, and Security for planned transport protection.
Planned setup in three steps
- Verify. You show that you control the domain.
- Enter. A DNS assistant should display the records. You enter them at your DNS provider.
- Check. The Autopilot should query the records and show each domain's state in a health dashboard.
Your address should then work in your usual mail app.
Moving an existing domain
We plan mail import over IMAP and a checklist for switching DNS records:
- Parallel operation. Old and new mailboxes run side by side for a while.
- Lower the TTL. Shorten the MX records' lifetime in advance so the change takes effect sooner.
- Switch MX. Only then do the MX records point to our servers.
Limits with an external DNS provider
If another DNS provider hosts your zone, the Autopilot should check it from outside. It cannot change anything there.
- You enter the records yourself. The Autopilot should flag later changes; it cannot fix them.
- Your provider enables DNSSEC. It signs the zone; the registrar submits the DS record. Without DNSSEC, DANE does not apply to your domain. MTA-STS works without it.
- Only you know your other senders. A newsletter tool or other service sending under your domain needs matching SPF or DKIM records too.
Plans with your own domain
Custom domains are planned from the Pro plan upwards: 3 domains with Autopilot, provisionally 4 euros a month billed yearly, otherwise 5 euros. Team is planned with unlimited domains (see For teams), Personal with none. All plans are under Pricing.
What does not exist yet
The mail service has not launched; there is no registration. The Autopilot has not been built: it needs mail flow, which so far runs only in the development lab, and our DNS platform, which is not yet in place. We will name a date only once the external security reviews have been passed.
The roadmap shows the order, Transparency the evidenced state of the website.