Pulumi + Cloudflare email checklist
Use this when standing up or reviewing an org infra Pulumi stack (example: nonprofit-resources/infra, private).
Before pulumi up
-
[ ] Domain(s) on Cloudflare; note zone IDs
-
[ ] API token with Zone DNS Edit (add Email Routing edit if automating Routing)
-
[ ]
pulumi config set cloudflare:apiToken --secret … -
[ ] Netlify (or other) hostname for apex/
wwwCNAMEs -
[ ] Decide lanes: Resend (
updates.), Customer.io (news.), ZeptoMail (human), Routing (inbound)
Automatable vs manual
| In Pulumi / Cloudflare API | Manual / other UI |
|---|---|
Apex/ |
Resend / Customer.io “copy these records” paste into config then apply |
DKIM/SPF CNAMEs/TXT once values known |
ESP dashboard “verify domain” clicks |
Optional Email Routing MX (if you choose to manage MX in stack) |
Routing destination verify + create addresses in dashboard |
Stack outputs / runbooks |
Gmail Send mail as create (Composio can list/patch; create often UI-only) |
— |
ZeptoMail Mail Agent + per-user SMTP passwords |
Personal Gmail caveat
Founders on @gmail.com should read Personal Gmail send-as gotchas and Cloudflare Email Routing limits before assuming Cloudflare “email” replaces Workspace.