# Point your domain to Office Niaga Mail (MX, SPF, DKIM)

> The MX, SPF and sending (DKIM) records your domain needs for Office Niaga Mail, with steps for cPanel and Cloudflare, plus optional DMARC.
>
> Source: https://docs.officeniaga.com/mx-records/

To use your domain with Office Niaga Mail, set **one MX record** on your domain (host `@`) to `pmg.webimpian.net` with priority **10**, and delete every other MX record. Add **one SPF record**: a TXT record on `@` with the value `v=spf1 a mx include:spf.mailniaga.mx ~all`. Then add the **two CNAME records** for sending that Office Niaga sends you.

`pmg.webimpian.net` is our mail gateway. It filters spam and viruses, then passes your email to your Office Niaga Mail mailbox. We add your domain to the gateway and to our sending service for you when your account is set up, so there is nothing to do on our side.

> **Changing the MX record moves your email**
> Once the MX record points to Office Niaga Mail, **all new email goes to Office Niaga Mail**, and your old email host stops receiving it. [Create every mailbox](/add-mailbox/) first, so no email bounces.

## Before you start

A few things save you time before you touch any DNS records.

- **Find where your DNS is managed.** This is usually one of these: your domain registrar (for example Exabytes or another MYNIC reseller), Cloudflare, or the **Zone Editor** in your website's cPanel hosting. If you are not sure, WhatsApp us and we will check for you.
- **Create your mailboxes first.** Every address that receives email today, such as `admin@yourcompany.com.my` or `sales@yourcompany.com.my`, should exist in Office Niaga Mail before you change the MX record.
- **Have your two CNAME values ready.** Office Niaga sends them to you for your domain. If you do not have them yet, WhatsApp us.

## The records

These are all the DNS records for Office Niaga Mail. Replace `yourcompany.com.my` with your own domain, and `<number>` with the numbers Office Niaga sends you.

| Type | Host / Name | Value | Priority | Required? |
| --- | --- | --- | --- | --- |
| MX | `@` (or `yourcompany.com.my`) | `pmg.webimpian.net` | **10** | Yes. Delete all other MX records. |
| TXT | `@` (or `yourcompany.com.my`) | `v=spf1 a mx include:spf.mailniaga.mx ~all` | - | Yes. Only one SPF record per domain. |
| CNAME | `em<number>` (given by Office Niaga for your domain) | `return.smtp2go.net` | - | Yes, for sending |
| CNAME | `s<number>._domainkey` (given by Office Niaga for your domain) | `dkim.smtp2go.net` | - | Yes, for sending |
| TXT | `_dmarc` | `v=DMARC1; p=none;` | - | Optional |

The MX and SPF records bring email in. The two CNAME records are for email you send: they let our sending service prove your emails really come from your domain. The `em<number>` record is the return address for sent mail, so SPF checks pass, and the `s<number>._domainkey` record is your DKIM signature. The numbers are unique to your domain. Without these two records, your outgoing email is refused with "sender domain not verified" or lands in spam.

> **Already sending through another service?**
> If your website or another tool also sends email for your domain, such as a contact form mailer, do **not** add a second SPF record. Add that service's `include:` to the same record instead, for example `v=spf1 a mx include:spf.mailniaga.mx include:<other service> ~all`. Copy the exact `include:` value from that service's own setup guide.

Your webmail and email apps do not use these records. They still connect to `mail.officeniaga.com`, as shown in [Email server settings](/server-settings/). Outgoing mail uses port **465** with SSL/TLS (port 587 is closed).

## Steps in cPanel Zone Editor

Most of our customers manage DNS in the cPanel of their website hosting. Follow these steps in order.

1. Log in to cPanel and go to **Domains** → **Zone Editor**.
2. Next to your domain, select **Manage**.
3. Filter by **MX**. Delete every existing MX record, or edit one of them, so that only one remains: **Priority** `10`, **Destination** `pmg.webimpian.net`.
4. Filter by **TXT**. Find the record that starts with `v=spf1`. Edit it so it reads `v=spf1 a mx include:spf.mailniaga.mx ~all`, keeping any `include:` for other services you still use. If there is no SPF record, select **Add Record**, choose **TXT**, set the name to your domain and paste the value.
5. Select **Add Record** and choose **CNAME**. Set **Name** to `em<number>` and **Record** to `return.smtp2go.net`.
6. Add another **CNAME**. Set **Name** to `s<number>._domainkey` and **Record** to `dkim.smtp2go.net`.
7. Select **Save Record** after each change. cPanel adds your domain to the end of each name automatically.
8. Go to **Email** → **Email Routing**. Choose your domain, select **Remote Mail Exchanger** and select **Change**.

> **Do not skip Email Routing**
> If **Email Routing** stays on **Local Mail Exchanger**, the cPanel server still thinks it handles your email. Anything sent from your website, such as contact form messages, then stays on the old hosting and never reaches Office Niaga Mail.

## Steps in Cloudflare DNS

If your domain uses Cloudflare, make the changes in the Cloudflare dashboard. Your registrar's DNS page is not used while Cloudflare is active.

1. Log in to Cloudflare and select your domain.
2. Go to **DNS** → **Records**.
3. Delete every existing **MX** record. Then select **Add record** and choose **Type** `MX`, **Name** `@`, **Mail server** `pmg.webimpian.net`, **Priority** `10`. Select **Save**.
4. Find the **TXT** record whose content starts with `v=spf1`. Select **Edit** and set it to `v=spf1 a mx include:spf.mailniaga.mx ~all`, keeping any `include:` for other services you still use. If there is none, add a new **TXT** record with **Name** `@` and that content.
5. Select **Add record**, choose **Type** `CNAME`, **Name** `em<number>`, **Target** `return.smtp2go.net`. Turn **Proxy status** off so it shows **DNS only** (grey cloud). Select **Save**.
6. Add another **CNAME** with **Name** `s<number>._domainkey` and **Target** `dkim.smtp2go.net`, also **DNS only** (grey cloud). Select **Save**.

> **Both CNAME records must be DNS only**
> Cloudflare turns on the proxy (orange cloud) for new CNAME records by default. A proxied CNAME breaks DKIM and the sending check, so your email fails or lands in spam. Make sure both show **DNS only** (grey cloud).

MX and TXT records are never proxied in Cloudflare, so they have no cloud icon to change.

## Optional: DMARC

DKIM is already covered by the `s<number>._domainkey` record above, so there is nothing more to add for it.

**DMARC** tells other mail servers what to do with email that fails SPF or DKIM. It is optional. A safe start is a TXT record with **Name** `_dmarc` and value `v=DMARC1; p=none;`. It only reports and does not block any email.

## Check it works

DNS changes take effect after the old record's TTL runs out. That is often 1 to 4 hours, but some DNS hosts take up to 24 to 48 hours. Your email can arrive at the old host during that time.

When the time has passed, run these checks.

1. Enter your domain in Google's [Check MX tool](https://toolbox.googleapps.com/apps/checkmx/). It should show one MX record, `pmg.webimpian.net`, and find your SPF record.
2. Send an email from a Gmail or Outlook.com address to one of your mailboxes, then [log in to webmail](/log-in/) and check it arrived.
3. Reply to that email and check that the reply lands in the Gmail or Outlook.com inbox, not in spam and not bounced.

## Still stuck

WhatsApp our support team at [+60 16-916 3324](https://wa.me/60169163324). Send us your domain name and we will check your records.

## Common issues

### I can send email but I do not receive any.

Your MX record most likely still points to your old email host, so new email is delivered there instead of to Office Niaga Mail. Check it with Google's Check MX tool (https://toolbox.googleapps.com/apps/checkmx/). There should be one MX record only: pmg.webimpian.net with priority 10. Delete every other MX record. If your website is on cPanel hosting, also set Email Routing to Remote Mail Exchanger (see Steps in cPanel Zone Editor).

### My emails go to spam, or bounce with 'sender domain not verified'.

The two sending CNAME records (em<number> and s<number>._domainkey) are missing or wrong. Without them, our sending service cannot prove your email comes from your domain, so it refuses to send it or the recipient treats it as spam. Check that both are added exactly as we sent them, and that they are DNS only if you use Cloudflare. If you are not sure, WhatsApp us at +60 16-916 3324 (https://wa.me/60169163324) and we will check.

### I have two SPF records. Which one do I delete?

Merge them into one. Keep a single TXT record that starts with v=spf1, put every include: from both records into it, and delete the other one. For example: v=spf1 a mx include:spf.mailniaga.mx include:<other service> ~all.

### Will changing the MX record affect my website?

No. The MX record only controls where email for your domain is delivered. Your website uses different records (A or CNAME), so it keeps working.

### Do I need to set anything up on Office Niaga's side?

No. We add your domain to our mail gateway and our sending service, and send you the two CNAME values.
