Skip to content
OwnSMTP

Email identity

Domains and deliverability

Understand sender authorization, authentication records, and what SMTP acceptance means.

Domain authorization

OwnSMTP does not independently prove that you own a domain. ALLOWED_FROM_DOMAINS is only a local allowlist that constrains request-level visible sender addresses. Your SMTP provider must still authorize every identity you use.

Some providers let an authenticated account send from any local part under a verified domain. Others require every address to exist as a mailbox or alias. Follow the rules of your configured provider.

SPF, DKIM, and DMARC

  • SPF publishes which systems may send for a domain used in the SMTP envelope.
  • DKIM adds a cryptographic signature that receiving systems can validate against DNS.
  • DMARC sets policy and reporting based on alignment between the visible From domain and authenticated SPF or DKIM domains.

Configure these records according to your SMTP provider. OwnSMTP cannot repair missing DNS authentication or create provider signing keys.

Envelope sender and visible From

SMTP_FROM_EMAIL is the envelope sender used during SMTP submission and is typically where delivery-status notifications are directed. The request-level from_email controls the visible From header. DMARC alignment and provider policy may require their domains to align.

Bounces and delivery

SMTP acceptance is only one stage. The receiving system may reject or bounce a message later, place it in spam, quarantine it, or accept it without showing it in the primary inbox. OwnSMTP does not operate a bounce-processing pipeline; monitor the mailbox or tooling associated with your envelope sender and provider.

Why arbitrary spoofing does not work

A local allowlist cannot grant authority over someone else’s domain. SMTP-provider identity checks, SPF, DKIM, DMARC, and recipient filtering all constrain legitimate sending. Configure only domains you control and that your provider authorizes.