Scan a domain, generate every mail record it needs, push them to Cloudflare, then verify they resolve.
Reads live DNS over Cloudflare and Google resolvers. Nothing is written until you ask it to.
Answers below prefill the form.
The part before .onmicrosoft.com — used for the DKIM CNAMEs.
| Type | Name | Value | Prio |
|---|
One domain per line. Optional second and third column: tenant, tracking target.
Settings come from the One domain tab, so fill that in first.
| Domain | Records | Notes |
|---|
Your token is forwarded straight to Cloudflare for each call and never stored or logged. The proxy only accepts zone-read and DNS-record calls. Prefer a token scoped to the zones you are editing.
Nothing queued yet — generate records first.
| Domain | Type | Name | Outcome |
|---|