Help Center β€Ί Deliverability β€Ί How to authenticate your domain name on IONOS
πŸ“¨ Deliverability

How to authenticate your domain name on IONOS

πŸ“… Last updated: June 2026
⏱ 4 min read
βœ… All plans

In this guide, you will discover the step-by-step configuration protocols required to successfully authenticate your IONOS custom domain name. Implementing proper cryptographic records is a vital milestone in proving your sending legitimacy to internet service providers and optimizing your ongoing email deliverability rates.

Case 1: Distributing email marketing streams natively via SystemeScale

If you leverage our built-in autoresponder engine to route your newsletter broadcasts, implement this dual-stage process to map your tracking assets.

Step 1: Generate your custom security variables inside SystemeScale

1
Open your Email Configuration panel
Hover over your main profile avatar image in the upper control toolbar and click on Settings. From the left sidebar options panel, choose Emails.
2
Launch the validation wizard
Scroll down to the Domains manager layout module, then click the unique validation link labeled: "Click here to authenticate your domain and display its information in your email header, which will help improve your email delivery rates".
3
Input your naked domain parameter
In the pop-up modal box prompt that triggers open, enter your clean root domain string without including the "www" sub-label prefix (e.g., sio-demo.com) and click Save.
4
Display your unique DNS record targets
Refresh your primary browser page view. Locate your custom domain path row inside the index list and click on its coordinating eye-shaped icon. The system will slide open an overview box displaying three CNAME records and one TXT record (your mandatory DMARC protection token block). Leave this grid open.
πŸ›‘
Mandatory DNS Infrastructure Rules
  • Domain name authentication is mandatory to process email broadcasts through our system servers.
  • Your custom domain must resolve to an active, working website environment. If your target domain path yields a 404 server page error or resolves to a broken, empty parking page layout, receiving mail gateways will systematically block your broadcasts. For instance, your site path must resolve cleanly; otherwise, outbound email sent from addresses like info@sio-demo.com will face immediate server blockades.
  • You cannot authenticate domain signatures from public electronic webmail suppliers (e.g., Gmail, Yahoo Mail, ProtonMail). Only custom, privately owned business domain names can be validated.

The generated security TXT record provides your account with a required cryptographic DMARC policy structure. To read further details on structuring policy behaviors across external setups, visit our distinct walkthrough: How to create a DMARC record.

Step 2: Deploy your records inside your IONOS DNS zone dashboard

Now, you must copy these parameters and input them safely inside your external IONOS account panel.

5
Access your IONOS DNS record manager
Log directly into your central IONOS customer portal account. Select the custom domain asset you are configuring from your portfolio directory dashboard panel, click on the DNS options menu block, and then choose the primary Add a record link action button.
6
Deploy the three individual CNAME records
Choose the structural CNAME option row from your record type selector dropdown listing panel. Complete the entry row fields precisely using your open workspace values:
  • Hostname field: Paste the generated Name string from your workspace. Crucial Rule: Input only the specific sub-prefix host segment that appears before your root domain block (e.g., if the workspace row outputs si942517.sio-demo.com, strip away your root domain string and fill in only si942517).
  • Value or Points to field: Paste the full matching target string provided by our interface, and append a trailing period (.) directly to the absolute end of the target string value (e.g., inbound.systeme.io.).
Select the Save button to commit the row entry to the zone layer. Repeat this exact mapping process for all three individual generated CNAME nodes.
7
Deploy your mandatory DMARC TXT record row
Initialize another new row addition inside IONOS, setting the structural type selector dropdown choice strictly to TXT. Map the values precisely as follows:
  • Hostname: _dmarc
  • Value (Points to): v=DMARC1; p=none; rua=mailto:yourreportingaddress@domain.com
Click Save to validate and activate your custom security policy.

Step 3: Track network propagation data nodes

Once your four structural record node rows are fully committed to IONOS, verify that your namespace edits are cleanly broadcasting across the public network layer.

Open a public technical lookup tool like DNS Checker. Enter your full prefix string combined with your root domain into the lookup query search engine (e.g., si942517.sio-demo.com) and check for CNAME results. If the engine displays a green confirmation checkmark next to your record destinations, propagation is processing successfully.

Similarly, scan your root domain via an external DMARC Checker tool to verify that your protection text record is fully readable. Once these entries show active across the network, you must contact our support staff to clear internal system lookup caches on our end.

⚑
Final Mandatory Sender Address Confirmation Requirement
To initialize outgoing delivery operations from your validated custom domain asset, you must complete the sender address identity step. Review our dedicated guide layout: How to confirm your email sender address.

Case 2: You are deploying an external custom SendGrid account engine connection

If you choose to route your outbound transactional emails using an independent, external SendGrid API account bridge connection rather than leveraging our built-in system autoresponder server pools, we recommend reaching out directly to SendGrid's technical support specialists or analyzing documentation inside your SendGrid panel for their custom IONOS domain configuration steps.

Was this article helpful?