Prompt
How do I add SPF DKIM and DMARC for an email sending API?
Latest observation
To add SPF, DKIM, and DMARC for an email sending API (like SendGrid, Mailgun, Amazon SES, Postmark, etc.), you typically need to configure records in your domain’s DNS so mail sent through the API is authenticated as coming from your domain.
1) SPF
SPF tells receiving mail servers which servers are allowed to send email for your domain.
What to do
Your email provider will give you an SPF record to add as a TXT record in DNS.
Example
v=spf1 include:spf.your-email-provider.com ~all
Important notes
- You should have only one SPF record per domain.
- If you already have one, merge the provider’s
include:into it rather than creating a second SPF record. - Example merge:
v=spf1 include:_spf.google.com include:spf.your-email-provider.com ~all
2) DKIM
DKIM signs outgoing mail with a cryptographic signature so recipients can verify it wasn’t altered and really came from your domain.
What to do
Your provider will usually ask you to add one or more DNS records, often CNAME or TXT records, for DKIM.
Example
You might be asked to add:
selector1._domainkey.yourdomain.comselector2._domainkey.yourdomain.com
These may point to provider-hosted values like:
selector1._domainkey.yourdomain.com CNAME selector1.domainkey.provider.com
Notes
- Most providers generate the DKIM keys for you.
- Some use CNAME records, others use TXT records.
- DNS changes can take time to propagate.
3) DMARC
DMARC tells receiving servers what to do if SPF/DKIM fail and provides reporting.
What to do
Add a TXT record at:
_dmarc.yourdomain.com
Starter example
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
Policy options
p=none— monitor onlyp=quarantine— suspicious mail may go to spamp=reject— reject mail that fails DMARC
Suggested rollout
- Start with
p=none - Review reports
- Move to
p=quarantine - Then to
p=rejectwhen confident
4) Also set the “From” domain correctly
For authentication to work well:
- The From address should use your domain, like
noreply@yourdomain.com - If your API allows it, set a custom return-path / bounce domain too
- Avoid sending from a mismatch domain (like
from@gmail.comvia your API)
5) Typical setup process
- Verify your domain with the email provider
- Add SPF TXT record
- Add DKIM CNAME/TXT records
- Add DMARC TXT record
- Wait for DNS propagation
- Test by sending mail and checking headers/authentication results
6) How to check if it works
Send a test email to Gmail or Outlook and view the message headers. Look for:
spf=passdkim=passdmarc=pass
You can also use tools like:
- MXToolbox
- Google Postmaster Tools
- Your provider’s domain authentication checker
7) Example DNS records
Here’s a generic example:
SPF
yourdomain.com TXT "v=spf1 include:spf.emailprovider.com ~all"
DKIM
s1._domainkey.yourdomain.com CNAME s1.domainkey.emailprovider.com
s2._domainkey.yourdomain.com CNAME s2.domainkey.emailprovider.com
DMARC
_dmarc.yourdomain.com TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com"
If you tell me which email API/provider you’re using and your DNS host (Cloudflare, Route 53, GoDaddy, etc.), I can give you the exact records to add.