Set up your sending domain: SPF, DKIM and DMARC

Before your first issue goes out from your own domain, three DNS records tell Gmail, Yahoo and Outlook that we are allowed to send for you. Here is what each one does, how to check it worked, and what to do if you already have an SPF record.

For mail sent in your name to reach the inbox and not the spam folder, inbox providers need to see that your domain has authorized us to send for it. That is done once per sending domain, with three DNS records, whether you send from the editor or through the API.

You do not have to work this out alone. Email us the domain you want to send from and who manages its DNS. We send you the exact values, confirm they took effect, and stay with you until delivery is clean. This page explains what you are setting up, so you know what each record is for.

The three records

RecordWhat it tells the inbox providerWithout it
SPFWhich servers may send mail for this domainYour mail looks like someone impersonating you, and lands in spam or bounces
DKIMA signature proving the message came from us and was not changed on the wayNo proof of origin, and your domain's reputation does not build up
DMARCWhat to do with a message that fails SPF or DKIM, and where to reportGmail and Yahoo in particular are strict with domains that have none

What the records look like

Mail goes out from a dedicated subdomain called sender under your domain, so your mailings do not affect the reputation of your everyday office mail.

; DMARC
Type:  TXT
Name:  _dmarc
Value: v=DMARC1; p=none

; SPF (on the sender subdomain)
Type:  TXT
Name:  sender
Value: v=spf1 include:msr10.com ~all

; DKIM and infrastructure records
Type:  CNAME / A / MX
Name:  sender  (plus several _domainkey records)
Value: sent to you by our support team

The DKIM and infrastructure values are different for every customer, so we send you the full list for your domain. p=none in DMARC is a deliberate starting point: it collects reports without rejecting mail, and can be tightened step by step later.

How to check the records took effect

DNS changes are not instant: minutes with most providers, up to 24 hours with some. Three ways to check, from easiest to most thorough:

1. Send yourself a test. Send a message from your account to your Gmail address, open it, and choose Show original from the message menu. At the top you will see SPF, DKIM and DMARC. All three should say PASS. This is the test that counts, because it shows exactly what the inbox provider saw.

2. Look the record up. From a command line, nslookup -type=TXT sender.yourdomain.com shows SPF and nslookup -type=TXT _dmarc.yourdomain.com shows DMARC. An empty answer means the record is missing or saved under the wrong name.

3. Ask us. Email us the domain name. We check the records from our side and tell you what is missing or wrong, including things that are hard to spot yourself, like a duplicate SPF record.

Four mistakes we see again and again

Two SPF records on the same name. Only one is allowed. If you already have one, for Google Workspace or Microsoft 365 for example, do not add a second: add our include inside the existing record.

The full domain typed into the name field. Many DNS panels add the domain for you. If you type sender.yourdomain.com instead of sender, the record ends up as sender.yourdomain.com.yourdomain.com and never works. Check how the name looks after saving.

Quotes or a trailing space in the value. Copying from an email sometimes brings them along. Save the value exactly as we sent it.

Editing DNS in the wrong place. Your DNS is not always managed where you bought the domain. If nothing changes after a day, you are probably editing a panel that is not in charge of the domain.

Once the records are right

Correct records are required, not a guarantee. A new domain that starts sending large volumes in one day looks suspicious even with perfect SPF and DKIM. That is why we warm up your domain ourselves and raise the volume gradually.

Questions

How long until the records take effect?

With most DNS providers, minutes. With some, up to 24 hours. The test that counts is sending yourself a message and checking in Gmail's Show original that SPF, DKIM and DMARC all say PASS.

I already have an SPF record from Google or Microsoft. What do I do?

Do not add a second one. A name may have only one SPF record, so the extra include goes inside the existing record. If you are not sure, send us your current record and we will send back the combined version.

Why send from a sender subdomain and not my main domain?

So your mailings do not affect the reputation of your everyday office mail. A problem with a campaign will not hurt the mail your staff send from the main domain, and each builds its own reputation.

What does p=none in DMARC mean?

It tells inbox providers not to reject messages that fail, only to report them. It is a deliberate starting point, so you can confirm everything works without risking real mail, and tighten it gradually later.

Can I send without setting up DNS at all?

Technically yes, but delivery will be poor: Gmail and Yahoo are strict with unauthenticated domains, and your issues will land in spam or bounce. If you would rather not touch DNS, ask us about a managed sending domain.

The records are correct but mail still goes to spam.

Authentication is required, not sufficient. A new domain needs gradual warm-up, which we do for you, and a list with bad addresses produces bounces that hurt reputation. Send us the domain and we will check which applies.

Want the records for your domain?

Email us the domain and who manages its DNS, and we will send the exact values and check them with you.

Email support
This site is operated by Meser-Eser Ltd. (Meser 10), an Israeli email and SMS marketing platform. Company no. 514381128.