Pulumi + Cloudflare email checklist

Use this when standing up or reviewing an org infra Pulumi stack (example: nonprofit-resources/infra, private).

Before pulumi up

  1. [ ] Domain(s) on Cloudflare; note zone IDs

  2. [ ] API token with Zone DNS Edit (add Email Routing edit if automating Routing)

  3. [ ] pulumi config set cloudflare:apiToken --secret …

  4. [ ] Netlify (or other) hostname for apex/www CNAMEs

  5. [ ] Decide lanes: Resend (updates.), Customer.io (news.), ZeptoMail (human), Routing (inbound)

Automatable vs manual

In Pulumi / Cloudflare API Manual / other UI

Apex/www → site host; DMARC TXT

Resend / Customer.io “copy these records” paste into config then apply

DKIM/SPF CNAMEs/TXT once values known

ESP dashboard “verify domain” clicks

Optional Email Routing MX (if you choose to manage MX in stack)

Routing destination verify + create addresses in dashboard

Stack outputs / runbooks

Gmail Send mail as create (Composio can list/patch; create often UI-only)

ZeptoMail Mail Agent + per-user SMTP passwords

Personal Gmail caveat

Founders on @gmail.com should read Personal Gmail send-as gotchas and Cloudflare Email Routing limits before assuming Cloudflare “email” replaces Workspace.