[email protected]) instead of a default system address. This improves deliverability, builds trust with your supporters, and gives you control over your sender identity.
You manage everything from Settings → Email Settings, which is where you add domains, authenticate them, create sender addresses, set up your sender avatar, and monitor email health.
Setting up a custom email domain has two core parts:
- Authenticate your domain so WeGive is authorized to send email on your behalf.
- Create one or more sender addresses at that authenticated domain to send from.
Before You Start
You’ll need admin access to your DNS provider (GoDaddy, Cloudflare, Namecheap, Google Domains, Bluehost, etc.) to add the verification records. If your DNS is managed by a web team or IT, coordinate with them before making changes.Email Suppression Headers
At the top of Email Settings is the Email Suppression Headers toggle. Enabling it adds auto-reply suppression headers to your outbound emails, which prevents automated responses (out-of-office replies, bots, etc.) from email clients. This is an org-wide setting and is independent of any individual domain.Step 1: Add Your Domain
- Go to Settings → Email Settings.
- Click Add Custom Domain (top right).
-
Enter your domain only — not a full email address and not the
www.prefix:- ✅
yourorganization.org - ❌
[email protected] - ❌
www.yourorganization.org
- ✅
- Click Save.
mail.yourorganization.org) if you prefer to keep your sending domain separate from your main domain.
Your domain appears in the Custom Domains list with a status badge. It will show Unauthenticated until the DNS records are verified, and Authenticated once they pass. Use the Verify button and the arrow on the right of each domain card to expand its setup panel.
Step 2: Authenticate Your Domain
Expand the domain and open the Authenticate Domain section. This is where you give WeGive permission to send email on your behalf by adding DNS records at your provider.Required records
These three records are required and must show a Valid status before the domain is considered authenticated:
Copy the Name and Value for each record exactly as shown in WeGive into your DNS provider. The exact values are generated for your specific domain — use the copy icons next to each field.
Optional: Receive replies (MX records)
To let supporters’ replies route back into WeGive so they appear in Platform Messaging, add both MX records. These are optional and only needed for two-way communication:Optional: DMARC record
Adding a DMARC record tells receiving email servers how to handle messages that fail SPF or DKIM checks. It improves email security and helps prevent spoofing:
DMARC is optional for sending, but it becomes required if you want to use a Sender Avatar (BIMI) — see below.
Step 3: Add the Records to Your DNS Provider
Log in to your DNS provider and create each record exactly as shown in WeGive:- Create a new DNS record.
- Set the Type (TXT, CNAME, or MX).
- Copy the Name field exactly as shown in WeGive.
- Copy the Value field exactly as shown in WeGive.
- Save the record.
Tips:
- Some providers append your domain to the Name field automatically — check whether you need to enter only the subdomain portion.
- TTL can be left at the default value.
- Watch for extra spaces when pasting, and check your provider’s handling of trailing periods.
- If you already have an SPF record from another email service, you may need to merge it rather than create a duplicate.
Step 4: Verify Your Domain
- Return to WeGive.
- Click Verify on the domain.
Step 5: Create Your Sender Address
Open the Manage Custom Addresses section under the authenticated domain. Custom addresses can be used as “from” and “reply-to” addresses when you send emails — useful if you want certain outbound emails to appear as coming from a team, or to change how your name appears in email clients.- Click Add Custom Address.
-
Enter:
- Display Name — the name recipients see in their inbox (e.g., “Hope Foundation Support”).
- Handle — the username portion before the
@(e.g.,donate,info,support).
- Click Save.
- The address shows a Verified status once it’s connected. You can edit or delete any address with the icons on its row.
hopefoundation.org and your handle is donate, your sender address will be [email protected].
You can create multiple addresses under one domain — for example donate@, info@, events@, and support@ — for different purposes. When you build an email, you’ll select your custom address from the From dropdown.
Receiving replies: If you want an address to receive replies, make sure you added the optional MX records in Step 2 and that you own a real inbox at that address in your email platform.
Step 6 (Optional): Set Up a Sender Avatar (BIMI)
The Sender Avatar (BIMI) section lets supported email clients display your logo as the sender avatar. BIMI (Brand Indicators for Message Identification) is supported by Gmail, Yahoo, and Apple Mail. DMARC enforcement required: BIMI requires a DMARC policy ofp=quarantine or p=reject on your sending domain. If your current policy is p=none, you can still set up the logo and DNS record now and enforce DMARC later — but the avatar won’t display until enforcement is in place.
Brand Logo (SVG Tiny P/S): Upload your logo as an SVG Tiny Portable/Secure file, 32 KB or smaller. No scripts, animations, or external references are allowed. Use the upload area (or drag and drop).
CMC/VMC Certificate URL: Gmail and Apple Mail require a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC) to display your logo. You procure the certificate externally, host the PEM file, and paste the hosted PEM URL here, then click Save.
Tracking
Email open and click tracking runs through your authenticated domain’s CNAME (tracking) record. You can turn enable it per domain with the Enable Tracking button at the bottom of the domain panel. Once your domain is authenticated and tracking is active, WeGive automatically issues a TLS/SSL certificate for your tracking subdomain so links stay secure. If you use a proxy service like Cloudflare for the tracking CNAME, set the SSL mode to Full (not Flexible) and enable the proxy so links resolve over HTTPS. If tracking links ever appear broken or “insecure,” this SSL configuration is the first thing to check.Removing a Domain
To stop using a domain entirely, expand it and click Remove Domain at the bottom of the panel. This removes the domain and its addresses from WeGive — you can leave or remove the DNS records at your provider afterward.Monitoring Email Health
The left-hand Email Health menu gives you reports for your sending:- Bounces — emails that couldn’t be delivered (invalid address, full inbox, server issues).
- Complaints — recipients who marked your email as spam.
- Unsubscribes — recipients who opted out.
- Whitelist — addresses you’ve manually approved.
Troubleshooting
Same-domain emails failing to arrive, even though your domain is Authenticated
If your domain shows Authenticated and every required DNS record is Valid, but emails sent from your custom domain to a recipient at that same domain aren’t arriving — while sends to other domains (a personal Gmail address, a different organization) go through fine — the cause is usually not a problem with your domain’s authentication or WeGive’s setup. Some email platforms (Google Workspace is a common example) apply their own extra anti-spoofing check to incoming mail when the sender’s address and the recipient’s address share the same domain, but the mail arrives through outside sending infrastructure rather than that platform’s own outbound mail path. This can happen even when your SPF, DKIM, and DMARC records are all fully valid — it’s a separate check the recipient’s mail platform applies on its own, not a sign that something is misconfigured on your end or in WeGive. How to confirm this is what’s happening: the pattern is narrow and specific — only same-domain-to-same-domain sends fail, while sends to any other destination succeed. How to fix it: this requires a change on the recipient side, from whoever manages that mail platform (your own IT/mail admin, if the affected mailbox is on your own domain):- Whitelist your email provider’s sending IP ranges in the mail platform’s spam/anti-spoofing settings, or
- Add a DKIM-pass-based exception for your sending service in the mail platform’s anti-spoofing configuration — this is the more durable fix, since it doesn’t depend on IP ranges staying the same over time.
When to Contact Support
Reach out to [email protected] if records appear correct but verification still fails after 48 hours, if deliverability problems persist despite authentication, or if you need help merging records with an existing email service. Include your domain, screenshots of your DNS records, any error messages, and when the issue started.Setup Checklist
- (Optional) Toggle Email Suppression Headers if you want to suppress auto-replies
- Add your domain in Settings → Email Settings (domain only, no prefix)
- Expand Authenticate Domain to view the DNS records
- Add the SPF (TXT) record to your DNS provider
- Add the DKIM (TXT) record to your DNS provider
- Add the tracking (CNAME) record to your DNS provider
- (Optional) Add both MX records if you want replies to land in Platform Messaging
- (Optional) Add the DMARC (TXT) record for security — required for BIMI
- Wait for DNS propagation, then click Verify until all required records show Valid
- Confirm the domain shows Authenticated
- Create your sender address(es) under Manage Custom Addresses and confirm each shows Verified
- (Optional) Upload your Sender Avatar (BIMI) logo and VMC/CMC certificate URL
- Send a test email to Gmail, Outlook, and Yahoo to confirm deliverability