How do I add SPF, DKIM, and DMARC records?
SPF and DKIM
SPF is a single TXT record on your root domain, starting with v=spf1. It lists the servers allowed to send mail for your domain, and ends with a policy like -all (hard fail) or ~all (soft fail).
DKIM is a TXT record published at a selector hostname, such as selector1._domainkey.example.com. Your mail provider gives you the exact name and value.
Keep SPF under the 10-lookup limit. Each include, a, mx, ptr, or exists mechanism counts as a lookup.
DMARC and rollout
DMARC is a TXT record at _dmarc.yourdomain.com. It tells receivers what to do when SPF or DKIM fails, and where to send reports.
Start with v=DMARC1; p=none; rua=mailto:you@example.com to monitor without blocking mail. After a few weeks of clean reports, move to p=quarantine, then p=reject.
Add pct= to roll out gradually if you have a lot of mail streams, and use rua for aggregate reports and ruf for forensic reports.
- SPF: v=spf1 include:_spf.google.com ~all
- DKIM: selector._domainkey TXT with your provider's public key
- DMARC: v=DMARC1; p=none; rua=mailto:dmarc@example.com
- Use only one SPF record per domain
- DMARC requires an aligned SPF or DKIM domain
Common mistakes
- Publishing two SPF records instead of merging them into one — receivers treat this as a permanent error.
- Jumping straight to p=reject without monitoring, which can block legitimate mail you forgot to authenticate.
- Assuming DKIM works without checking the selector name; a typo in the hostname means the signature is never found.
