How to Set Up SPF, DKIM, and DMARC Records

Configure the three core email authentication DNS records to prove your mail is genuine and improve deliverability.

· Updated · 3,873 views

SPF, DKIM, and DMARC are DNS records that prove your email is legitimate and not spoofed. Together they reduce spam filtering and protect your domain from being forged.

What Each Record Does

  • SPF lists the servers allowed to send mail for your domain.
  • DKIM adds a cryptographic signature that proves a message was not altered.
  • DMARC tells receiving servers what to do when SPF or DKIM checks fail.

Add the Records in cPanel

  1. Open the Zone Editor (or Email Deliverability) in cPanel.
  2. cPanel can often generate and install SPF and DKIM automatically. Click Manage next to your domain and apply any suggested records.
  3. To add manually, create TXT records in the Zone Editor.

Example records:

SPF   @     TXT   v=spf1 +mx +a +include:yourdomain.com ~all
DKIM  default._domainkey  TXT  v=DKIM1; k=rsa; p=PUBLICKEY
DMARC _dmarc  TXT  v=DMARC1; p=quarantine; rua=mailto:postmaster@yourdomain.com

Verify

  • Use the Email Deliverability page in cPanel to confirm all three show as valid.
  • DNS changes can take up to 24 hours to propagate.

Tips

  • Start DMARC with p=none to monitor, then move to p=quarantine or p=reject once confident.
  • Keep only one SPF record per domain; multiple SPF records cause failures.

For help generating the exact records for your setup, reach us on WhatsApp at +254 796 358081.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.