{"id":"699fa764ad75d77892c87e07","title":"2026 02 26","path":"how-to/committee/release-notes/2026-02-26","contentMarkdown":"# 26-Feb-2026 — add Brevo domain authentication UI and stale DNS cleanup [ref: #167](https://github.com/nbarrett/ngx-ramblers/issues/167)\n\n## [build 500](https://github.com/nbarrett/ngx-ramblers/actions/runs/22424029078) — [commit ca57a0d](https://github.com/nbarrett/ngx-ramblers/commit/ca57a0d25f9dbf723dd3d5906b24dfd1df6530aa)\n\n_____\n# Brevo Domain Authentication Guide\n- Add domain authentication status badge and authenticate button to mail senders list. \n- Clean up stale TXT records in Cloudflare before creating new ones and skip DNS propagation delay when records are already verified.\n- Show actionable fallback message with Brevo Domains link when DKIM is unavailable for subdomains. Add authenticate-brevo-domain environment\nsetup route and option.\n- Use this when setting up sender domain authentication from **Admin > Mail Settings > Senders**.\n\n![](https://ngx-ramblers.org.uk/api/aws/s3/site-content/95e92063-e80c-4bd8-a1ec-c6f4384f631c.jpeg)\n\n\n## What this feature now does\n- Shows current domain authentication status on the Senders tab\n- Adds an Authenticate Domain action for the selected sender domain\n- Creates or reuses the required brevo-code TXT record in Cloudflare\n- Cleans up previously registered parent-domain records when authenticating a configured subdomain\n- Detects when Brevo already reports DNS verification and skips unnecessary wait time\n- Gives a clear next-step message with a direct Brevo Domains link when API authentication cannot complete\n## Expected flow for a normal domain\n1. Open Admin > Mail Settings > Senders\n2. Click Authenticate Domain\n3. Wait for status refresh\n4. If Brevo returns all required DNS records, the status changes to authenticated\n## Expected flow for subdomains\nFor subdomains e.g. `xxxx.ngx-ramblers.org.uk`, Brevo may not return DKIM via API.\n### In this case:\n1. Click Authenticate Domain in NGX-Ramblers\n2. Use the warning link to open Brevo Domains\n3. In Brevo, run Authenticate the domain yourself\n4. Return to NGX-Ramblers and refresh or retry authentication\nWhen Brevo completes domain-side authentication, the badge updates to authenticated.\n## Troubleshooting\n- If authentication targets the wrong parent domain, rerun authentication from the Senders tab. Legacy parent-domain registrations are now removed automatically for configured subdomain flows.\n- If Brevo returns HTTP 400 mentioning missing DKIM/DMARC, complete the manual Brevo step and retry.\n- If sender deletion appears successful but the sender still exists remotely, the API now surfaces this as a failure instead of reporting success.\n### Technical details:\n- Sender domain status and Authenticate Domain action were added to the Senders tab.\n- Legacy parent-domain registrations are automatically removed for configured subdomain authentication flows.\n- Existing verified DNS records are reused to avoid unnecessary propagation waits.\n- Sender deletion now returns failure when Brevo still reports the sender after delete.","contentHtml":"<h1>26-Feb-2026 — add Brevo domain authentication UI and stale DNS cleanup <a href=\"https://github.com/nbarrett/ngx-ramblers/issues/167\">ref: #167</a></h1>\n<h2><a href=\"https://github.com/nbarrett/ngx-ramblers/actions/runs/22424029078\">build 500</a> — <a href=\"https://github.com/nbarrett/ngx-ramblers/commit/ca57a0d25f9dbf723dd3d5906b24dfd1df6530aa\">commit ca57a0d</a></h2>\n<hr>\n<h1>Brevo Domain Authentication Guide</h1>\n<ul>\n<li>Add domain authentication status badge and authenticate button to mail senders list. </li>\n<li>Clean up stale TXT records in Cloudflare before creating new ones and skip DNS propagation delay when records are already verified.</li>\n<li>Show actionable fallback message with Brevo Domains link when DKIM is unavailable for subdomains. Add authenticate-brevo-domain environment\nsetup route and option.</li>\n<li>Use this when setting up sender domain authentication from <strong>Admin &gt; Mail Settings &gt; Senders</strong>.</li>\n</ul>\n<p><img src=\"https://ngx-ramblers.org.uk/api/aws/s3/site-content/95e92063-e80c-4bd8-a1ec-c6f4384f631c.jpeg\" alt=\"\"></p>\n<h2>What this feature now does</h2>\n<ul>\n<li>Shows current domain authentication status on the Senders tab</li>\n<li>Adds an Authenticate Domain action for the selected sender domain</li>\n<li>Creates or reuses the required brevo-code TXT record in Cloudflare</li>\n<li>Cleans up previously registered parent-domain records when authenticating a configured subdomain</li>\n<li>Detects when Brevo already reports DNS verification and skips unnecessary wait time</li>\n<li>Gives a clear next-step message with a direct Brevo Domains link when API authentication cannot complete</li>\n</ul>\n<h2>Expected flow for a normal domain</h2>\n<ol>\n<li>Open Admin &gt; Mail Settings &gt; Senders</li>\n<li>Click Authenticate Domain</li>\n<li>Wait for status refresh</li>\n<li>If Brevo returns all required DNS records, the status changes to authenticated</li>\n</ol>\n<h2>Expected flow for subdomains</h2>\n<p>For subdomains e.g. <code>xxxx.ngx-ramblers.org.uk</code>, Brevo may not return DKIM via API.</p>\n<h3>In this case:</h3>\n<ol>\n<li>Click Authenticate Domain in NGX-Ramblers</li>\n<li>Use the warning link to open Brevo Domains</li>\n<li>In Brevo, run Authenticate the domain yourself</li>\n<li>Return to NGX-Ramblers and refresh or retry authentication\nWhen Brevo completes domain-side authentication, the badge updates to authenticated.</li>\n</ol>\n<h2>Troubleshooting</h2>\n<ul>\n<li>If authentication targets the wrong parent domain, rerun authentication from the Senders tab. Legacy parent-domain registrations are now removed automatically for configured subdomain flows.</li>\n<li>If Brevo returns HTTP 400 mentioning missing DKIM/DMARC, complete the manual Brevo step and retry.</li>\n<li>If sender deletion appears successful but the sender still exists remotely, the API now surfaces this as a failure instead of reporting success.</li>\n</ul>\n<h3>Technical details:</h3>\n<ul>\n<li>Sender domain status and Authenticate Domain action were added to the Senders tab.</li>\n<li>Legacy parent-domain registrations are automatically removed for configured subdomain authentication flows.</li>\n<li>Existing verified DNS records are reused to avoid unnecessary propagation waits.</li>\n<li>Sender deletion now returns failure when Brevo still reports the sender after delete.</li>\n</ul>\n"}