twisted1919
Administrator
Staff memberHi everyone,
MailWizz 3.0.7 changes how delivery servers handle DKIM signing and the "Force FROM email" setting. Please take a few minutes to read this before you update.
Background: Force FROM email and sending domains
By default, every delivery server uses Force FROM email = Always. All emails sent through that server use the FROM address set in the delivery server settings, no matter what FROM address the campaign, list or transactional email has. In this setup you don't need sending domains at all. DKIM signing is usually done by your SMTP server or email provider, based on the delivery server's FROM domain, and MailWizz isn't involved.
Sending domains are for a different setup. Your SMTP server or provider accepts emails from several domains, and you (or your customers) want campaigns to go out from those domains. Once you add those domains in MailWizz as verified sending domains, MailWizz can:
3.0.7 makes this setup clearer and more predictable.
1. MailWizz now signs only with the FROM domain
This applies to every "Force FROM email" option.
Before: If a delivery server had a bounce server attached, MailWizz first tried to sign with the bounce server's (return path) domain. It only fell back to the FROM domain if the bounce domain wasn't a verified sending domain.
From 3.0.7: MailWizz signs only with the domain of the FROM address that is actually sent, the one recipients see. If that domain isn't a verified sending domain with signing enabled, MailWizz doesn't sign the email. The bounce server domain is never used for signing anymore.
The reason: DKIM only helps deliverability (DMARC) when the signing domain matches the FROM domain. A signature from the bounce domain usually didn't match.
Who is affected: only people who added their bounce server's domain as a verified sending domain with signing enabled, but not the FROM domain. For example, the bounce address is on
What to do:
Note: the domain must match exactly. If you send from
2. New "Force FROM email" option: "When no verified sending domain"
This is the option to use when you want emails to go out from their own FROM address on verified domains:
Whether the FROM address is replaced depends only on whether the domain is verified. It doesn't depend on the signing settings. Signing still happens separately, when signing is enabled for both the sending domain and the delivery server.
Typical setup:
If you use a web API or Amazon SES delivery server: verifying a domain in MailWizz doesn't verify it with your provider. The domain must also be verified with the provider (Amazon SES, Mailjet, SendGrid, etc.). Otherwise the provider will reject the emails.
Template test emails now follow the same rules: the FROM address you enter when sending a template test is checked the same way as for campaigns.
3. "When no valid signing domain" is deprecated
The old "When no valid signing domain" option is replaced by "When no verified sending domain".
How it decides has changed, though:
Before: The FROM address was kept if MailWizz found any signing domain, and that could be the bounce server's domain.
From 3.0.7: The FROM address is kept only if signing is enabled on the delivery server and the FROM domain is a verified sending domain with signing enabled. Otherwise it's replaced with the delivery server's FROM address.
Who is affected: people using this option who verified the bounce server domain rather than the FROM domains. Until now their emails kept their original FROM address. From 3.0.7 subscribers will see the delivery server's FROM address instead.
What to do: switch these servers to When no verified sending domain and make sure your FROM domains are verified sending domains. The deprecated option will be removed in a future release.
4. Fix: sending domain lookups in long-running processes
We fixed a caching bug in how MailWizz looks up sending domains during long-running processes such as campaign sending and queue processing. The cache didn't take into account which customer was sending or whether signing was required. In rare cases one customer's verified domain could affect another customer's emails in the same process, and a cached result could ignore the signing requirement.
You don't need to do anything for this one.
Quick check before updating to 3.0.7
Force FROM email = Always (default), no sending domains:
Force FROM email = Always, with sending domains:
Force FROM email = When no valid signing domain (deprecated):
Force FROM email = When no verified sending domain:
After updating, if MailWizz signs your emails, send a test email and check the headers for
If you're not sure whether your setup is affected, open a support ticket and we'll help you check.
Thank you!
MailWizz 3.0.7 changes how delivery servers handle DKIM signing and the "Force FROM email" setting. Please take a few minutes to read this before you update.
Short version: if your delivery servers use the default Force FROM email = Always and you don't use Sending domains in MailWizz, nothing changes for you. Your emails go out exactly as before.
Background: Force FROM email and sending domains
By default, every delivery server uses Force FROM email = Always. All emails sent through that server use the FROM address set in the delivery server settings, no matter what FROM address the campaign, list or transactional email has. In this setup you don't need sending domains at all. DKIM signing is usually done by your SMTP server or email provider, based on the delivery server's FROM domain, and MailWizz isn't involved.
Sending domains are for a different setup. Your SMTP server or provider accepts emails from several domains, and you (or your customers) want campaigns to go out from those domains. Once you add those domains in MailWizz as verified sending domains, MailWizz can:
- let emails go out with their own FROM address, without replacing it with the delivery server's FROM address, because the domain is verified;
- sign those emails with DKIM, if signing is enabled for the sending domain and the delivery server.
3.0.7 makes this setup clearer and more predictable.
1. MailWizz now signs only with the FROM domain
This applies to every "Force FROM email" option.
Before: If a delivery server had a bounce server attached, MailWizz first tried to sign with the bounce server's (return path) domain. It only fell back to the FROM domain if the bounce domain wasn't a verified sending domain.
From 3.0.7: MailWizz signs only with the domain of the FROM address that is actually sent, the one recipients see. If that domain isn't a verified sending domain with signing enabled, MailWizz doesn't sign the email. The bounce server domain is never used for signing anymore.
The reason: DKIM only helps deliverability (DMARC) when the signing domain matches the FROM domain. A signature from the bounce domain usually didn't match.
Who is affected: only people who added their bounce server's domain as a verified sending domain with signing enabled, but not the FROM domain. For example, the bounce address is on
bounces.example.com (verified in MailWizz) and emails go out FROM example.com (not added in MailWizz). Until now MailWizz signed those emails with bounces.example.com. From 3.0.7 it won't sign them.What to do:
- If your SMTP server or provider signs the emails itself: you don't need to do anything. MailWizz will simply stop adding a second signature that didn't match your FROM domain anyway.
- If you rely on MailWizz to sign: add the FROM domain under Sending domains, verify it, and enable signing for it. With "Always", that's the domain of the delivery server's FROM email.
Note: the domain must match exactly. If you send from
news.example.com, that is the domain you need to add. Adding example.com doesn't cover its subdomains.2. New "Force FROM email" option: "When no verified sending domain"
This is the option to use when you want emails to go out from their own FROM address on verified domains:
When no verified sending domain: the email keeps its own FROM address if that address's domain is a verified sending domain. Otherwise the FROM address is replaced with the delivery server's FROM address.
Whether the FROM address is replaced depends only on whether the domain is verified. It doesn't depend on the signing settings. Signing still happens separately, when signing is enabled for both the sending domain and the delivery server.
Typical setup:
- Your SMTP server or provider accepts emails from
brand-a.comandbrand-b.com. - You add both as sending domains in MailWizz and verify them.
- You set the delivery server to When no verified sending domain.
- Campaigns FROM
@brand-a.comor@brand-b.comkeep their FROM address and can be DKIM signed by MailWizz. - Campaigns FROM any other domain use the delivery server's FROM address.
If you use a web API or Amazon SES delivery server: verifying a domain in MailWizz doesn't verify it with your provider. The domain must also be verified with the provider (Amazon SES, Mailjet, SendGrid, etc.). Otherwise the provider will reject the emails.
Template test emails now follow the same rules: the FROM address you enter when sending a template test is checked the same way as for campaigns.
3. "When no valid signing domain" is deprecated
The old "When no valid signing domain" option is replaced by "When no verified sending domain".
- If your servers already use it: they keep working, and the option stays in the dropdown marked "(deprecated)".
- If your servers don't use it: it no longer appears in the dropdown.
How it decides has changed, though:
Before: The FROM address was kept if MailWizz found any signing domain, and that could be the bounce server's domain.
From 3.0.7: The FROM address is kept only if signing is enabled on the delivery server and the FROM domain is a verified sending domain with signing enabled. Otherwise it's replaced with the delivery server's FROM address.
Who is affected: people using this option who verified the bounce server domain rather than the FROM domains. Until now their emails kept their original FROM address. From 3.0.7 subscribers will see the delivery server's FROM address instead.
What to do: switch these servers to When no verified sending domain and make sure your FROM domains are verified sending domains. The deprecated option will be removed in a future release.
4. Fix: sending domain lookups in long-running processes
We fixed a caching bug in how MailWizz looks up sending domains during long-running processes such as campaign sending and queue processing. The cache didn't take into account which customer was sending or whether signing was required. In rare cases one customer's verified domain could affect another customer's emails in the same process, and a cached result could ignore the signing requirement.
You don't need to do anything for this one.
Quick check before updating to 3.0.7
Force FROM email = Always (default), no sending domains:
- Nothing to do.
Force FROM email = Always, with sending domains:
- If you want MailWizz to sign, make sure the delivery server's FROM domain is a verified sending domain with signing enabled.
- Don't rely on the bounce server domain for signing anymore.
Force FROM email = When no valid signing domain (deprecated):
- Switch to When no verified sending domain.
- Make sure every FROM domain you send from is a verified sending domain, matched exactly, subdomains included.
Force FROM email = When no verified sending domain:
- Make sure every FROM domain you send from is a verified sending domain, matched exactly, subdomains included.
- For web API or Amazon SES servers, also verify the domains with your provider.
After updating, if MailWizz signs your emails, send a test email and check the headers for
DKIM-Signature (the d= value should match your FROM domain) and dkim=pass / dmarc=pass.If you're not sure whether your setup is affected, open a support ticket and we'll help you check.
Thank you!