Mastodon

Proton Mail and Route-53 DNS

A step-by-step guide for setting up an AWS Route-53 domain name for use with Proton Mail.

A desperate-looking man, his eyes wide open, sitting at a desk trying to configure Proton Mail. Next to him at the wall, sticky notes about TXT, MX, DNS Record, verification and CNAME.
The correct setup of the DNS records can be tricky.

Having a Proton Unlimited or higher account for Proton Mail means you can set up email based on your own domain name. The procedure involves setting up multiple MX and TXT records in DNS, which can be tricky depending on your domain registration service and the tools they provide. Proton has documented the procedure, but the description isn't specific enough to give you a straightforward recipe.

I have done it several times based on domain names registered with AWS Route 53, and it involved quite some trial-and-error. Below I describe how it's done.

Preliminaries

The following assumes you own an AWS account, have access to the AWS Console (i.e. the admin web interface AWS provides) for that account, and have registered a domain name with Route 53. You can then go to Route 53 > Hosted Zones and click on the domain name you want to configure for email.

Step 1: Verification

Proton needs you to verify that you are in control of the domain and can set up a harmless TXT record before it lets you go further steps.

For this you set up a TXT record with empty subdomain. Let's say your domain is example.com, then you define a TXT record for the pure domain (empty string for subdomain) and the value that Proton asks you to use:

"protonmail-verification=ea91f1b81f6c5d0c099b3ebf331fb673b777ec5e"

(The specific value will be different in your case.)

The configuration screen in AWS looks like this (you might have zoom in to see the details):

Screenshot showing the TXT record configuration in Route 53

Proton suggests using @ as subdomain (host) name, but I found that is not a good idea. Where possible, avoid using the @ host names suggested by Proton. (There is one instance below where you cannot avoid it, and that is ok.)

Step 2: Define an Email Address in Proton

You do this in the Settings > Identity and addresses section of the Proton account information. Define the specific address you'd like to use, such as me@example.com. It won't work yet, but Proton wants you first to define it in Proton and then set the actual DNS redirect to Proton. This is particularly important when you have been using that address with another service before, and you are moving it to Proton. By first defining it in Proton and then setting the DNS record you avoid losing email that gets sent to Proton before Proton knows about the email identity.

Step 3: The MX Record

MX records are the ones that trigger that actual sending of emails to the Proton server. Proton wants you to set two MX records at priority levels 10 and 20, respectively:

10 mail.protonmail.ch
20 mailsec.protonmail.ch

Technically, Route 53 allows you to set both (separated by newline) as a single record, but such a configuration isn't effective. Proton will, after a while, warn you that the setup isn't working, and you will in fact never receive email through Proton this way.

So you have to set up two distinct records, and that is not possible if both have the same (empty) subdomain name. So here you set up the priority-10 one with an empty subdomain, and the priority-20 one with the @ subdomain. That set up works:

Screenshot showing the MX records configuration in Route 53

(You get this by first creating one record and then using the "Add another record" button. Alernatively, you can create them one after the other.)

Step 4: Other TXT Records

Proton requires further TXT records to prevent spoofing and for DMARC.

The anti-spoofing entry you should add as as additional line to the TXT record you created in Step 1 above, rather than create a separate record. (If you also want to send emails under your domain from services other than Proton, you can add further anti-spoofing lines for those services to the record.)

Screenshot showing the SPF configuration in Route 53

For DMARC you add a TXT entry for a subdomain named _dmarc, like this:

Screenshot showing the DMARC TXT configuration in Route 53

Step 5: CNAME entries

Finally, you need three distinct CNAME entries, each for a separate subdomain:

  • protonmail._domainkey
  • protonmail2._domainkey
  • protonmail3._domainkey

Proton will tell you the value for each of them.

Final Check

Proton Mail will show you whether you set up every part correctly. It looks something like this when it's all correct:

Screenshot showing the final configuration check in Proton Mail

The above is for two domains, and has CATCH-ALL configurations which are optional. (They are independent of DNS settings and defined by clicking "Set catch-all" in the Actions menu. The option becomes available once the basic TXT verification step has completed.)

It might take a few minutes before Proton has confirmed all the DNS settings.

Other DNS Records

In case you have any doubts: It's fine to have further DNS records for other services (such as a webserver for the domain--in which case you'll have A and AAAA entries for the blank subdomain name, in addition to the MX and TXT entries).