Set up SPF, DKIM and DMARC

Authenticate your domain’s email in the right order, and prove each record works using Gmail’s message headers.

IntermediateAbout 30 minutes8 steps

What you’ll need

  • DirectAdmin access
  • A working mailbox on your domain
  • A Gmail address to test with

SPF says which servers may send your mail, DKIM signs each message, and DMARC ties them to your From address. Doing them in order lets you check each one before moving on. SPF, DKIM and DMARC explained

Before you begin: These steps assume your nameservers point to Traxio. If your DNS is elsewhere, make the DNS changes at your provider instead. SPF, DKIM and DMARC when your DNS isn’t at Traxio

Steps

  1. Step 1: List everything that sends as your domain

    Traxio mailboxes and your website — plus any newsletter tool, CRM, invoicing app or Google/Microsoft service. Each needs to be covered.

  2. Step 2: Check or create SPF

    In Account Manager then DNS Management, find the TXT record on your domain beginning v=spf1. For mail sent only through Traxio, v=spf1 a mx ~all is typical. Add each extra service’s include: to this one record. How to set up an SPF record

  3. Step 3: Enable DKIM

    Open E-mail Manager then E-mail Accounts and select Enable DKIM for the domain. Confirm a TXT record named x._domainkey now appears in Account Manager then DNS Management. How to enable DKIM in DirectAdmin

  4. Step 4: Test SPF and DKIM

    Send a message from your mailbox to Gmail. Open it, choose ⋮ → Show original, and look for SPF: PASS and DKIM: 'PASS' with domain yourdomain.co.uk.

  5. Step 5: Create a mailbox for reports

    Create dmarc@yourdomain.co.uk or choose an existing address to receive DMARC reports.

  6. Step 6: Add DMARC in monitoring mode

    Add a TXT record named _dmarc with:

    v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.co.uk

    How to set up a DMARC record

  7. Step 7: Test DMARC

    Send another test to Gmail and check Show original now shows DMARC: 'PASS'.

  8. Step 8: Tighten later

    After a few weeks of reports showing all legitimate mail passing, change p=none to p=quarantine.

Check it worked

Gmail’s Show original shows SPF, DKIM and DMARC all as PASS for a message sent from your mailbox, and a DNS lookup of _dmarc.yourdomain.co.uk returns your record.

If something goes wrong

What happensWhat to do
SPF: PERMERRORTwo SPF records, or more than 10 lookups. Merge and trim. How to set up an SPF record
DKIM: FAILThe published key doesn’t match — re-copy it, especially if DNS is elsewhere.
DMARC fails but SPF passesThe passing domain doesn’t match your From address — common with third-party senders. Set up that service’s domain authentication.
Records don’t appear in lookupsYou may be editing DNS that isn’t live. DNS changes not working

Popular

Tip: press / to search from any pageSee all results