Cloudflare Automatic DNS Setup
Set up email DNS records automatically for one or all your Cloudflare domains.
Article details
Type, difficulty, plans, and last updated info.
▼
Article details
Type, difficulty, plans, and last updated info.
- Type
- Reference
- Difficulty
- Beginner
- Plans
- Nano · Starter · Pro · Agency
- Last updated
- Sep 9, 2026
TrekMail can help create email DNS records for domains managed by Cloudflare. Both methods show you a confirmation step; DNS verification happens afterwards. Choose the one that fits the domain:
Method 1: Automatic setup (eligible single domains)
When it is available in the DNS & Health tab, this is the quickest route for one Cloudflare-managed domain. It does not need an API token. The button is not offered for every configuration, such as a sending-only domain or a domain whose setup needs a different DKIM selector.
- Go to your domain's DNS & Health tab.
- Click Set up DNS automatically.
- You will be redirected to Cloudflare, where you can review the records.
- Approve the change on Cloudflare.
- Return to TrekMail. It starts a DNS check after the provider flow completes; wait for the status in TrekMail before treating setup as finished.
This uses the Domain Connect protocol. Your domain must use Cloudflare DNS (nameservers).
Method 2: API Token Setup (Single or Bulk)
Use this method to set up many domains at once, or if Domain Connect isn't available for your domain.
How it works
- You create an API token on Cloudflare.
- TrekMail finds the Cloudflare zones that the token can access and shows which ones you can add or connect.
- You review and apply the changes. TrekMail then adds the domains and creates the DNS records automatically.
Step-by-step
Step 1: Connect to Cloudflare
- In TrekMail, go to Domains and click the Cloudflare tab in the "Add a domain" card. You can also go directly to
/app/domains?add=cloudflare. - Click Open Cloudflare to open the token creation page.
- On Cloudflare:
- Click "Create Token".
- Start with the "Edit zone DNS" template, or create a custom token with Zone → DNS → Edit.
- Under Zone Resources, choose the specific zone or zones you want TrekMail to manage. Use All zones only when you intentionally want a broad batch connection.
- Leave unrelated permissions out of the token.
- Click "Continue to summary" → "Create Token".
- Copy the token (you'll only see it once).
- Paste the token back in TrekMail. A green checkmark confirms it's valid.
Step 2: Select domains
TrekMail shows the Cloudflare zones accessible to the token. Review the selection before continuing; deselect any domain you do not want to connect.
- Setup DNS: domain already exists in TrekMail; DNS records will be configured.
- Add + DNS: domain is new; it will be added to TrekMail and DNS will be configured automatically.
Domains not managed by Cloudflare won't appear in this list.
Step 3: Apply DNS records
TrekMail previews the changes for each selected domain:
- Will be added: new DNS record will be created.
- Will be merged: your existing SPF record will be updated to include TrekMail.
- Already set up: no changes needed.
- Will be replaced: an existing record conflicts with what TrekMail needs. Use the Replace / Keep toggle on that record to decide: Replace overwrites the old value with TrekMail's, Keep leaves your record untouched.
Before applying, you can also choose exactly which records to write. Each record has a checkbox, so you can apply only MX and SPF now and come back for DKIM later, or skip a record you already manage elsewhere, anything you uncheck is left alone.
Click Apply DNS to all domains to create the records you selected. TrekMail schedules a DNS check after a successful apply. The check confirms what is publicly visible; it is the final setup status to rely on.
Bulk setup
If you have many domains on Cloudflare, the wizard handles them all at once:
- When creating the API token on Cloudflare, select "All zones" under Zone Resources.
- In Step 2, select the domains you want to include and review them before continuing.
- TrekMail will add new domains and apply DNS records to each domain sequentially.
Plan limits
Your plan's domain limit applies:
- Nano: up to 10 domains total
- Starter: up to 50 domains total
- Pro: up to 100 domains total
- Agency: up to 1,000 domains total
You can connect up to 50 domains per batch. New domains count toward your plan limit.
Security
- Your API token is encrypted at rest and TrekMail does not log the token value.
- The preview is the authority for what TrekMail may create or update. Read it carefully, especially where an existing SPF or conflicting record is involved.
- Disconnecting Cloudflare stops TrekMail from making future DNS changes. It does not undo records that were already written.
Troubleshooting
"This API token is invalid or expired" Create a new token on Cloudflare. Copy it when Cloudflare displays it, then paste it into TrekMail. Keep it private like a password.
"Domain wasn't found in your Cloudflare account" Make sure the domain is added to Cloudflare and shows as "Active" status.
"Doesn't have permission to edit DNS records" Your token needs DNS editing permissions. Create a new token: Permissions → + Add more → Zone → DNS → Edit.
DNS still showing as pending after setup Give the DNS check time to run, then use Verify DNS on the domain's DNS page if needed. DNS caching depends on the record TTL and resolver, so avoid treating a fixed number of minutes or hours as a guarantee. Review the specific missing or conflicting record shown by TrekMail before applying changes again.
For Cloudflare's current record-management steps and API-token permissions, see Cloudflare DNS records and Cloudflare API token permissions.
Related articles
Jump to nearby guides that continue the workflow.