DEV Community

Cover image for Free Email Forwarding for Your Personal Domain With Cloudflare Email Routing
Khasky
Khasky

Posted on

Free Email Forwarding for Your Personal Domain With Cloudflare Email Routing

Forward any address at your domain, such as hello@example.com, to an external inbox. For a public address that only has to receive mail, I would put it on Cloudflare Email Routing: the messages land in the inbox I already read, and forwarding to a verified destination costs nothing on any plan. šŸ’ø

Prerequisites: the domain is on Cloudflare DNS (nameservers delegated, DNS Setup = Full), and it has no MX records from another mail host. Email Routing owns the MX set.

1. Verify the destination address

Compute > Email Service > Email Routing > Destination Addresses > Add address. Enter the external inbox (for example, you@gmail.com). Cloudflare emails a confirmation link, and you click it.

The row must read Verified. Until it does, any rule that points to the address stays disabled.

Destination addresses are account-wide: once verified, any zone in the account can target it.

2. Enable routing and add the DNS records

Open the zone's Email Routing > Settings > DNS records > Add missing records. Cloudflare writes these records and locks them:

Type  Name                             Value
MX    example.com                      route1.mx.cloudflare.net (+ route2, route3)
TXT   example.com                      v=spf1 include:_spf.mx.cloudflare.net ~all
TXT   cf2024-1._domainkey.example.com  v=DKIM1; h=sha256; k=rsa; p=...
Enter fullscreen mode Exit fullscreen mode

A locked record cannot be edited or deleted from the DNS page until you unlock it in the Email Routing settings.

Keep one SPF TXT record per name. If the domain already has one, the merge is yours to do: Cloudflare's example combines both includes in a single record, v=spf1 include:_spf.mx.cloudflare.net include:_spf.google.com ~all.

3. Create the routing rule

Email Routing > Routing rules > Create routing rule:

  • Email pattern: hello @ example.com
  • Action: Send to an email
  • Destination: the verified address

Save. The rule must show Active.

The pattern takes any local part, not only hello: sales, support or your own name work the same way, one rule per address.

4. Decide the catch-all

The catch-all in Routing rules defines what happens to every other address at the domain. Enabled with Send to an email, it forwards all of them, typos such as ifno@example.com included. Enabled with Drop, it discards them silently.

I would start with it off and turn on forwarding only if people keep misspelling the real address.

5. Verify

# MX must answer from the Cloudflare route hosts
curl -sH 'accept: application/dns-json' \
  'https://cloudflare-dns.com/dns-query?name=example.com&type=MX'

# SPF
curl -sH 'accept: application/dns-json' \
  'https://cloudflare-dns.com/dns-query?name=example.com&type=TXT'
Enter fullscreen mode Exit fullscreen mode

Then send a real message to hello@example.com and confirm it lands in the destination inbox. šŸ“¬

Email Routing > Activity Log shows the decision for each message: Forwarded, Dropped, Rejected or Delivery failed.

Notes

  • Forwarding only. A routing rule receives mail and does not send it, so a reply from the destination inbox goes out through that provider, from its address. Sending from the domain is a separate product, Cloudflare Email Sending, which is still in beta.
  • Negative DNS answers stay cached for the zone's SOA minimum TTL, 1800 seconds (30 minutes) by default on Cloudflare. If you queried MX before the records existed, your resolver may keep returning empty. Query a different resolver or go over DoH to confirm.

Five steps give a domain working addresses with no mailbox bill, and I would pay for a mailbox only on the day replies have to come from the domain itself.

References


Follow me for more on AI, LLMs, and Software Development:

khasky — LinkedIn / Patreon / GitHub / Bluesky / Mastodon

khaskydev — X / Threads / Instagram / Pinterest / Facebook

Top comments (1)

Collapse
 
respect17 profile image
Kudzai Murimi •

The SPF merge warning is the detail that saves someone a debugging session, having two separate v=spf1 records instead of one merged one silently breaks SPF for both. Good call keeping the catch-all off by default too, forwarding every typo'd address is how a domain quietly becomes a spam magnet.