What the three records do
When you send an email, the inbox on the other end asks your domain's DNS two questions. Is this service allowed to send for this domain? And what should I do if it is not? Three records answer.
- SPF lists the services that may send email for your domain, like Google Workspace, Microsoft 365 or your newsletter tool.
- DKIM puts a signature on each email. The inbox checks it with a key in your DNS. Each service that sends for you has its own key, found under a name called a selector.
- DMARC tells the inbox what to do with an email that fails both: let it through, put it in spam, or turn it away. It also asks inboxes to send you reports.
Since 2024, Gmail and Yahoo expect SPF, DKIM and DMARC from anyone who sends a lot of email. Without them, more of your email lands in spam, and anyone can send email that looks like it came from you.
How to use the checker
- Type your domain, like yourbusiness.com, and press Check.
- Read the SPF and DMARC cards. Each line says what we found, in plain words, and if you need to do something.
- For DKIM, type the selector your email service gave you, or press Try common selectors.
- If something is missing, copy the record under Records to add and add it where you manage your domain's DNS.
Where to add a record
Records are added at the company that runs your domain's DNS. That is often where you bought the domain, like GoDaddy, Namecheap, Squarespace or Cloudflare, or your web host. The checker names the company when it knows it.
- Sign in there and find the page called DNS, DNS records or Zone editor.
- Add a record of the type TXT.
- Copy the name and the value from the checker. Most DNS pages add your domain to the name by themselves, so use the short name, like _dmarc. For the domain itself, the name is @.
- Save, wait a few minutes, and check again. Some changes take up to a day to show.
Never add a second SPF record. Change the one you have instead, and put every service in it.
SPF in plain words
- ~all at the end marks email from other senders as suspicious. With DMARC on, this is the usual choice.
- -all makes email from other senders fail. Strict, and fine when every service that sends for you is listed.
- ?all says nothing about other senders, and +all lets anyone send as you. Change both to ~all.
- The 10 lookup limit. Each include, a, mx, ptr, exists and redirect makes the inbox look something up, and the includes inside an include count too. Above 10, SPF fails for every email. The checker counts them for you. To get under the limit, remove services you no longer use.
DMARC in plain words
- p=none only collects reports. A good first step while you learn who sends as you.
- p=quarantine sends email that fails to spam. Move here when the reports show only your own services.
- p=reject turns failing email away. The strongest setting.
- rua is the address the reports go to. Without it you get none.
- pct below 100 applies the policy to part of the failing email only. sp sets a separate policy for subdomains.
FAQ
Do I need SPF, DKIM and DMARC?
If you send email from your own domain, yes. Gmail and Yahoo expect all three from anyone who sends a lot of email, and every domain is safer with them, because they stop others from sending email in your name.
What is a DKIM selector?
The name of a key. Each service that signs your email has its own, and the key sits in DNS at selector._domainkey.yourdomain.com. Google Workspace uses google, Microsoft 365 uses selector1 and selector2, and Mailchimp uses k2 and k3. Amazon SES and Postfjord make long random selectors for each domain, which you find in their setup screens.
Why does my SPF record fail with too many lookups?
Each service you include can include others, and they all count toward a limit of 10. When you go over, the inbox stops checking and SPF fails. Remove services you no longer use, or ask a service if it can send from its own subdomain.
Is p=none safe?
It is safe for your email, because nothing is blocked. It does not protect your name, though: email that fails still arrives. Use it for a few weeks while you read the reports, then move to quarantine.
Does the checker send my domain to Postfjord?
No. Your browser asks Cloudflare's public DNS for the records, and the checker reads the answers in your browser. Nothing is sent to Postfjord or saved.
Can Postfjord send email from my domain?
Yes. With postmail, your campaigns and automations can come from an address on your own domain on every paid plan. You add three records, and Postfjord checks them and tells you when the domain is ready. How it works