authepy.

Domain & BYOD

Configuration Guide

Domain & BYOD

Upgrading to a paid infrastructure plan requires linking your own domain. This completely isolates your sender reputation, removes Authepy branding, and ensures maximum global inbox placement.

By default, Authepy routes Sandbox traffic through our shared secure domain (no-reply@authepy.com). To unlock the full volume of your Launch, Scale, or Enterprise tier, you must verify cryptographic ownership of your own domain. Once verified, all outward traffic will dynamically shift to dispatch from your brand (e.g., auth@yourcompany.com).


Step 1: Generate DNS Records

In your Authepy Dashboard, navigate to the Domains & BYOD tab and click Configure your domain. Enter the domain you wish to use.

Subdomain Recommendation

If you plan to send over 100,000 OTPs a month, we highly recommend utilizing a subdomain (e.g., auth.yourcompany.com) instead of your root domain. This completely isolates your automated notification reputation from your primary human-to-human corporate emails.

Clicking Generate DNS Records will instruct Authepy to securely negotiate with AWS SES to generate your unique DKIM and SPF signature keys.

Step 2: Beware the "Host" Trap

When copying records into popular domain registrars like GoDaddy or Namecheap, you must strip your domain name from the "Name" or "Host" field.

Many registrars automatically append your domain to whatever you type. If you paste the exact string Authepy provides, your registrar might accidentally duplicate it, resulting in a broken record.

Authepy Shows (Host) What to paste in GoDaddy Broken Example (Do Not Do)
_amazonses.yourcompany.com _amazonses _amazonses.yourcompany.com.yourcompany.com
abcd123._domainkey.yourcompany.com abcd123._domainkey abcd123._domainkey.yourcompany.com.yourcompany.com

Step 3: Cloudflare Proxy Settings

If you are managing your DNS through Cloudflare, you must disable the proxy status for all Authepy CNAME records.

  • Disable the Orange Cloud When adding the three DKIM CNAME records, ensure the proxy status icon is toggled from Orange to Grey ("DNS only"). Authepy requires direct resolution to verify the cryptographic signatures.

Step 4: Verification & Propagation

Once you have added the one TXT record and three CNAME records to your registrar, return to the Authepy Dashboard.

Click the Verify DNS Records button. DNS propagation usually takes between 5 to 15 minutes, though in rare cases it can take up to 48 hours. Our edge routers will continually poll the network. Once successful, your domain card will turn green and display "Production Ready."

Your paid API limits are now fully unlocked, and all Authepy branding is permanently stripped from your outgoing transactions.