Configuring Mailgun with Your CRM Using a Private API Key
Introduction
Use your Mailgun Private API key to connect a verified Mailgun domain to your CRM, enabling reliable email sending and receiving. This guide covers how to locate the key in Mailgun, where to enter it in your CRM at both the Agency and Location levels, and how to validate and troubleshoot the connection.
What Is the Mailgun Private API Key Used For?
The Mailgun Private API key authenticates your CRM with your Mailgun account, allowing the CRM to access your verified sending domains, send emails, and process replies. The key is generated in Mailgun and then entered into your CRM. Once saved, eligible verified domains from the US region will appear in the domain dropdown for selection at the Location level.
Important: Treat Private API keys as confidential information. Do not share them in support tickets or screenshots. Rotate keys periodically or if you suspect exposure by generating a new key in Mailgun and updating it in your CRM at the appropriate Agency or Location level.
Key Benefits
Using a Mailgun Private API key offers several advantages for email reliability, control, and scalability:
- Centralized authentication: Use one key at the Agency level to serve multiple Locations when appropriate.
- Location-level control: Override the Agency key at a specific Location for clients requiring their own Mailgun account and domain.
- Domain dropdown visibility: Select a verified US-region domain from a dropdown to reduce misconfigurations and ensure correct sending.
- Reply handling enablement: A valid key with proper receiving routes ensures replies land in Conversations for the correct sub-account.
- Security and rotation: Regenerate keys in Mailgun and update them in your CRM to maintain account security.
- Scalability: Multi-client agencies can standardize setups, speed up onboarding, and align with client-owned infrastructure.
Prerequisites
Before adding your key, confirm the following:
- A Mailgun account with at least one verified sending domain (marked with a green check) set up under the US region.
- Access to your CRM’s Agency view and relevant Location with permissions to open Settings → Email Services.
- DNS for the Mailgun domain is correctly configured (including DKIM, SPF, MX, and tracking CNAME if using link tracking).
- Temporarily relax any Mailgun IP allowlist to allow your CRM to sync domains (restore after validation).
Region and Domain Visibility
Your CRM reads verified domains from Mailgun’s US region only. Domains created in the EU region will not appear in the domain dropdown. Ensure your domain is set up in the US region and shows as Verified. If your domain is in the EU, create or migrate a US-region domain for use with your CRM.
How to Set Up the Mailgun Private API Key
Follow these steps to configure your Mailgun Private API key in your CRM.
Step 1: Copy Your Private API Key from Mailgun
Log in to your Mailgun account. Click your profile avatar in the top-right corner and select API Security. Create a new key if needed, or copy an existing Private API key.
Step 2: Add the Key at the Agency Level (Optional)
In your CRM’s Agency view, navigate to Settings → Email Services. Select Mailgun and paste the Private API key. Choose the domain from the dropdown and click Save. Optionally, open a Location to confirm the domain appears in its dropdown after synchronization.
Important: Ensure the domain is set up for the US region and has a green checkmark next to it for a successful connection.
Location Settings Considerations
You can configure each Location with its own Mailgun account or use a shared one. Options include:
- Using the same Mailgun API key and domain/subdomain for multiple Locations.
- Using the same Mailgun API key with different domains/subdomains for multiple Locations.
- Using different Mailgun API keys and domains/subdomains for multiple Locations.
- Setting up a unique domain/subdomain for each Location to capture cold inbound emails.
Troubleshooting and Validation
If your domain does not appear in the dropdown:
- Ensure the domain or subdomain is set up under the US region, not the EU.
- Check if the Mailgun account has an IP allowlist preventing access. Temporarily remove all IP whitelist entries; you can add them back later.
Frequently Asked Questions
Q: Do I need the Private or Public API key?
Use the Private API key. Public keys will not authenticate the provider in your CRM.
Q: My domain is verified in Mailgun EU. Why can’t I select it in my CRM?
Your CRM reads verified domains from the US region only. Create or migrate a US-region domain to use it.
Q: What happens if I paste a key at both the Agency and Location levels?
The Location configuration overrides the Agency provider for that Location, allowing client-specific domains and sending.
Q: Can multiple Locations share one Mailgun key?
Yes. Paste the key at the Agency level to make its verified US-region domains available across Locations. Use Location-level keys for client isolation.
Q: My domain doesn’t appear even after saving the key—what next?
Re-check that the domain is set up for the US region and verify all prerequisites are met.