# Email and deliverability

> Send signing emails from your own domain, add the DNS records and a DMARC policy, and what to do when emails land in spam.

Tally Sign Support › [Admin](https://www.tallysign.com/support/admin)

Tally Sign emails signing requests, reminders, completed copies and team invites for you. By default they come from Tally Sign's shared address with your company name on them. Owners and admins can have them come from your own domain instead, like sign@yourcompany.com, which helps them reach the inbox. Everything is in **Settings → Email**.

## How your emails are sent

Open **Settings → Email**. **Delivery** shows the address your emails come from, where replies go and what's sent.

- **Without your own domain**, emails come from Tally Sign's shared address and show as "Your company via Tally Sign".
- **With a verified domain**, they come from your own address, such as **Northbeam Software <sign@northbeam.example>**.
- Either way, when a recipient replies, the reply goes to the teammate who sent the document, or to your company email when no one did.

Signing requests, reminders, updated versions, void notices, completed copies with the signed PDF, messages to signers about changes and questions, automation emails to recipients and team invites all use your domain. Notices from Tally Sign to your own team, such as seat requests and alerts about a signer's comments, still come from the shared address.

## Send from your own domain

1. Open **Settings → Email** and find **Sending domain**. Only owners and admins can change it.
2. Enter your domain, for example `northbeam.example`, and choose **Add domain**.
3. Add the DNS records Tally Sign shows (next section), then choose **Check DNS**.

![The Sending domain panel with northbeam.example typed in and an Add domain button](https://www.tallysign.com/university/admin/email-add-domain.png)

*Add the domain you want signing emails to come from.*

> **Why it matters:** Email providers trust a message more when the domain in the From address says the sender is allowed to use it. Your own verified domain does that, and recipients see a name and address they already know.

> **Note:** A subdomain such as `mail.yourcompany.com` works too, and keeps signing emails apart from your team's everyday email. You need to be able to change DNS for the domain you add. Public email domains such as gmail.com can't be used, and a domain can belong to one Tally Sign company only.

Until the domain is verified, nothing changes: emails keep coming from the shared address.

## Add the DNS records

After you add a domain, **Sending domain** lists the DNS records our email provider (Resend) needs. Add each one where your domain's DNS is managed, usually your domain registrar (GoDaddy, Namecheap, Squarespace) or DNS host (Cloudflare, Route 53, Google Cloud DNS).

![Sending domain for northbeam.example: the from address, three DNS records (MX and TXT for SPF, TXT for DKIM), a recommended DMARC record and a Check DNS button](https://www.tallysign.com/university/admin/email-dns-records.png)

*The records to add, each with a copy button, and the status of each.*

1. At your DNS host, create a record of the **Type** shown (MX or TXT).
2. Copy the **Name** with its copy button. Most DNS hosts want the short name, like `send`; if yours wants the full name, use the one shown under it, like `send.northbeam.example`.
3. Copy the **Value**. For the MX record, set the priority to the number shown (10).
4. Repeat for each record, save, then come back and choose **Check DNS**.

| Record | What it does |
| --- | --- |
| **MX** and **TXT** named `send` (SPF) | Say our email provider may send for your domain, and where bounces go |
| **TXT** named `resend._domainkey` (DKIM) | A key that proves each email really came from your domain and wasn't changed |
| **TXT** named `_dmarc` (DMARC) | Your policy for email that fails those checks. Recommended; see below |

DNS changes usually show up within minutes, but can take a few hours. After **Check DNS**, the status reads **Checking DNS** while the records are looked up, and the page updates by itself.

| Status | What it means |
| --- | --- |
| **Waiting for DNS records** | Added, but not checked yet. Add the records and choose **Check DNS** |
| **Checking DNS** | The records are being looked up |
| **Verified** | Your emails now come from your domain |
| **Records not found** | It was verified, but the records can't be found now. Emails use the shared address until they're back |
| **Not verified** | The records weren't found within 72 hours. Check them and choose **Check DNS** again |

> **Note:** Adding these records doesn't change the email your team sends and receives today. The SPF records are on the `send` subdomain, not on your main domain.

## Choose the from address

Under **From address**, set the part before the @ (for example `sign` or `contracts`) and the **Display name** people see in their inbox. Leave the display name empty to use your company name. **Recipients see** shows exactly how it will look. Choose **Save**.

![Delivery shows Northbeam Software <sign@northbeam.example>; Sending domain is Verified with the from address sign@northbeam.example](https://www.tallysign.com/university/admin/email-verified.png)

*Once the domain is verified, Delivery shows your own address.*

The address doesn't need a mailbox: replies go to the teammate who sent the document, not to this address. Pick one and keep it; a from address that stays the same builds trust with email providers over time.

## Add a DMARC policy

DMARC tells email providers what to do with email that claims to be from your domain but fails the SPF and DKIM checks. Gmail, Yahoo and Outlook expect domains that send email to have one, and email without it is more likely to be filtered.

- **Your domain has no DMARC record:** add the one shown under **DMARC**, a TXT record named `_dmarc` with `v=DMARC1; p=none; rua=mailto:dmarc@yourdomain`. `p=none` only asks for reports, so it doesn't change how any of your email is delivered. Change the address after `rua=mailto:` to a mailbox you read, or remove that part.
- **Your domain already has one:** the status reads **Found** and shows it. Keep it; there's nothing to add. If you send from a subdomain, the policy of your main domain covers it.

Once the reports show that all your email passes, your IT team can tighten the policy to `p=quarantine` and later `p=reject`, which stops others from sending email that pretends to be from your domain.

## If your domain stops working

Tally Sign checks your domain's status when you open Settings, every hour in the background, and right away if our email provider refuses an email from it. If the domain stops passing its check (for example, someone removed a DNS record), emails don't stop: they go out from the shared address, as "Your company via Tally Sign", until it's fixed. Nothing waits and nothing is lost.

![A warning in Sending domain: northbeam.example stopped passing its DNS check, and emails are going out from the shared address](https://www.tallysign.com/university/admin/email-fallback-warning.png)

*A warning shows while emails use the shared address.*

1. Open **Settings → Email** and read the warning under **Sending domain**. Records that can't be found are marked **Not found**.
2. Put those records back at your DNS host, exactly as shown.
3. Choose **Check DNS**. Once it reads **Verified**, emails come from your domain again.

To stop using your domain, choose **Remove** next to it. Emails come from the shared address again. You can add the domain later, and it will need the DNS records and **Check DNS** again.

## Why signing emails land in spam

Signing emails have everything spam filters look at closely: a link to open, often a PDF attached, and a sender the recipient may never have heard from. The usual reasons one lands in spam or quarantine:

- It comes from a shared address instead of your own domain, so the recipient's email provider can't tie it to your company.
- Your domain has no DMARC policy, or its SPF and DKIM records are missing or wrong.
- The recipient's company filters email from outside senders strictly (Microsoft 365 quarantine, Mimecast, Proofpoint and similar tools often hold messages with links for review).
- It's the first email the recipient has had from that address.
- Many emails went out at once to people who weren't expecting them, or earlier ones were marked as spam.

## What to do about it

1. **Verify your own domain** in **Settings → Email**, as above. This helps more than anything else.
2. **Add a DMARC policy** to your domain, or check that it already has one.
3. **Tell the recipient it's coming.** A quick note that a document is on its way from your address helps them find it, and gets them to open it instead of ignoring it.
4. **Ask recipients to allow the address.** They can add it to their contacts or safe senders list. For a company that quarantines outside email, ask their IT team to allow your from address (or your domain) in their email filter.
5. **Check the activity log** on the document to see whether and from which address each email went out (next section).
6. **Share the link directly** if an email still can't be found: open the document and choose **Copy link** next to the recipient, then send it to them yourself.

## Check the activity log

Every document's **Activity**, on its page in Tally Sign, records each email: who it went to, when, and the address it came from.

![Activity: Signing request emailed to Dana Brooks <dana.brooks@brightline.example> from sign@northbeam.example](https://www.tallysign.com/university/admin/email-activity-log.png)

*Each signing request, reminder and completed copy is listed with the address it came from.*

- **Emailed … from sign@yourcompany.com**: it left from your own domain.
- **Emailed … from** the shared address: your domain wasn't verified at that moment, so the email used the shared address.
- **Not emailed**: it didn't go out. Email may not be set up, or our email provider refused the recipient's address. Use **Copy link** to share the link yourself.

> **Note:** "Emailed" means our email provider accepted the email for delivery. Tally Sign can't see into the recipient's inbox, so if they can't find it, ask them to check spam or quarantine, and use the steps above.

Next guide: [Single sign-on](https://www.tallysign.com/support/admin/single-sign-on)

Source: https://www.tallysign.com/support/admin/email-and-deliverability
