Skip to content
TECHNOARTH Technology in practice.
Security

How to set up SPF, DKIM and DMARC for your domain

The three DNS records that get your email into the inbox and stop scammers from using your domain. A practical guide with examples for Google Workspace, Microsoft 365 and Hostinger.

If your company’s email lands in spam, or someone has received a fake message “sent” from your domain, the cause is almost always three missing DNS records: SPF, DKIM and DMARC. They prove to mailbox providers (Gmail, Outlook, Yahoo and others) that a message really came from a server you authorized.

Since 2024, Gmail and Yahoo require authentication from every sender, and bulk senders need all three records. In practice, they are now mandatory for any business that relies on email.

In this article
  1. What each record does
  2. Before you start
  3. Step 1: set up SPF
  4. Step 2: turn on DKIM
  5. Step 3: publish DMARC
  6. Step 4: verify your setup
  7. Common errors
  8. FAQ

What each record does

RecordWhat it checksWhere it lives in DNS
SPFWhich servers may send email for your domainTXT at the domain root
DKIMWhether the message was signed by your domain and not alteredTXT or CNAME at selector._domainkey
DMARCWhat to do when SPF and DKIM fail, and where to send reportsTXT at _dmarc

Before you start

  • Access to the dashboard where your domain’s DNS is managed (Cloudflare, your registrar, Hostinger, GoDaddy, etc.).
  • A list of every service that sends email on behalf of your domain: mailbox provider, invoicing system, CRM, email marketing tool, website.

Step 1: set up SPF

SPF is a single TXT record at the domain root that lists who is allowed to send. Use your provider’s include:

ProviderSPF snippet
Google Workspaceinclude:_spf.google.com
Microsoft 365include:spf.protection.outlook.com
Hostingerinclude:_spf.mail.hostinger.com

Example for a company using Microsoft 365 plus an email marketing service:

v=spf1 include:spf.protection.outlook.com include:marketing-service.com ~all
  1. In your DNS dashboard, create (or edit) a TXT record with host @ (root) and the value above, adapted to your services.
  2. End it with ~all (soft fail) while testing. Once everything checks out, you can switch to -all (hard fail).

Step 2: turn on DKIM

DKIM is generated by your email provider, which creates a key pair and tells you which record to publish.

  • Google Workspace: in the Admin console, go to Apps › Google Workspace › Gmail › Authenticate email, generate a 2048-bit key and publish the google._domainkey TXT record shown. Then come back and click Start authentication.
  • Microsoft 365: in the Microsoft Defender portal, open the email authentication settings (DKIM section), select your domain and publish the two CNAME records shown (selector1._domainkey and selector2._domainkey). Then enable signing.
  • Hostinger: in hPanel, the email settings for your domain show the authentication records (including DKIM) for you to copy. If your DNS is hosted at Hostinger, they are usually created automatically.

Repeat for every service that sends as your domain (email marketing, CRM): each one provides its own DKIM record.

Step 3: publish DMARC

Create a TXT record with host _dmarc. Start in monitoring mode:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; fo=1
  • p=none: blocks nothing, only generates reports.
  • rua=: the address that will receive daily reports from mailbox providers.

Watch the reports for a few weeks. Once every legitimate service shows SPF or DKIM passing, tighten the policy gradually:

  1. p=quarantine; pct=25 — sends 25% of unauthenticated messages to spam.
  2. p=quarantine — applies to all of them.
  3. p=reject — rejects spoofed messages. This is full protection against domain spoofing.
DNS panel with the SPF (root TXT), DKIM (selector1 and selector2 CNAME) and DMARC (_dmarc TXT) records highlighted
Microsoft 365 example: SPF (1), the two DKIM CNAMEs (2) and DMARC (3). Field names vary by DNS provider.

Step 4: verify your setup

After publishing, wait a few minutes (some DNS providers take a few hours) and check from a terminal:

Command
nslookup -type=txt yourdomain.com
nslookup -type=txt _dmarc.yourdomain.com
nslookup -type=txt google._domainkey.yourdomain.com

Then send an email to a Gmail account, open it and click ⋮ › Show original.

Common errors

FAQ

Do I need all three records, or just SPF?

All three. SPF alone doesn’t protect the visible “From” address and doesn’t survive forwarding. DKIM signs the message, and DMARC tells providers what to do when something fails.

Can I start with p=reject?

It’s not recommended. Start with p=none, use the reports to find every service sending on your behalf, and only then move to quarantine and reject. Skipping steps can block legitimate email such as invoices.

Everything is set up but my email still goes to spam. Now what?

Authentication is a prerequisite, not a guarantee. Domain and IP reputation, message content, complaint rates and outdated contact lists also affect delivery.

Share

About the author

TECHNOARTH Editorial Team

The TECHNOARTH newsroom: technology tutorials, guides, comparisons and news produced with AI assistance and checked against manufacturers’ official sources.