Prompt

How do I set up SPF DKIM and DMARC for an app sending from my domain?

Technology / API Platforms1 observationLast seen Oct 9, 2026

Latest observation

Oct 9, 2026OpenAI APIWeb search: off

To set up SPF, DKIM, and DMARC for an app that sends email from your domain, you’ll usually do this in your DNS and your email-sending app/service.

1) SPF

SPF tells receiving mail servers which servers are allowed to send mail for your domain.

What to add

Create or update a TXT record for your domain, like:

v=spf1 include:YOUR-EMAIL-SERVICE.com -all

Examples:

  • SendGrid: include:sendgrid.net
  • Mailgun: include:mailgun.org
  • Amazon SES: usually a custom SPF or include depending on setup

Notes

  • You should have only one SPF record per domain.
  • If you already have one, merge the new sender into the existing record.
  • -all means “hard fail” for anything not listed.

2) DKIM

DKIM signs outgoing mail so receivers can verify it wasn’t altered and that it really came from your domain.

What to do

Your email provider or app service will give you:

  • a DKIM selector
  • one or more DNS CNAME or TXT records
  • a public key or targets to publish in DNS

Example CNAME records:

selector1._domainkey.yourdomain.com  CNAME  selector1.your-email-service.com
selector2._domainkey.yourdomain.com  CNAME  selector2.your-email-service.com

Or a TXT record with a key like:

selector1._domainkey.yourdomain.com TXT "v=DKIM1; k=rsa; p=PUBLICKEY..."

Notes

  • Use the exact records your provider gives you.
  • After DNS propagates, enable DKIM signing in the app/service dashboard.

3) DMARC

DMARC tells receivers what to do if SPF/DKIM fail and where to send reports.

What to add

Create a TXT record at:

_dmarc.yourdomain.com

A common starting policy:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com

Policies

  • p=none = monitor only
  • p=quarantine = send suspicious mail to spam
  • p=reject = reject failing mail

Recommended progression

  1. Start with p=none
  2. Review reports for a while
  3. Move to p=quarantine
  4. Then p=reject

Important alignment rule

For DMARC to pass, either SPF or DKIM must align with the visible From: domain.

Example:

  • From: billing@yourdomain.com
  • SPF may authenticate the envelope sender
  • DKIM should ideally sign with d=yourdomain.com

If the app sends from a third-party domain without alignment, DMARC can fail even if SPF or DKIM technically pass.


Typical setup workflow

  1. Verify which email service your app uses
  2. Add the SPF include they require
  3. Add DKIM DNS records from the provider
  4. Add a DMARC record with p=none
  5. Test by sending to Gmail/Outlook and checking headers
  6. Tighten DMARC policy over time

How to check if it’s working

Send a test email to Gmail and view the original message / headers. Look for:

  • SPF: PASS
  • DKIM: PASS
  • DMARC: PASS

You can also use tools like:

  • MXToolbox
  • mail-tester.com
  • dmarcian

Example DNS records

For yourdomain.com:

@ TXT "v=spf1 include:sendgrid.net -all"

selector1._domainkey CNAME selector1.sendgrid.net
selector2._domainkey CNAME selector2.sendgrid.net

_dmarc TXT "v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com"

If you tell me which app/email provider you’re using (SendGrid, Mailgun, Postmark, SES, etc.) and your domain setup, I can give you the exact DNS records to add.

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as dotdotPR. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.