Suped

Why is my email deliverability low after changing NS records and delegating from SFMC to AWS?

Summary

When you switch your domain's nameservers and delegate from one Email Service Provider (ESP), like Salesforce Marketing Cloud (SFMC), to a new DNS provider, such as Amazon Web Services (AWS), a significant drop in email deliverability is often linked to misconfigured or missing DNS records. While NS (nameserver) delegation confirms the new provider is authoritative for your domain, it doesn't automatically ensure that all necessary email-related records (SPF, DKIM, MX, CNAMEs for tracking) are correctly migrated and resolving. Common issues include 'lacks required authentication' errors, especially for recipients like Yahoo, and messages being blocked due to perceived spam or sender reputation problems.

What email marketers say

Email marketers frequently encounter deliverability challenges when making significant changes to their DNS infrastructure, especially when migrating from a managed ESP environment (like SFMC) to a self-hosted solution (like AWS). The consensus among marketers is that while nameserver changes are a fundamental step, the intricacies of migrating all associated DNS records are often underestimated, leading to unexpected service disruptions and reputation impacts. Issues with email authentication, such as broken DKIM, are commonly cited as immediate causes for deliverability drops.

Marketer view

Email marketer from Email Geeks notes that after changing nameservers from SFMC delegation to an AWS hosted zone, email deliverability plummeted to 8%, seeking advice on self-hosted domains used in SFMC.

02 Jul 2024 - Email Geeks

Marketer view

Email marketer from Email Geeks observes that their emails are primarily blocked due to spam or sender reputation issues, with specific 'lacks required authentication' failures reported by Yahoo.

02 Jul 2024 - Email Geeks

What the experts say

Email deliverability experts agree that changes to nameservers, while seemingly straightforward, are high-impact events that demand meticulous attention to all underlying DNS records. The consensus is that low deliverability rates and authentication failures post-migration are almost always attributable to overlooked or incorrectly transferred records, rather than the new DNS provider itself (especially reputable ones like AWS). Fixing authentication, particularly DKIM, is typically the first and most critical step in troubleshooting.

Expert view

Expert from Email Geeks notes that nameserver changes can have a substantial impact on email delivery performance, often leading to immediate disruptions.

02 Jul 2024 - Email Geeks

Expert view

Expert from Word to the Wise (referencing tools.wordtothewise.com) observes that their DNS tools do not cache records, ensuring real-time data for troubleshooting DNS issues.

02 Jul 2024 - Word to the Wise

What the documentation says

Official documentation from email service providers, DNS hosts, and internet standards (RFCs) consistently emphasize the critical role of accurate DNS configuration for email deliverability. They detail the specific types of records required for proper email authentication (SPF, DKIM, DMARC) and the functionality of branded sending domains. Any delegation or change of nameservers necessitates a complete and precise migration of all these records to the new system, as even minor discrepancies can lead to significant delivery failures and reputation degradation.

Technical article

Documentation from Salesforce Marketing Cloud outlines that a complete Sender Authentication Package requires specific DNS records for email sending, bounce handling, link wrapping, and image hosting, all of which are essential for deliverability.

10 Jan 2024 - Salesforce Marketing Cloud Documentation

Technical article

Documentation from AWS explains that delegating a domain's nameservers to an AWS hosted zone transfers DNS management, requiring all existing records to be re-created in the new zone for continued service.

01 Feb 2024 - AWS Documentation

2 resources

Start improving your email deliverability today

Get started