How I Got an Email at My Own Domain, for Free
Sending mail from your own domain is really two separate jobs, not one. A forwarding trick and one Gmail setting got me dmb@futari.live, no mailbox rented.
By Dumebi ·
Start with a letter and a mailbox
Imagine you want to receive letters from your friend. The world's answer is beautifully old, and you already probably know this You have a physical address right, and at that address there is a mailbox. Your friend writes your address on an envelope, drops it in a post box, and a chain of sorting offices carries it to the one box that belongs to you. Your address is how you're found. The mailbox is where things land.
Now imagine you also want to send letters. You write a return address in the corner, drop the envelope in a post box, and the postal system carries it onward. Here's the quiet thing almost nobody notices which is that nothing stops you from writing any return address you like. You could write the King's address (or Tinubu's if you want to moonlight as a president) if you want. The post office doesn't check. It just moves the envelope.
Hold onto both of those ideas: receiving is about a mailbox, sending is about a return address, and they are two different jobs. This is important because email is exactly this, and the whole reason getting dmb@futari.live took three tools instead of one is that I had to solve both jobs separately.
What a custom email address actually is
I already own a domain name: futari.live. A domain is just a name the internet agrees points at things I control (maybe more on domains in another article 🤔), and my website lives at dmb.futari.live. Owning the name is like owning a plot of land with a street address on it. And once you own an address, you're allowed to hang a mailbox on it. dmb@futari.live is simply that: a named mailbox at an address I already own.
The thing that trips everyone up is assuming that "having the address" means that the mail will arrive and that mail can leave. It actually doesn't at all. An address on a plot of land is just a label. Someone still has to actually carry letters to it, and someone still has to accept your outgoing letters and vouch that they're really from that address. Those "someones" are what I had to arrange. I hope at this point you are not confused.
So, the goal splits cleanly in two jobs:
Receiving: when someone emails
dmb@futari.live, it should land somewhere I already read.Sending: when I reply, it should go out as
dmb@futari.live, and most importantly the world should believe it is fromdmb@futari.live.
Let me take them one at a time, because they're solved by completely different means.
Job one: receiving, or the magic of mail redirect
I did not want a whole new inbox to check. I already live in Gmail. What I wanted was for a letter addressed to the new mailbox to be quietly walked over and dropped into my existing one.
We started with the postal world as an analogy, and building on that they already actually have this as a service: mail redirect. When you move houses, you tell the post office, and for a while every letter to the old address is automatically re-routed to the new one. You don't keep visiting the old house. The letters just follow you.
Email's version is called forwarding, and it is free! Because I registered my domain at Namecheap, Namecheap runs the little sorting office for my address, and it will happily accept a rule that reads: anything addressed to dmb, carry it onward to my Gmail. I add that one rule, and from then on, a stranger emailing dmb@futari.live sees their message appear in my familiar Gmail inbox a moment later. No need for a new app. No need for a new password. The emails automatically follow me home.
As a quick sidebar there's a small honesty to note about how a computer finds my sorting office in the first place. Attached to my domain is a kind of public directory listing. It has DNS records and there is a particular record with one special line in it, the MX record (think: "Mail eXchange"). It is a signpost that says, "letters for this domain go here." Namecheap sets that signpost up automatically when you turn forwarding on. It is similar to the postal system's way of knowing which building to deliver to.
And that's receiving, entirely solved. One forwarding rule. If this were all I wanted (an address on my business card that reaches me) I could have stopped here, for nothing. But I wanted to reply as myself, and that turns out to be the harder half!
Job two: sending, and why you can't just claim to be yourself
Remember the return address you could forge on a paper envelope? On the early internet, email worked exactly that carelessly. You could type any "From" address you wanted and the system would carry it. Which is wonderful right up until you realize that every scammer on earth realized it too. This is why your spam folder is full of mail claiming to be your bank. Anyone can write "your bank" in the corner. Writing it doesn't make it true.
So, the email world, over years, bolted on a way to tell a real sender from a liar. The idea is roughly this: to send mail as a domain, you must prove you're authorized by that domain. Think of this like the way a signet ring pressed into wax once proved a letter really came from the person whose seal it was. A forged envelope has no matching seal, and the receiving post office learns to get rid of anything whose seal doesn't check out.
In email, that seal is stamped by whoever actually sends your mail on your behalf, and the domain publishes in that public DNS directory a note saying, "I trust this sender to sign for me." When Gmail or Outlook receives a message claiming to be from futari.live, it checks the seal against that published note. If it is a match, then the letter is trusted. If it is a mismatch, then it is treated as the forgery it probably is.
Which means I couldn't just declare that I send as futari.live. I needed a real, reputable sending office to press the seal for me and my domain had to publicly bless it. I hope you are still with me 🥱.
The sending office I already had
Here's the lucky part. My website already sends email for example the little "thanks for subscribing" messages. To send those reliably, it goes through a service called Brevo, whose entire job is to be a trustworthy sending office that big providers like Gmail already respect. And when I set that up, I'd already done the one-time ceremony of publishing the "I trust Brevo to sign for me" note in my domain's directory.
So, the sending office was already hired and already blessed. To have my app's mail go out as dmb@futari.live, I only had to change the return address it writes which is a single setting. No new machinery. The seal and the trust were already in place from months earlier.
That covered mail my website sends. But I also wanted to sit in Gmail and personally reply as dmb@futari.live and of course Gmail sensibly won't let you claim an address you can't prove you own.
Teaching Gmail to sign my letters
Gmail has a feature politely called "Send mail as." You tell it, "I'd like to also send as dmb@futari.live," and because it refuses to let people impersonate addresses it does two checks.
First, it wants to know the letter will actually be sealed by a real office, so it asks for the sending office's details: Brevo's address, and a password You can easily get this from Brevo. Now it can hand my outgoing replies to Brevo, which presses the trusted seal on the way out.
Second, it proves I really control the mailbox, using a small loop that's rather elegant. It emails a secret code to dmb@futari.live and thanks to the forwarding I set up in job one thanks to Namecheap, that code lands in my Gmail. I read it, type it back, and Gmail is satisfied: only the true owner of the mailbox could have received it. The two halves shake hands. Receiving made sending possible.
From then on, a little dropdown appears when I write or reply, which lets me choose which address the letter goes out as. Finally, there is one setting in gmail under Accounts & Import tab which is "reply from the same address the message was sent to". This makes it automatic so that a letter that arrived for dmb@futari.live gets answered as dmb@futari.live, without me thinking about it. The disguise becomes seamless!
The one place I got stuck (and why it made sense)
I'll leave you with the single snag, because it taught me something about how these seals work in practice.
The sending office, Brevo, has an optional bit of extra security: you can tell it, "Only accept outgoing mail from these specific machines." Basically, it has a whitelist of addresses and if the address is not on the whitelist, it bounces the request. That's a sensible lock if your mail always leaves from one fixed computer for example my website's server, which lives at one steady address. It's a bouncer with a short guest list.
However, Gmail doesn't send from one machine. Google's mail leaves from an enormous, ever shifting pool of computers and because of this each of my attempts to verify Brevo from Gmail came from a different IP address (machine). Therefore, the bouncer kept turning them away: "you're not on the list." I'd add the IP address (machine) that was blocked, retry, and the next attempt arrived from a different IP address (machine), also not on the list. A door I could never finish unlocking!
The fix was to add Googe cidr range to the whitelist. A cidr range is a group of IP addresses (I would try to talk about this in another article perhaps) and with this cidr range I was able to capture all of Google's possible addresses that the request could have come from. After adding the cidr range I was able to connect Brevo to Gmail successfully.
What it all cost
Nothing, beyond the domain I already owned. Receiving is simply a free forwarding rule on the Namecheap side. Sending reuses a service (Brevo) my site was already paying nothing to start with. And the personal "reply as me" is one Gmail feature and a seven-minute (I counted) handshake.
Which brings me back to the letter and the mailbox. A custom email address looks like a single thing: a name with an @ in it. However, it's really two quiet promises the internet has to keep for you
that letters addressed to that name will find you
and that letters you send under that name will be believed.
Arrange the mail redirect, borrow a sealing office your domain trusts, and teach your everyday inbox to use both, and the name on your business card would finally do what people already assume it does!
For what does the Scripture say? "Abraham believed God, and it was accounted to him for righteousness." - Romans 4:3