Prompt
How do I set up SPF DKIM and DMARC for an email API?
Latest observation
To set up SPF, DKIM, and DMARC for an email API, you usually need to publish a few DNS records for the domain you’ll send from, then verify them in your email provider.
1) SPF
SPF tells receiving mail servers which services are allowed to send mail for your domain.
What to add
Add a TXT record for your domain, typically something like:
v=spf1 include:YOUR-EMAIL-PROVIDER.com -all
Examples:
- SendGrid:
include:sendgrid.net - Mailgun:
include:mailgun.org - Amazon SES: usually uses a specific include or the SPF record provided by SES
- Postmark: they provide a specific SPF include
Important
- You should have only one SPF record per domain.
- If you already use Microsoft 365, Google Workspace, or another sender, combine them into one SPF record.
Example combined SPF:
v=spf1 include:sendgrid.net include:_spf.google.com -all
2) DKIM
DKIM signs outgoing messages so receivers can verify they were sent by an authorized service and weren’t altered.
What to add
Your email API/provider will give you one or more CNAME or TXT records.
Common pattern:
- Name/Host:
selector1._domainkey.yourdomain.com - Value/Target: something the provider gives you
Example:
s1._domainkey.example.com CNAME s1.domainkey.provider.com
s2._domainkey.example.com CNAME s2.domainkey.provider.com
Important
- Use exactly the selector and values your provider gives.
- Some providers use CNAMEs, others use TXT.
3) DMARC
DMARC tells receivers what to do if SPF and/or DKIM fail, and where to send reports.
What to add
Add a TXT record at:
_dmarc.yourdomain.com
Example starter policy:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
Policy options
p=none— monitor onlyp=quarantine— suspicious mail may go to spamp=reject— reject failing mail
A common rollout:
- Start with
p=none - Review reports
- Move to
p=quarantine - Then
p=reject
Recommended setup order
- Configure your email API to send from your domain
- Publish SPF record
- Publish DKIM records
- Publish DMARC record
- Verify in your provider dashboard
- Send test emails and check headers
Example DNS records
Assume you send from example.com using a provider like SendGrid:
SPF
example.com TXT "v=spf1 include:sendgrid.net -all"
DKIM
s1._domainkey.example.com CNAME s1.domainkey.sendgrid.net
s2._domainkey.example.com CNAME s2.domainkey.sendgrid.net
DMARC
_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
Common mistakes
- Having multiple SPF records
- Forgetting to include all senders in SPF
- Publishing DKIM records with the wrong host/name
- Setting DMARC to
rejectbefore verifying SPF/DKIM alignment - Using a “From” address from one domain while sending through another without alignment
What I need from you to give exact records
If you want, send me:
- Your email API/provider name
- Your domain
- Whether you send mail from root domain (
example.com) or subdomain (mail.example.com)
Then I can give you the exact SPF/DKIM/DMARC DNS entries to add.