Set up your sending domain: SPF, DKIM and DMARC
Before your first issue goes out from your own domain, three DNS records tell Gmail, Yahoo and Outlook that we are allowed to send for you. Here is what each one does, how to check it worked, and what to do if you already have an SPF record.
For mail sent in your name to reach the inbox and not the spam folder, inbox providers need to see that your domain has authorized us to send for it. That is done once per sending domain, with three DNS records, whether you send from the editor or through the API.
The three records
| Record | What it tells the inbox provider | Without it |
|---|---|---|
| SPF | Which servers may send mail for this domain | Your mail looks like someone impersonating you, and lands in spam or bounces |
| DKIM | A signature proving the message came from us and was not changed on the way | No proof of origin, and your domain's reputation does not build up |
| DMARC | What to do with a message that fails SPF or DKIM, and where to report | Gmail and Yahoo in particular are strict with domains that have none |
What the records look like
Mail goes out from a dedicated subdomain called sender under your domain, so your mailings do not affect the reputation of your everyday office mail.
; DMARC Type: TXT Name: _dmarc Value: v=DMARC1; p=none ; SPF (on the sender subdomain) Type: TXT Name: sender Value: v=spf1 include:msr10.com ~all ; DKIM and infrastructure records Type: CNAME / A / MX Name: sender (plus several _domainkey records) Value: sent to you by our support team
The DKIM and infrastructure values are different for every customer, so we send you the full list for your domain. p=none in DMARC is a deliberate starting point: it collects reports without rejecting mail, and can be tightened step by step later.
How to check the records took effect
DNS changes are not instant: minutes with most providers, up to 24 hours with some. Three ways to check, from easiest to most thorough:
1. Send yourself a test. Send a message from your account to your Gmail address, open it, and choose Show original from the message menu. At the top you will see SPF, DKIM and DMARC. All three should say PASS. This is the test that counts, because it shows exactly what the inbox provider saw.
2. Look the record up. From a command line, nslookup -type=TXT sender.yourdomain.com shows SPF and nslookup -type=TXT _dmarc.yourdomain.com shows DMARC. An empty answer means the record is missing or saved under the wrong name.
3. Ask us. Email us the domain name. We check the records from our side and tell you what is missing or wrong, including things that are hard to spot yourself, like a duplicate SPF record.
Four mistakes we see again and again
Two SPF records on the same name. Only one is allowed. If you already have one, for Google Workspace or Microsoft 365 for example, do not add a second: add our include inside the existing record.
The full domain typed into the name field. Many DNS panels add the domain for you. If you type sender.yourdomain.com instead of sender, the record ends up as sender.yourdomain.com.yourdomain.com and never works. Check how the name looks after saving.
Quotes or a trailing space in the value. Copying from an email sometimes brings them along. Save the value exactly as we sent it.
Editing DNS in the wrong place. Your DNS is not always managed where you bought the domain. If nothing changes after a day, you are probably editing a panel that is not in charge of the domain.
Once the records are right
Correct records are required, not a guarantee. A new domain that starts sending large volumes in one day looks suspicious even with perfect SPF and DKIM. That is why we warm up your domain ourselves and raise the volume gradually.
Questions
How long until the records take effect?
With most DNS providers, minutes. With some, up to 24 hours. The test that counts is sending yourself a message and checking in Gmail's Show original that SPF, DKIM and DMARC all say PASS.
I already have an SPF record from Google or Microsoft. What do I do?
Do not add a second one. A name may have only one SPF record, so the extra include goes inside the existing record. If you are not sure, send us your current record and we will send back the combined version.
Why send from a sender subdomain and not my main domain?
So your mailings do not affect the reputation of your everyday office mail. A problem with a campaign will not hurt the mail your staff send from the main domain, and each builds its own reputation.
What does p=none in DMARC mean?
It tells inbox providers not to reject messages that fail, only to report them. It is a deliberate starting point, so you can confirm everything works without risking real mail, and tighten it gradually later.
Can I send without setting up DNS at all?
Technically yes, but delivery will be poor: Gmail and Yahoo are strict with unauthenticated domains, and your issues will land in spam or bounce. If you would rather not touch DNS, ask us about a managed sending domain.
The records are correct but mail still goes to spam.
Authentication is required, not sufficient. A new domain needs gradual warm-up, which we do for you, and a list with bad addresses produces bounces that hurt reputation. Send us the domain and we will check which applies.
Want the records for your domain?
Email us the domain and who manages its DNS, and we will send the exact values and check them with you.
Email support