How can we help?

Send emails from your own domain

Netanel Hugi
Netanel Hugi
  • Updated

By default, Torii emails are sent from hello@toriihq.com. If you verify a sending domain you own, organization emails can be sent from an address on your own domain instead.

For example, an offboarding task or access request can arrive from it@acme.com instead of hello@toriihq.com.

This feature is available on Enterprise plans.

The setup takes five steps: Add your domain → publish two DNS records → verify the domain → choose your sender address → send a test email.

Related: Email Settings and Logo explains how to configure the display name and logo shown on Torii emails. Adding Domains to a Torii Account covers the domains Torii uses to recognize your people. That is separate from the sending domains described in this article.

Before you start

  • Admin access in Torii, since sending domains are configured under Settings.
  • Access to your DNS provider, or someone who can publish DNS records for the domain. Torii will provide two records that must be added before the domain can be verified.

Add a sending domain

  1. Go to Settings > Emails and find Sending domains.
  2. Select Add domain.
  3. Enter the full domain exactly as it appears after the @ in the email addresses you want Torii to send from.
  4. Select Continue.

Which domain should I enter?

Copy everything after the @ in the email address you want to use.

If the address looks like... Enter this Not this
dana@acme.com acme.com dana@acme.com, www.acme.com
dana@mail.acme.com mail.acme.com acme.com
dana@acme.co.uk acme.co.uk acme.com

Enter only the domain. Do not include @, www., or https://.

Each sending domain must be added separately. Verifying acme.com does not automatically verify mail.acme.com or acme.co.uk.

Publish the DNS records

After you add the domain, Torii shows two DNS records. Use the copy buttons and publish both records at your DNS provider exactly as shown.

Important: some DNS providers automatically append your domain to the Host or Name field. Make sure the domain is not added twice.

TXT record: DKIM

  • Host: scph0125._domainkey.acme.com
  • Value: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GN…

DKIM allows receiving mail servers to confirm that a message was authorized by your domain and was not modified in transit.

Your DKIM selector and key are unique to your domain. Always copy the values shown by Torii rather than using the example above.

CNAME record: bounce domain

  • Host: bounce.acme.com
  • Value: sparkpostmail.com

This configures the return path Torii uses for delivery and bounce handling.

Verify the domain

After both DNS records are published, return to Torii and select Verify.

Torii checks the DNS records immediately and shows the result.

DNS changes may take a few hours to propagate. If Torii does not find the records immediately, leave the domain configured and try Verify again later.

You can close the dialog and return to it at any time. The DNS records remain available behind the eye icon next to the domain.

Verification checks are limited to one every 15 seconds. If you try again too quickly, Torii displays:

We just checked this domain. Please wait a moment before checking again.

Once verification succeeds, the domain is marked Verified and can be used as a sending domain.

Choose the address recipients see

Under Settings > Emails, find Send emails from.

Once you have at least one verified domain, the Organization emails row lets you choose the address Torii uses.

From and Reply-To address

Enter the part before the @, such as notifications or it, and select one of your verified domains.

Only verified domains appear in the list.

The local part can contain letters, numbers, and the characters ., _, +, and -, up to 64 characters. Values are saved in lowercase.

The address is saved when you click away from the field. There is no separate Save button.

To return to Torii's default sender, select Reset to hello@toriihq.com.

The configured address is used both as the sender address recipients see and as the Reply-To address. We recommend using a mailbox that someone monitors so replies to access requests, tasks, or other organization emails are not missed.

Display name

The display name is the name shown beside the email address. The default is IT.

Recipients see the display name followed by via Torii, indicating that Torii sent the message on your organization's behalf.

The display name can be configured whether or not you use a verified sending domain.

Send yourself a test email

For any verified domain, select Send yourself a test email from this domain.

The test is sent to the email address associated with your Torii account.

If you have not configured an organization sender address yet, the test is sent from test@yourdomain.com. Once an organization address is configured, the test uses that address instead.

We recommend sending a test before relying on the domain for production emails. Confirm that the sender looks correct and that the message arrives as expected.

If your email client exposes authentication details, such as Gmail's Show original, you can also confirm that authentication passed for your domain.

Which emails use the custom domain?

Torii sends several types of email. You can see the current sender for each type under Settings > Emails.

Row in Settings > Emails Examples Sender
System emails Password resets, invitations, sign-ups Always hello@toriihq.com. System emails are not affected by sending-domain settings.
Organization emails Tasks, offboarding, access requests, reports Your configured organization address when its domain is verified. Otherwise, hello@toriihq.com.
User email sender address Workflow emails configured to originate from a specific user The user's own email address if its domain is verified. Otherwise, Torii uses your organization sender address. If no organization sender is available, Torii uses hello@toriihq.com.

Domain statuses and fallback behavior

Status What it means What to do
Pending The domain was added but setup or verification is not complete. Make sure both DNS records are published, then select Verify.
Verified The DNS records are valid and Torii can use the domain for sending. No action is required.
Failed Torii could not validate the required DNS configuration. Check the DNS records, correct any issues, and select Verify again.

Email delivery is not blocked if your sending domain cannot be used. Torii falls back to another sender address instead.

Organization emails fall back to hello@toriihq.com. Emails sent on behalf of a user first fall back to your configured organization sender address, and then to hello@toriihq.com if no organization sender is available.

Automatic domain checks

Torii re-checks verified sending domains once a day.

If the required DNS records are removed or changed, the domain can no longer be used and Torii falls back to the appropriate sender address until the DNS configuration is restored.

Pending and Failed domains are not verified automatically. After correcting the DNS configuration, open the domain and select Verify again.

If a domain still appears Verified but emails unexpectedly arrive from hello@toriihq.com, contact Torii support.

Troubleshooting

The domain will not add

We could not add acme.com. Please contact support and we will look into it.

The sending domain may already be registered with our email provider or may require additional review.

This cannot be resolved from your DNS settings. Contact Torii support and include the domain name.

A small number of top-level domains may also be unavailable for sending. Support can confirm whether this applies to your domain.

Verification says the DNS records were not found

Verification failed: The DNS records could not be found

Check the following:

  • The DNS changes may still be propagating. Wait a little longer and select Verify again.
  • Your DNS provider may have appended the domain twice. Some providers automatically add your domain to the Host or Name field. For example, pasting scph0125._domainkey.acme.com might result in scph0125._domainkey.acme.com.acme.com.
  • The DKIM value may be incomplete. Re-copy the full value from Torii and make sure your DNS provider saved the entire string.

The records look correct, but the domain still will not verify

Our email provider could not confirm this domain yet. Please try again shortly.

Torii found the DNS records, but our email provider has not confirmed them yet. Wait a few minutes and select Verify again.

If the message continues for several hours and the DNS records have not changed, contact Torii support.

Our email provider will not send from this domain. Please contact support and we will look into it.

This requires assistance from Torii. Contact Torii support and include the domain name.

The domain is Verified, but the email does not arrive

If the sending domain is marked Verified but a test or organization email does not arrive, a common cause is an email security gateway or filtering policy in front of your mailboxes.

Examples include Mimecast, Proofpoint, Barracuda, and similar email security products.

First, check your spam or quarantine folders and ask your email or security administrator to inspect the gateway logs for the message.

Information for your email or security team

Emails sent through a verified sending domain are authenticated using your domain's DKIM configuration and use a return path under bounce.yourdomain.com.

If your gateway requires an allow rule, prefer one of the following:

  • Your domain's DKIM signature. Messages are signed with d=yourdomain.com.
  • The return-path domain. The envelope sender uses bounce.yourdomain.com.
  • The sending host names. Sending servers use host names under sparkpostmail.com.

Do not add Torii's email provider to the SPF record of your main domain. This is not required for this setup because SPF is evaluated against the return path used for delivery.

If your security gateway still blocks the message, ask your administrator for the exact reason recorded in the gateway logs and send that information to Torii support.

Remove a sending domain

To remove a domain, open it under Sending domains and select Remove sending domain.

If your organization sender address uses that domain, the address is cleared and organization emails fall back to hello@toriihq.com.

You can safely remove the DNS records after removing the domain from Torii.

If you add the domain again later, Torii will provide a new DKIM configuration. Publish the new records shown in Torii rather than reusing the previous values.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request