When customers receive invoices from your store, they expect the emails to come from your business email address.
If your domain is not authenticated, email providers may treat those messages as less trusted, which can affect email deliverability.
Sufio is an invoicing app for Shopify stores that sends invoice emails and related documents on behalf of your store. To help these emails appear as trusted messages from your business, your sending domain needs to be authenticated and aligned with your DMARC policy.
When you first set up your account, invoices are sent to your customers from an email address in the your-shop-name@sufioemail.com format.
This lets your customers receive invoice emails before your domain is authenticated.
They can still reply to these emails, and their replies will be sent to the sender email address set up in your Sufio account.
The following steps will walk you through the setup process:
To authenticate your email domain, you need to add Sufio’s DNS records to your domain.
After you add the DNS records to your domain, Sufio checks whether they have been set up correctly.
Once the records are authenticated, Sufio can start sending emails on behalf of your domain.
To generate DNS records for your email domain:
- In your Sufio account, go to the Settings → Emails page.
- In the Sender email section, click Set up DNS records.

Note
Within your domain (for example, acmeshop.com), Sufio uses its own subdomain, such as invoices-txhq.acmeshop.com, for the DNS records used to authenticate your domain.
This helps protect the reputation of your primary domain, especially when sending a high volume of emails.
Sufio uses DKIM and SPF records to verify that emails sent from your domain are authorized and trusted by receiving mail servers.
DomainKeys Identified Mail (DKIM) helps email providers check that an email was sent by an authorized sender and was not changed during delivery.
When an email sent by Sufio from your domain reaches a recipient, their email provider verifies that it was signed with a valid Sufio DKIM key.
To set up DKIM records for your custom mailing domain:
- Open the list of DNS records for your email domain.
- In the Required records section in your Sufio account, navigate to the CNAME configuration snippets.

- In your domain provider’s management console, go to the DNS record settings, also called domain settings, and locate the option to create or edit records.
- Create a new CNAME record.
- In the Name and Value fields, copy and paste the values from your Sufio account.
- Repeat the previous step for the second CNAME record from the list of DNS records.
- Save your changes.
Sender Policy Framework (SPF) is a TXT record added to the Domain Name System (DNS). It lists the servers authorized to use your domain name to send emails.
To set up an SPF record:
- Open the list of DNS records for your email domain.
- In the Required records section in your Sufio account, navigate to the TXT configuration snippet.
- In your domain provider management console, go to the DNS record settings, also called domain settings, and locate the option to create or edit records.
- Create a new TXT record.
- In the Name and Value fields, copy and paste the values from your Sufio account.
- Save your changes.
Caution
Before adding DNS records, keep the following in mind:
You can only authenticate domains that you own. Domains provided by email services, such as gmail.com or yahoo.com, cannot be authenticated.
Some domain providers automatically add your root domain to the hostname you enter in the DNS settings. If your provider does this, enter only the subdomain in the hostname field.
For example, enter invoices instead of invoices.acmeshop.com. Otherwise, the record may be created incorrectly, such as invoices.acmeshop.com.acmeshop.com.
These MX records are not required for Sufio to send emails on your behalf. However, they help improve email deliverability tracking.
When they are set up correctly, Sufio can track whether invoice emails have been successfully delivered to your customers.
Mail Exchange (MX) records specify which mail servers should receive emails sent to addresses on your domain.
When a customer receives an email from Sufio, their server sends back a confirmation that the email was received. The MX record ensures that this confirmation is sent back to Sufio.
To set up an MX record:
- Open the list of DNS records for your email domain.
- In the Recommended records section in your Sufio account, navigate to the MX configuration snippets.

- In your domain provider management console, create a new MX record.
- In the Name and Value fields, copy and paste the values from your Sufio account.
- Repeat the previous step with the second set of values.
- Save your changes.
Note
Sufio uses a dedicated subdomain to send document emails.
These MX records are used only to track the deliverability of emails sent by Sufio and do not affect any other emails sent from your domain.
A DMARC policy record helps email providers authenticate messages that claim to come from your domain. This improves email security and helps protect your domain from unauthorized use.
If your domain doesn’t have a DMARC policy record yet, Sufio displays an example record in the popup.
The provided record includes only the minimum requirements, but you can also set up a stricter DMARC policy to enforce higher security standards.
To set up a DMARC record:
- Open the list of DNS records for your email domain.
- Navigate to the DMARC policy record configuration snippet.

- In your domain provider management console, create a new TXT record, and in the Name and Value fields, copy and paste the values from your Sufio account.
- Save your changes.
After you add the DNS records to your domain management console, make sure each record has the correct type, then authenticate them in Sufio.
To authenticate DNS records in Sufio:
- In your Sufio account, go to the Settings → Emails page.
- In the Sender email section, click Set up DNS records.
- At the bottom of the popup window, click Authenticate domain.
Sufio automatically verifies that your email domain is set up correctly. Once the records are authenticated, Sufio starts sending emails on behalf of your email domain.

Please note that it may take up to 48 hours for changes to your DNS records to be applied.
Plan-specific feature
Email domain authentication is available on the Growth plan and higher.
