# Separate Domains — Multi-Tenant — PostFrame — EternalEngine

Verified sending domains belong to their tenant. SPF, DKIM, and DMARC records are managed per-organization with completely independent reputation tracking.

[Back to Multi-Tenant](https://eternalengineos.io/features/postframe/multi-tenant/)

Enterprise Architecture

# Separate Domains

A sending domain is claimed by exactly one workspace across the whole platform, carries its own DKIM tokens, SPF, bounce domain and DMARC record, and reports its own reputation.

[Start free](https://app.eternalengineos.io/signup?plan=free&interval=annual)[Multi-tenant overview](https://eternalengineos.io/features/postframe/multi-tenant/)

## Domain-Level Isolation

Per-tenant verification

Each tenant verifies their own domains — no domain sharing between organizations

Independent reputation

One tenant's deliverability issues never affect another tenant's sender reputation

Dedicated DKIM keys

Each tenant-domain pair gets its own DKIM signing key for cryptographic isolation

Bounce domain per domain

bounce.yourdomain.com gets its own MX and SPF so bounces and alignment stay with the owning workspace

Domain Security

DKIM keys unique per tenant

Cryptographic signing isolation between organizations

One workspace per domain

A second workspace that tries to add a claimed domain gets a clear refusal, never a silent share

DMARC policies per domain

Independent enforcement levels per tenant domain

Reputation tracked independently

Sender scores isolated across tenant boundaries

## Keep exploring PostFrame

[### Domain verification The guided setup, record by record. Open Domain verification →](https://eternalengineos.io/features/postframe/domain-verification/)[### DKIM signing Three CNAMEs per domain, keys on the signing side. Open DKIM signing →](https://eternalengineos.io/features/postframe/domain-verification/dkim/)[### Isolated providers Credentials, priority and limits per workspace. Open Isolated providers →](https://eternalengineos.io/features/postframe/multi-tenant/isolated-providers/)

Questions

## Common questions, straight answers.

Can two workspaces verify the same domain?

No. A domain is claimed platform-wide by the first workspace that adds it; a second attempt is refused with a message saying the domain is already claimed. Deleting the domain releases the claim.

Are DKIM keys shared between workspaces?

No. Each domain gets its own DKIM tokens when it is registered, and a domain belongs to one workspace, so signing keys never cross a workspace boundary.

Where do I see my domain's reputation?

The Domain reputation report in PostFrame analytics, computed from your own sends — bounces, complaints and delivery on that domain only.

## Run your business from one place.

Five plans, seventeen launch apps, one dashboard. Set up in under 5 minutes — change tiers any time.

[Start free$0 forever &bull; No card &bull; Upgrade any time](https://app.eternalengineos.io/signup?plan=free&interval=annual)[Talk to Sales](https://eternalengineos.io/contact/)

From $0 · Basic $9.95/mo · Save 20% on annual billing · Upgrade or downgrade any time
