AxeneAxene Docs

Domains

Add a domain, publish the DNS records, verify, and hand DNS off to your IT person.

Every mailbox in Workspace lives on a domain you own. Adding a domain generates the DNS records that route mail to Axene and authenticate what you send. This page covers the full lifecycle: adding, verifying, handing off DNS, enabling hosting, and removing.

Domain management requires the owner or admin role. Members can see domains but not change them.

Add a domain

  1. Go to Admin → Domains.
  2. Click Add domain.
  3. Enter the domain name (e.g. acme.co.ke) and confirm.

Workspace generates a DKIM keypair and a unique verification token for the domain, then shows you the five records to publish.

A domain can only be configured on one Workspace organisation. If it is already claimed elsewhere (including a live axene-verify record belonging to another account), adding it fails with a conflict. If you believe a domain is wrongly claimed, contact support.

The DNS records

Workspace asks for five records. Copy the host and value exactly as shown on the domain page; the values below show the shape of each record (acme.co.ke stands in for your domain):

PurposeTypeHostValue
OwnershipTXTacme.co.keaxene-verify=<your token>
Mail exchangerMXacme.co.kemail.axene.io (priority 10)
SPFTXTacme.co.kev=spf1 mx ~all
DKIMTXTaxmail._domainkey.acme.co.kev=DKIM1; k=rsa; p=<your public key>
DMARCTXT_dmarc.acme.co.kev=DMARC1; p=none; rua=mailto:[email protected]

What each one does:

  • Ownership proves you control the domain. The token is unique to your account.
  • MX routes incoming mail for the domain to mail.axene.io. Without it you can send but not receive.
  • SPF lists which servers may send mail for your domain. v=spf1 mx ~all authorises your MX host (Axene). If you already publish an SPF record, keep a single record and make sure it covers mx.
  • DKIM publishes the public half of your signing key at the axmail selector, so receivers can verify your messages were not tampered with.
  • DMARC tells receiving servers what to do when SPF or DKIM fails, and where to send aggregate reports. The default policy p=none is monitoring-only; tighten it once you are confident in your setup.

At most registrars, records on the bare domain are entered with @ as the host. For the DKIM and DMARC records, some providers want only the subdomain part (axmail._domainkey and _dmarc) rather than the full hostname.

Verify the domain

Once the records are published:

  1. Open the domain under Admin → Domains.
  2. Click Recheck DNS.

Workspace checks each record individually and shows a live verified flag per record, so you can see exactly which ones are still propagating. When all five pass, the domain status moves from pending to verified and DKIM signing for outgoing mail is activated.

During onboarding, the wizard runs this same check automatically every 5 seconds while you are on the DNS step, so verification usually happens the moment your records propagate.

DNS propagation can take from minutes up to 48 hours depending on your provider and TTL settings. If one record refuses to verify, recheck the host and value character by character; DKIM values are long and easy to truncate.

If a verified domain breaks later

Workspace keeps rechecking verified domains. If records disappear (for example after a registrar migration), the domain drops to degraded status and mail flow can be affected. Restore the records and click Recheck DNS; the domain returns to verified once everything passes again.

Hand DNS off to your IT person

Often the person setting up Workspace is not the person who controls DNS. Instead of pasting records into email or chat, send a handoff link:

  1. Open the domain under Admin → Domains.
  2. Click Copy handoff link. The link looks like https://workspace.axene.io/handoff/<token> and is copied to your clipboard.
  3. Send it to whoever manages your DNS.

The handoff page is public and needs no Axene account. It shows:

  • Every required record with one-click copy buttons for the host and value.
  • A live progress count of how many records are verified.
  • A Recheck button that runs the real verification, so your IT person can confirm their work on the spot. Once every record shows as live, they can close the page; your domain is verified on your side too.

The page is read-only: nothing on it can change your DNS or your Workspace account. Creating the link, revoking it, and every recheck through it are recorded in the audit log.

To kill a link, click Revoke link on the domain page. The existing URL stops working immediately; clicking Copy handoff link again issues a fresh one.

Enable hosting

Receiving mail on the domain requires hosting to be switched on. The onboarding wizard does this automatically when your domain verifies. If you added the domain from the admin console instead:

  1. Open the verified domain under Admin → Domains.
  2. Click Enable hosting.

The button requires the domain to be verified and the MX record to point at mail.axene.io. Once enabled, the domain shows a Hosting on pill and incoming mail is delivered to its mailboxes.

Diagnostics

The domain detail page includes a diagnostics card with live health probes:

CheckWhat it tells you
MXWhether incoming mail routes to Axene
DKIM keyKey type and strength (RSA bits)
SPF lookupsHow many DNS lookups your SPF record triggers, against the limit of 10 (RFC 7208). Going over the limit breaks SPF for some receivers
MTA-STSWhether the domain publishes an MTA-STS policy

Use this after big DNS changes, or when deliverability looks off.

Remove a domain

Deleting a domain from Admin → Domains removes the domain and everything attached to it: its DNS record entries, all its mailboxes and their mail, aliases, and app passwords. Its DKIM key is retired. This cannot be undone, so export or migrate anything you need first.

What next?

  • Mailboxes - create mailboxes and aliases on your verified domain.
  • Getting started - the guided first-time setup.
  • Admin - audit log, storage, and organisation settings.

On this page