# Mailgun: Private API Key Setup

> Find your Mailgun Private API key, add it at Agency or Location in GHL Customer Care, select a US‑region verified domain, and validate sending and replies.

- Source: https://docs.ghlcustomercare.com/docs/email/mailgun/mailgun-private-api-key-setup
- Section: Email / MailGun
- Reading time: 5 min
- Images: 6, each explained below
- Modified on Wed, 3 Sep, 2025 at 8:16 AM

---
Use your Mailgun Private API key to connect a verified Mailgun domain to GHL Customer Care so you can send and receive emails reliably. This guide explains where to find the key in Mailgun, exactly where to paste it in GHL Customer Care at the Agency and Location levels, and how to validate and troubleshoot the connection.

---

**TABLE OF CONTENTS**

-   [What is the Mailgun Private API Key for GHL Customer Care?](#what-is-the-mailgun-private-api-key-for-ghl-customer-care)
-   [Key Benefits of Using a Mailgun Private API Key](#key-benefits-of-using-a-mailgun-private-api-key)
-   [Prerequisites](#prerequisites)
-   [Region and Domain Visibility (US vs. EU)](#region-and-domain-visibility-us-vs-eu)
-   [How To Set Up the Mailgun Private API Key in GHL Customer Care](#how-to-set-up-the-mailgun-private-api-key-in-ghl-customer-care)
    -   [Step 1: Copy your Private API key from Mailgun](#step-1-copy-your-private-api-key-from-mailgun)
    -   [Step 2: Add the key at the Agency level (optional, shared use)](#step-2-add-the-key-at-the-agency-level-optional-shared-use)
-   [Location Settings Considerations](#location-settings-considerations)
-   [Troubleshooting & Validation](#troubleshooting-and-validation)
-   [Frequently Asked Questions](#frequently-asked-questions)

---

---

## **What is the Mailgun Private API Key for GHL Customer Care?**

The Mailgun Private API key authenticates GHL Customer Care with your Mailgun account so GHL Customer Care can access your verified sending domains, send emails, and process replies. The key is generated in Mailgun and then pasted into GHL Customer Care. Once saved, eligible US‑region verified domains appear in the domain dropdown for selection at the Location level.

**IMPORTANT**: Treat these **Private API keys** as a secret; do not share in tickets or screenshots. **Rotate periodically** or whenever you suspect exposure; generate a new key in Mailgun and update it in GHL Customer Care at the Agency/Location where it’s stored.

---

## **Key Benefits of Using a Mailgun Private API Key**

Understanding the value of this connection helps you choose the right place to configure it and avoid sending issues. The bullets below highlight how a correct setup improves reliability, control, and scalability when emailing from GHL Customer Care.

-   **Centralized authentication:** Use one key at the Agency level to power multiple Locations when appropriate.
    
-   **Location‑level control:** Override the Agency key at a specific Location when a client needs their own Mailgun account and domain.
    
-   **Domain dropdown visibility:** Selecting a verified US‑region domain from a dropdown reduces misconfiguration and ensures you send from the correct domain.
    
-   **Reply handling enablement:** A valid key plus a proper receiving route helps replies land in Conversations for the right sub‑account.
    
-   **Security & rotation:** Keys can be regenerated in Mailgun and updated in GHL Customer Care to maintain account security.
    
-   **Scalability:** Multi‑client agencies can standardize setup, speed onboarding, and align with client‑owned infrastructure when needed.
    

---

## **Prerequisites**

Preparing the environment first prevents common blockers where the domain doesn’t appear in GHL Customer Care or emails fail to send. Confirm each item before pasting your key.

-   A Mailgun account with at least one **verified** sending domain (green check) set up under the **US region**.
    
-   Access to the High-Level **Agency** view and the relevant **Location** with permissions to open **Settings → Email Services**.
    
-   DNS for the Mailgun domain is correctly configured (DKIM, SPF, MX, and tracking CNAME if you use link tracking).
    
-   Any Mailgun IP allowlist will be temporarily relaxed if needed to allow GHL Customer Care to sync domains (restore after validation).
    

---

## **Region and Domain Visibility (US vs. EU)**

GHL Customer Care reads verified domains from Mailgun’s **US region** only. If a domain is created in the EU region, it will not populate in the High-Level domain dropdown.

-   Ensure the Mailgun domain lives in the **US** and shows as **Verified**.
    
-   If your domain is in the **EU**, create/migrate a US‑region domain for use with GHL Customer Care.
    

---

## **How To Set Up the Mailgun Private API Key in GHL Customer Care**

Following the steps in order prevents the most common misconfigurations. Start in Mailgun to retrieve the key, then paste it into GHL Customer Care at the Agency or Location level, select your domain, and validate.

### **Step 1:** Copy your Private API key from Mailgun

Log in to **Mailgun.** Click your **profile avatar** (top‑right) → **API Security**. Create a new key if needed, or **copy** the existing **Private API key**.

![Step 1: Copy your Private API key from Mailgun (image 1 of 6)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155053009311/original/GtL1-0NEzqjrBBuInbEo7iGwCdJMlMXDJg.png)

**Step 1: Copy your Private API key from Mailgun (image 1 of 6)**

This screenshot appears in the "Step 1: Copy your Private API key from Mailgun" section of "Mailgun: Private API Key Setup". The text alongside this image reads: Log in to Mailgun. Click your profile avatar (top‑right) → API Security. Create a new key if needed, or copy the existing Private API key. Immediately after, the guide continues: In GHL Customer Care (Agency view), go to Settings → Email Services. Select Mailgun and paste the Private API key. Select the domain and then click Save.
- What to copy: Log in to Mailgun. Click your profile avatar (top‑right) → API Security. Create a new key if needed, or copy the existing Private API key.
- Controls: Mailgun., profile avatar, API Security, copy, Private API key
- Next: In GHL Customer Care (Agency view), go to Settings → Email Services. Select Mailgun and paste the Private API key. Select the domain and then click Save.

### **Step 2:** Add the key at the Agency level (optional, shared use)

In **GHL Customer Care (Agency view)**, go to **Settings → Email Services**. Select **Mailgun** and paste the **Private API key**. Select the domain and then click **Save**. 

(Optional) Open a **Location** to confirm the domain appears in its dropdown after sync.

![Step 2: Add the key at the Agency level (optional, shared use) (image 2 of 6)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155053009956/original/qkvDGL6oRHmywR-iuQL6r5qAEsjbwNL4-A.gif)

**Step 2: Add the key at the Agency level (optional, shared use) (image 2 of 6)**

This animation appears in the "Step 2: Add the key at the Agency level (optional, shared use)" section of "Mailgun: Private API Key Setup". The text alongside this image reads: (Optional) Open a Location to confirm the domain appears in its dropdown after sync. Immediately after, the guide continues: IMPORTANT: Make sure the domain is set up for US and there's a green checkmark next to the domain.
- What to choose: (Optional) Open a Location to confirm the domain appears in its dropdown after sync.
- Controls: GHL Customer Care (Agency view), Settings → Email Services, Mailgun, Private API key, Save, Location, IMPORTANT, US, green checkmark
- Next: IMPORTANT: Make sure the domain is set up for US and there's a green checkmark next to the domain.

**IMPORTANT**: Make sure the domain is set up for **US** and there's a **green checkmark** next to the domain.

![Step 2: Add the key at the Agency level (optional, shared use) (image 3 of 6)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155053010520/original/wTfs0PssGmngzK3Zuvif__AnMaGOueL_bQ.png)

**Step 2: Add the key at the Agency level (optional, shared use) (image 3 of 6)**

This screenshot appears in the "Step 2: Add the key at the Agency level (optional, shared use)" section of "Mailgun: Private API Key Setup". The text alongside this image reads: (Optional) Open a Location to confirm the domain appears in its dropdown after sync. Immediately after, the guide continues: This is how a successful Connection would look-.
- What to choose: (Optional) Open a Location to confirm the domain appears in its dropdown after sync.
- Controls: GHL Customer Care (Agency view), Settings → Email Services, Mailgun, Private API key, Save, Location, IMPORTANT, US, green checkmark
- Next: This is how a successful Connection would look-

This is how a successful Connection would look-

![Step 2: Add the key at the Agency level (optional, shared use) (image 4 of 6)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/48279962136/original/B2HJkrzdKmeChQEF6-kdruFACqTiCGu4bQ.png)

**Step 2: Add the key at the Agency level (optional, shared use) (image 4 of 6)**

This screenshot appears in the "Step 2: Add the key at the Agency level (optional, shared use)" section of "Mailgun: Private API Key Setup". The text alongside this image reads: This is how a successful Connection would look-. Immediately after, the guide continues: You can configure each location with your client's own Mailgun or your Mailgun. We can use the same Mailgun API and the same domain/subdomain for multiple locations. We can use the same Mailgun API and different domains/subdomains for….
- What this covers: This is how a successful Connection would look-
- Controls: GHL Customer Care (Agency view), Settings → Email Services, Mailgun, Private API key, Save, Location, IMPORTANT, US, green checkmark
- Next: You can configure each location with your client's own Mailgun or your Mailgun. We can use the same Mailgun API and the same domain/subdomain for multiple locations. We can use the same Mailgun API and different domains/subdomains for multiple locations. We can use the different Mailgun API and domains/subdomains for multiple locations. You can also set up a unique domain/subdomain for each location to capture cold inbound emails. Learn more about Cold Email Inbound Setup here.

---

## **Location Settings Considerations**

-   You can configure each location with your client's own Mailgun or your Mailgun.
-   We can use the same Mailgun API and the same domain/subdomain for multiple locations.
-   We can use the same Mailgun API and different domains/subdomains for multiple locations.
-   We can use the different Mailgun API and domains/subdomains for multiple locations.
-   You can also set up a unique domain/subdomain for each location to capture cold inbound emails. [](https://docs.ghlcustomercare.com/docs/email/mailgun/cold-email-inbound-setup-mailgun)[](https://docs.ghlcustomercare.com/docs/email/mailgun/cold-email-inbound-setup-mailgun)[](https://docs.ghlcustomercare.com/docs/email/mailgun/cold-email-inbound-setup-mailgun)[Learn more about Cold Email Inbound Setup here.](https://docs.ghlcustomercare.com/docs/email/mailgun/cold-email-inbound-setup-mailgun)

---

## **Troubleshooting & Validation**

If the domain you set up does not show up in the dropdown.

1\. Please set up the domain or subdomain under the US, not the EU. 

![Troubleshooting & Validation (image 5 of 6)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155053011369/original/DjcnT9n3f0d2eep2HYX_dDL2BMw-etfKvg.png)

**Troubleshooting & Validation (image 5 of 6)**

This screenshot appears in the "Troubleshooting & Validation" section of "Mailgun: Private API Key Setup". The text alongside this image reads: 1. Please set up the domain or subdomain under the US, not the EU. Immediately after, the guide continues: 2. Check if the Mailgun account has added the allowed IP in MailGun, so we are not able to pull it. Please remove all the IP whitelist; you can add it back later on.
- What this covers: 1. Please set up the domain or subdomain under the US, not the EU.
- Next: 2. Check if the Mailgun account has added the allowed IP in MailGun, so we are not able to pull it. Please remove all the IP whitelist; you can add it back later on.

2\. Check if the Mailgun account has added the allowed IP in MailGun, so we are not able to pull it. Please remove all the IP whitelist; you can add it back later on.

![Troubleshooting & Validation (image 6 of 6)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155053011609/original/jeX5H0Z7HskxTbYLqBiaDc9sqEipH4BMNQ.png)

**Troubleshooting & Validation (image 6 of 6)**

This screenshot appears in the "Troubleshooting & Validation" section of "Mailgun: Private API Key Setup". The text alongside this image reads: 2. Check if the Mailgun account has added the allowed IP in MailGun, so we are not able to pull it. Please remove all the IP whitelist; you can add it back later on. Immediately after, the guide continues: Q: Do I need the Private or Public API key?
- What this covers: 2. Check if the Mailgun account has added the allowed IP in MailGun, so we are not able to pull it. Please remove all the IP whitelist; you can add it back later on.
- Next: Q: Do I need the Private or Public API key?

---

## **Frequently Asked Questions**

**Q: Do I need the Private or Public API key?**

Use the **Private API key**. Public keys won’t authenticate the provider in GHL Customer Care.

**Q: My domain is verified in Mailgun EU. Why can’t I select it in GHL Customer Care?**

GHL Customer Care reads verified domains from the **US region**. Create or migrate a US‑region domain to use it in GHL Customer Care.

**Q: What happens if I paste a key at both the Agency and the Location?**

The **Location** configuration overrides the Agency provider for that Location, allowing client‑specific domains and sending.

**Q: Can multiple Locations share one Mailgun key?**

Yes. Paste the key at the **Agency** level to make its verified US‑region domains available across Locations. Use Location‑level keys when a client must be isolated.

**Q: My domain doesn’t appear even after saving the key—what next?**

Re‑check the US region and domain verification, temporarily relax the Mailgun IP allowlist to sync, then restore it. Also, confirm you’re saving at the intended level.

---

Documentation for GHL Customer Care. Support: support@ghlcustomercare.com