What you’ll need
- DirectAdmin access
- A working mailbox on your domain
- A Gmail address to test with
SPF says which servers may send your mail, DKIM signs each message, and DMARC ties them to your From address. Doing them in order lets you check each one before moving on. SPF, DKIM and DMARC explained
Before you begin: These steps assume your nameservers point to Traxio. If your DNS is elsewhere, make the DNS changes at your provider instead. SPF, DKIM and DMARC when your DNS isn’t at Traxio
Steps
Step 1: List everything that sends as your domain
Traxio mailboxes and your website — plus any newsletter tool, CRM, invoicing app or Google/Microsoft service. Each needs to be covered.
Step 2: Check or create SPF
In Account Manager then DNS Management, find the TXT record on your domain beginning
v=spf1. For mail sent only through Traxio,v=spf1 a mx ~allis typical. Add each extra service’sinclude:to this one record. How to set up an SPF recordStep 3: Enable DKIM
Open E-mail Manager then E-mail Accounts and select Enable DKIM for the domain. Confirm a TXT record named
x._domainkeynow appears in Account Manager then DNS Management. How to enable DKIM in DirectAdminStep 4: Test SPF and DKIM
Send a message from your mailbox to Gmail. Open it, choose ⋮ → Show original, and look for
SPF: PASSandDKIM: 'PASS' with domain yourdomain.co.uk.Step 5: Create a mailbox for reports
Create
dmarc@yourdomain.co.ukor choose an existing address to receive DMARC reports.Step 6: Add DMARC in monitoring mode
Add a TXT record named
_dmarcwith:v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.co.ukStep 7: Test DMARC
Send another test to Gmail and check Show original now shows
DMARC: 'PASS'.Step 8: Tighten later
After a few weeks of reports showing all legitimate mail passing, change
p=nonetop=quarantine.
Check it worked
Gmail’s Show original shows SPF, DKIM and DMARC all as PASS for a message sent from your mailbox, and a DNS lookup of _dmarc.yourdomain.co.uk returns your record.
If something goes wrong
| What happens | What to do |
|---|---|
| SPF: PERMERROR | Two SPF records, or more than 10 lookups. Merge and trim. How to set up an SPF record |
| DKIM: FAIL | The published key doesn’t match — re-copy it, especially if DNS is elsewhere. |
| DMARC fails but SPF passes | The passing domain doesn’t match your From address — common with third-party senders. Set up that service’s domain authentication. |
| Records don’t appear in lookups | You may be editing DNS that isn’t live. DNS changes not working |