A signature request from an unfamiliar vendor address asks the recipient to click a link and authenticate. That is identical to a phishing email, and some of your signers will treat it that way.
Sending from your own authenticated domain fixes the recognition problem and gives you control over inbox placement. The setup is DNS work, usually under an hour. The part worth getting right is which records actually matter, because the conventional advice gets this partly wrong.
Key takeaways
DKIM alignment is what makes your domain the authenticated sender. SPF often isn't involved at all.
DMARC inherits to subdomains. SPF and DKIM don't.
A new subdomain starts with no reputation — warm it up rather than switching everything at once.
Signature requests are transactional email. Don't add marketing footers or unsubscribe links.
DMARC enforcement protects your brand from being spoofed, which matters more than deliverability for most firms.
Decide where to send from
Root domain. Simple, inherits your existing reputation immediately, no warm-up. Good for low volume, where a dedicated subdomain would never accumulate enough traffic to build its own reputation.
Dedicated subdomain (sign.yourcompany.com, documents.yourcompany.com). Separates signing traffic from marketing, so a deliverability problem in one stream is partly insulated from the other. Partly, not entirely — receivers do weigh organizational domain reputation, so a badly damaged root domain still affects you.
The tradeoff nobody mentions: a new subdomain has no sending reputation. Mailbox providers treat unknown domains cautiously. For the first few weeks you may see worse placement than the vendor's established pool. If you send a handful of documents a month, a subdomain may never accumulate enough volume to establish reputation at all — root domain sending is the better call.
Root domain | Dedicated subdomain | |
|---|---|---|
Volume | Low to moderate | Moderate to high |
Reputation | Inherited immediately | Built from zero |
Warm-up needed | No | Yes |
Isolation from marketing | None | Partial |
Setup | Lower | Moderate |
Separate subdomains per department (HR, Legal, Sales) only make sense at genuine enterprise volume. Below that you're splitting thin traffic across domains that each need their own reputation.
The DNS records, and which ones matter
This is where most guides go wrong, so take it slowly.
DKIM is the important one. Your platform gives you a public key to publish, usually as a CNAME or TXT record on a selector subdomain. Messages are signed with the matching private key, and the signing domain is yours. For DMARC to pass, the authenticated domain must align with the From address — and with third-party senders, DKIM is almost always what provides that alignment. How DKIM works covers the mechanism.
SPF may not apply to you. Most sending platforms use their own Return-Path, which means SPF authenticates their domain, not yours — so SPF passes but doesn't align with your From address, and contributes nothing to DMARC. Two consequences:
If your platform doesn't ask you to add an
include:, don't add one. SPF permits only ten DNS lookups and unnecessary includes waste them.Some platforms offer a custom Return-Path via CNAME, which gives you SPF alignment too. Useful belt-and-braces, not essential if DKIM aligns.
Ask your platform directly: does your sending require an SPF include, or do you use your own Return-Path? The answer determines whether you touch SPF at all. How SPF works explains the lookup limit.
DMARC ties it together and inherits. A policy at _dmarc.yourcompany.com automatically covers every subdomain unless you override it with the sp= tag. You do not need a separate DMARC record for sign.yourcompany.com. How DMARC works covers the policy options.
Note the asymmetry, because it catches people out: DMARC inherits, SPF and DKIM do not. Records for those go on the sending subdomain itself.
Authentication is now effectively mandatory. Major mailbox providers have moved to requiring SPF, DKIM and DMARC from senders at volume, with spam complaint thresholds attached. Whatever the current specifics, the direction is settled — unauthenticated mail is increasingly filtered regardless of volume. [VERIFY — check current provider requirements before publishing]
Getting DMARC to enforcement
Start at p=none and read the aggregate reports. The goal isn't a fixed waiting period — it's confirming that every legitimate source of mail using your domain passes alignment. That means your signing platform, your mail provider, your CRM, your invoicing tool, your helpdesk, anything else sending as you. Teams routinely discover two or three forgotten senders at this stage.
Move to p=quarantine, watch for a few weeks, then p=reject once you're confident. Going to reject with an unidentified legitimate source silently destroys that mail.
Enforcement is the point. p=none gives you visibility but no protection. At p=reject, nobody can send mail that appears to come from your domain — which matters directly, because attackers impersonating signature requests from known brands is a live attack pattern. See email spoofing explained and how to spot fake signature requests.
Warm up before you switch everything
If you've set up a new subdomain, don't move your full volume on day one.
Send low volume to engaged recipients first — internal staff, existing clients who reliably open your mail. Build over two to four weeks. Positive engagement early establishes reputation faster than volume does.
Watch delivery and complaint rates throughout. If placement degrades, slow down rather than pushing through. Sender reputation covers what providers are measuring.
Configure the sender identity
In your platform's sender settings: verified sending domain, display name matching your company exactly, and a monitored reply-to address.
No-reply addresses are a genuine mistake here. Signers with questions will reply, and if nobody reads it they stall rather than signing. Route replies to a monitored shared mailbox — shared mailboxes covers how to set one up so it isn't one person's problem.
Test to addresses on different providers before going live. Rendering and filtering differ enough between them to be worth checking.
Template design
Short beats elaborate:
Subject line that names document and action. "Please sign: Q3 Vendor Agreement" outperforms "Document ready."
Two sentences. What it is, what they need to do.
One button. Competing links dilute the action and look more like marketing, which filters notice.
Personalised greeting and document title, so it never reads as bulk.
Plain-text fallback link.
Test on mobile. A large share of signing happens on phones.
Don't add marketing elements. Signature requests are transactional — a specific, requested, individual communication. Transactional messages are exempt from CAN-SPAM's unsubscribe and physical address requirements, and adding an unsubscribe footer to a contract request is actively confusing. Transactional versus marketing email covers where the line sits. [LEGAL REVIEW]
Heavy images and multiple tracking links push messages toward promotional classification. Restraint helps placement as well as clarity.
On what moves completion rates once the email arrives, see personalised signing experiences and signature field placement.
Send, track, automate
Monitor delivery, opens and completions. Reminders at 24, 72 and 168 hours are a reasonable default; cap at three, since gains flatten and complaints don't.
Connect to your source systems so requests fire on a deal stage change or an accepted offer. Integrations determines what's possible, and common signing workflows covers the trigger patterns.
For time-sensitive documents, SMS alongside email removes the deliverability variable entirely — see omnichannel signing.
Worth knowing: BIMI
Once you're at DMARC enforcement, BIMI can display your logo beside the message in supporting inboxes. It requires p=quarantine or p=reject, a logo in a specific SVG format, and for some providers a Verified Mark Certificate, which costs money annually.
It's the natural endpoint of branded sending and a reason to reach enforcement rather than stopping at p=none. Treat it as a later step, not part of initial setup.
What branded sending doesn't do
Two honest limits:
It isn't a legal requirement. No e-signature regulation requires branded sending. ESIGN governs consent and record retention; eIDAS governs signature levels. Enforceability comes from the audit trail recording who signed, when and how they were verified — not from your logo. See how audit trails work.
It doesn't guarantee higher completion rates. It removes one source of hesitation. If your documents are long, your fields excessive, or your reminders absent, branding won't fix that. Measure before and after rather than assuming — and if you want to attribute the change properly, run it as a controlled test.
Common mistakes
Adding an SPF include the platform doesn't need. Wasted lookups, no benefit.
Creating per-subdomain DMARC records. It inherits.
Stopping at
p=none. Visibility without protection.Switching all volume to a cold subdomain at once.
A no-reply address.
Marketing footers on transactional mail.
Not testing across providers and on mobile.
Subdomain sending at low volume, where reputation never establishes.
FAQ
Subdomain or main domain?
Main domain for low volume — it inherits existing reputation with no warm-up. Dedicated subdomain once volume justifies it and you want separation from marketing mail.
Which DNS records do I actually need?
DKIM on the sending domain, always. DMARC at the organizational level, which inherits to subdomains. SPF only if your platform requires an include rather than using its own Return-Path — ask them.
How long does verification take?
Records usually propagate within an hour but can take up to 48 depending on TTL. Verify each with a lookup tool before sending externally.
Why does DKIM matter more than SPF here?
Third-party senders typically use their own Return-Path, so SPF authenticates their domain, not yours, and doesn't align with your From address. DKIM signs with your domain and provides the alignment DMARC needs.
Will this improve completion rates?
It removes recognition friction, which usually helps. It won't compensate for a difficult document or missing reminders. Measure your own before and after.
What if a signer marks a request as spam?
One complaint is noise; a pattern damages reputation. Keep reminders capped, make the sender obvious, and don't send to people who aren't expecting a document.
Can I send from multiple brands?
Yes, with separate sender identities. Each domain needs its own DKIM, and DMARC applies per organizational domain.
Does branded sending affect enforceability?
Not materially. Enforceability rests on intent, consent and the audit trail. Branding helps recipients trust the request, which is a different benefit.
Branded sending is an afternoon of DNS work that removes a recurring question from every signature request you send. Get DKIM aligned, reach DMARC enforcement, and warm up before switching volume.
