Outbound email

Sending Domains

Add and verify your own domain for outbound email. MailAfrica generates DKIM, SPF, and DMARC records for self-hosted delivery — publish them, verify, and create from-addresses.


Send from your own domain with full authentication. MailAfrica self-hosts the outbound path: when you add a domain it generates a DKIM key pair plus SPF and DMARC records, and its own mail server relays and signs the mail. You publish three TXT records, verify, and mail goes out under your own domain.

You can add up to 5 sending domains. Sending from a custom domain costs the same flat 5 TZS per recipient as the platform sender.

Add a sending domain

bash
curl -X POST https://api.mailafrica.online/api/domains/ \
  -H "X-API-Key: MAIL_<your_api_key_here>" \
  -H "Content-Type: application/json" \
  -d '{"domain": "yourcompany.co.tz", "from_local_part": "noreply"}'

from_local_part (default noreply) is the default from-address for the domain. The response includes the three DNS records to publish:

json
{
  "success": true,
  "data": {
    "domain": {
      "id": 2,
      "domain": "yourcompany.co.tz",
      "purpose": "sending",
      "status": "pending",
      "from_local_part": "noreply",
      "created_at": "2026-08-15T00:00:00Z"
    },
    "dns_records": [
      { "type": "TXT", "host": "mail._domainkey.yourcompany.co.tz", "value": "v=DKIM1; k=rsa; p=<public-key>" },
      { "type": "TXT", "host": "yourcompany.co.tz", "value": "v=spf1 ip4:<mail-server-ip> -all" },
      { "type": "TXT", "host": "_dmarc.yourcompany.co.tz", "value": "v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:dmarc@yourcompany.co.tz; adkim=s; aspf=s" }
    ]
  }
}

Verify the domain

bash
curl -X POST https://api.mailafrica.online/api/domains/2/verify \
  -H "X-API-Key: MAIL_<your_api_key_here>"

Publish all three TXT records, then re-check. All three must resolve for the domain to verify — the DKIM record's public key must match the one MailAfrica issued (a full match, not just any key), SPF must be a v=spf1 record ending in -all (the value shown for you, either ip4:<mail-server-ip> or a mx), and DMARC must have an enforcement policy (p=quarantine or p=reject — p=none alone does not verify).

Status transitions pending → verified once all three match, with verified_at set. If POST /verify returns pending, at least one record is missing or mismatched — the response doesn't single out which, so verify each DNS record manually.

Some DNS providers merge multiple TXT records for the same name — make sure DKIM, SPF, and DMARC stay as separate records on their own host names. Publish the record values verbatim, including the full v= strings.

MailAfrica re-checks your DNS periodically. If a previously verified domain's records disappear, it is suspended so mail can't be sent unauthenticated — keep all three records in place, or restore them to be re-verified.

In the dashboard

On the Domains page of the dashboard, the Sending (outbound) panel — *"Send transactional email From addresses on this domain"* — shows the domain's DNS records with copy buttons and a Verify button:

TypeHostValueWhy it's needed
TXT (DKIM)mail._domainkey.<domain>v=DKIM1; k=rsa; p=<public-key>Lets providers verify your domain signs the mail
TXT (SPF)<domain> (apex)v=spf1 <mechanism> -allAuthorizes the MailAfrica mail server to send for your domain
TXT (DMARC)_dmarc.<domain>v=DMARC1; p=quarantine; ...Tells receivers how to handle mail that fails verification

Publish all three TXT records at your DNS provider, then click Verify. The badge moves from Pending verification to Verified (with the timestamp) once all three resolve. The dashboard surfaces the current status (pending | verified | suspended); verify at your DNS provider which record is still missing or wrong.

Nothing else to configure: once verified, from_domain_id sends work immediately through the MailAfrica relay, which signs automatically with the domain's DKIM key.

Create sender addresses

Each verified sending domain gets its default local part (e.g. noreply@yourcompany.co.tz) automatically. Add up to 100 additional from-addresses per account:

bash
curl -X POST https://api.mailafrica.online/api/domains/2/senders \
  -H "X-API-Key: MAIL_<your_api_key_here>" \
  -H "Content-Type: application/json" \
  -d '{"local_part": "billing"}'

You can then send as billing@yourcompany.co.tz by passing from_domain_id and from_address on the outbound call. Any other from-address is rejected with 400 — only the domain default and recorded senders are allowed.

List & delete

bash
# List sending domains
curl https://api.mailafrica.online/api/domains/ \
  -H "X-API-Key: MAIL_<your_api_key_here>"

# List all sender addresses
curl https://api.mailafrica.online/api/domains/senders \
  -H "X-API-Key: MAIL_<your_api_key_here>"

# Delete a sender address
curl -X DELETE https://api.mailafrica.online/api/domains/senders/99 \
  -H "X-API-Key: MAIL_<your_api_key_here>"

# Delete a sending domain
curl -X DELETE https://api.mailafrica.online/api/domains/2 \
  -H "X-API-Key: MAIL_<your_api_key_here>"
Only send from domains and addresses you have verified. Providers (and recipients) treat unauthenticated From addresses as spam, and DKIM is enforced under your own domain.