Authenticating a sending domain puts your own address on your survey emails, and it gives receiving mail servers a way to confirm the mail is genuinely yours. Setup is three CNAME records at your DNS provider and one click in Simplesat. Surveys still send without it, from [email protected].
How it works
Until you authenticate a domain, your survey email goes out from [email protected] with your company name as the sender name.
You add your domain in Simplesat, publish the three CNAME records it generates at your DNS provider, and click Validate DNS Records. From then on you can pick your own domain as the From address on any email survey. There's nothing else to configure, and nothing to request from us before you start.
Authenticating helps your mail reach the inbox, but it can't guarantee where a message lands, because the receiving side still applies its own filtering even to mail that passes every check.
Note: adding, validating and deleting sending domains needs the Owner or an Admin. Other roles can open Email authentication and read the records, and that's enough to hand them to whoever runs your DNS.
Authenticate your sending domain
Open Admin → Email authentication.
Click New domain.
Type your root domain, for example
yourcompany.com, and click Add domain. Use the root domain, notwww.Click the domain in the list to open its DNS records panel. You'll see three CNAME records, each with a Name and a Value. Two are named
sim._domainkeyandsim2._domainkey, and the third starts withemfollowed by digits.Add all three records at your DNS provider, copying each Name and Value exactly.
Come back to Simplesat and click Validate DNS Records.
The domain's status changes to Validated, and it's ready to use as a From address.
DNS changes usually resolve within a few minutes, though some providers take about an hour and a few take several hours. If the first validation fails, it's worth retrying later the same day.
Heads up: if this domain is already authenticated with SendGrid for another service, the record names Simplesat generates collide with the ones already there and validation never passes. Contact us for custom record names before you add anything to your DNS.
Where to add the records
Your DNS records live wherever your domain is registered or hosted, somewhere like GoDaddy, Cloudflare, Namecheap or AWS Route 53. Simplesat doesn't have a DNS dashboard of its own.
The steps are the same everywhere and only the labels differ: create a record, set its type to CNAME, and paste in the name and the value. In Route 53:
Open Route 53 → Hosted zones and select the zone for your domain.
Click Create record.
Paste the Name from Simplesat into Record name, set Record type to
CNAME, and paste the Value into the value box.Click Create records, and repeat for the other two.
Some control panels append your domain to whatever you type in the name field, which turns sim._domainkey.yourcompany.com into sim._domainkey.yourcompany.com.yourcompany.com. In those panels, enter only the part before your domain.
A name can hold one CNAME and no more, so if something already answers at that exact name, you'll need to remove it before the new record will take.
Domains already authenticated with SendGrid
Simplesat sends through SendGrid, and so do plenty of other tools. If your domain is already authenticated with SendGrid for another service, the default record names Simplesat generates land on names your zone is already using, and validation never passes.
A different set of record names clears it:
Contact us with the domain you want to authenticate, and mention that it's already set up with SendGrid.
We'll generate custom record names for that domain and send them to you.
Add those records at your DNS provider and click Validate DNS Records.
Send surveys from your authenticated domain
Once a domain is validated, any email survey can send from it, and each survey picks its own sender. Open the survey, go to the Publish tab, and use the email settings:
From is the sender name your recipients see.
Email is the sending address, split into two controls: a text box for the part before the
@, and a dropdown for the domain after it. Validated domains sit at the top of that dropdown, and they're the only ones you can pick.Subject and Design template control the rest of the message.
Click Send test email to see the result in your own inbox, where the From line shows exactly what the survey will send from.
Duplicating a survey resets its email settings to the defaults, so the copy sends from [email protected] with the subject How are we doing? until you set the sender, subject, intro and outro again on the new survey's Publish tab.
Heads up: if you save a sender address on a domain that isn't validated, the save is rejected with the message The domain "yourcompany.com" is not verified yet. and nothing is saved. Validate the domain first, then set up the email.
Check what happened to an email you sent
Open the survey and click Email activity, the tab beside Overview on its results page. Surveys that Simplesat emails out have this tab, and embedded surveys don't. Each row is one message to one customer, showing which email it was (Initial, or one of the follow-ups) and when it was sent, opened and clicked.
The Status column is an icon, so hover it to read the status in words.
Icon | Meaning |
Green check | Delivered. The recipient's mail server accepted the message. |
Red ✕ | Bounced, or reported as spam. |
Orange triangle | The recipient unsubscribed. |
No icon | Still pending, failed to send, or held back because the address is on the suppression list. |
Delivered is the last thing we can see. What the recipient's mail server does with the message after that doesn't show up anywhere in Simplesat.
Click Export email activities for the same data as a CSV. It arrives by email, and at busy times that takes a few hours.
If your response rate drops, this is where to start. Confirm the sends went out, confirm the follow-ups went with them, then check the statuses of the customers who say they saw nothing.
When one person stops receiving Simplesat email
When a recipient's mail server rejects a message, that address goes on a suppression list automatically and we stop sending to it. Everything stops: survey invitations, response notifications, weekly summaries, scheduled reports, export emails and user invitations.
Suppression applies per address, not per domain.
These signs together point at suppression:
Your own mail logs, whether that's a Microsoft 365 message trace, Proofpoint or Mimecast, show the message never reaching your mail system.
Other people on the same domain still receive Simplesat email.
The address stopped receiving everything on one specific date, not one kind of message.
Send us the affected addresses and we'll clear them from the list.
Whether clearing an address holds depends on the rejection your mail server returned:
Rejection | What it means |
| A temporary state on the receiving side. The mailbox is usually fine by the time you notice, and clearing the address is enough. |
| The address is invalid or the mailbox cannot receive mail. It'll bounce again unless the mailbox itself is fixed. |
Heads up: a cleared address goes back on the list the next time it bounces. If the same person keeps disappearing, fix the mailbox or the mail-flow rule that's rejecting us.
What to allowlist
Simplesat sends from two domains, one for surveys and one for everything the app itself sends. An allowlist that covers only one of them still loses half your email, so give your mail administrator all of it:
What | Value |
Survey emails, before you authenticate a domain | |
Survey emails, after you authenticate a domain | the address on your Publish tab, plus your validated domain |
Notifications, invitations, exports and reports | |
Reply-to on those emails | |
Sending IP addresses |
|
Return path on survey emails |
|
Link and unsubscribe tracking host |
|
Allowlisting us does nothing for an address that's already suppressed, because no message goes out to it in the first place.
Ask us about a specific send and we'll tell you what our provider recorded, including any bounce and the exact reason your server returned.
Surveys that land in spam
If your domain is validated and your mail still lands in junk, the filtering is happening on the receiving side. Microsoft 365 and Outlook tenant policies, Proofpoint and Mimecast all divert mail that passes SPF, DKIM and DMARC, and you can't see or change any of that from Simplesat.
Send the same survey to an address on an unrelated provider, a personal Gmail account for example. If it arrives there and not at your recipient's tenant, the filtering is happening in that tenant, and their mail administrator can release it.
To find a survey your recipient believes never arrived, search their quarantine for the sender address the survey uses and for its subject line. On a survey nobody has customized, that's [email protected] and How are we doing?
Recipients on Gmail and Outlook may see a via simplesat-mail.com note beside the sender name. That shows up when the From domain and the infrastructure that sent the mail differ, and authenticating your own domain is what removes it. Changing the From address to a live mailbox on a domain you haven't authenticated leaves the note in place and doesn't help with filtering.
Troubleshooting
The records are added and the domain still shows Failed
Work through these in order:
Look the record up publicly, with
dig CNAME sim._domainkey.yourcompany.comor any online DNS lookup, using the exact name from Simplesat. If the lookup returns nothing, the record isn't published yet and nothing else matters.Compare the name and the value character for character against the DNS records panel. Watch for a trailing copy of your own domain on the end of the name.
Confirm the domain you added is the root domain and not the
wwwversion.Check whether the domain is already authenticated with SendGrid for another service.
Give DNS a few more hours if the records went in recently.
If all of those check out and the status is still Failed, send us the domain name and we'll look at it from our side.
An external DNS checker says the records are correct
An external checker only confirms that something answers at that name, and it can't tell whether what answers is the record Simplesat is looking for. When a checker passes and Simplesat fails, check whether the domain is already authenticated with SendGrid for another service.
The domain has never left Pending
Pending means the domain has been added and nobody's run a validation yet. Open the domain and click Validate DNS Records. The status changes to Validated, or to Failed with the reason for each record that didn't pass.
Old or failed domains are cluttering the list
Open the domain, click the ⋮ menu at the top of its DNS records panel, and choose Delete. If a survey still sends from that domain, deleting it returns the survey to the default Simplesat sender, so check your surveys' email settings first.
Survey email settings went back to how they were
Saving a sender address on an unvalidated domain is rejected outright, with the domain named in the error, and nothing else you changed on that screen is saved either. Validate the domain, then set the sender, intro, outro and template together.
An export or a report never arrived
Exports and scheduled reports are emailed to you, so they sit behind the same suppression list as everything else. If the app says the export was sent, nothing arrived, and Simplesat email has stopped reaching you generally, contact us with your address and we'll check whether it's suppressed.
Email activity shows the message went out and the customer has nothing
Read the Status icon, not the Sent date. A green check puts the message inside the recipient's mail system, which makes their filtering the next thing to check. An empty status means it was suppressed, failed or is still pending, and that one's ours to look at.
FAQ
Do I have to authenticate a domain before I can send surveys?
No. Surveys send from [email protected] with no setup at all. Authenticating puts your own address on them and helps them reach the inbox.
Is there a limit on how many domains I can validate?
No. Sending domains aren't capped by plan, license or count.
Where are the DKIM and DMARC settings?
The three CNAME records handle DKIM signing for you, so there's nothing separate to configure. They also satisfy SPF, and those two are what a DMARC policy checks, so a domain validated in Simplesat passes a DMARC policy of your own.
Do I need to add an SPF record?
Not normally. The records Simplesat generates cover SPF for the mail we send, and an SPF record your domain already publishes stays as it is.
Can I use my own record names instead of the defaults?
Yes, on a domain that's already authenticated with SendGrid for another service. Contact us with the domain and we'll generate custom names for it.
Does Simplesat support canary records?
No. The three CNAME records are the whole set, with an optional SPF record if your policy needs one.
Can someone confirm on your side that our records came through?
Yes. Send us the domain name and we'll tell you what our provider sees for each of the three records.
Can you trace where our message went inside our mail system?
No. Once your mail server accepts a message, what happens to it is visible only in your own logs. What we can give you is the send itself, any bounce, and the exact reason your server returned.