SPF, DKIM and DMARC record generator
Pick your mail host, paste your DKIM key, and get three correctly formatted TXT records plus a zone file block. Lookup limits and policy mistakes are flagged before you publish.
What these three records do
Email authentication answers one question for the receiving server: is this message really from the domain it claims? SPF, DKIM and DMARC answer it in three different ways, and a receiver wants all three to agree. Since 2024 both Google and Yahoo require all three from anyone sending bulk mail to their users, so this is no longer optional configuration for a serious sender.
SPF: which servers may send
A Sender Policy Framework record is a TXT record on the domain itself that lists authorised sending
sources, using include mechanisms for services and ip4 or ip6 mechanisms for your own servers. It ends
with a policy: ~all soft fails anything not listed, -all hard fails it, and
?all is neutral. Two rules break SPF more often than anything else. First, a domain may
publish exactly one SPF record; two records is a permanent error and the check fails entirely. Second,
evaluating the record may cost at most ten DNS lookups, and each include counts, including the ones
nested inside your provider's record. The generator counts your lookups and warns you as you approach
the limit.
DKIM: a signature on the message
DomainKeys Identified Mail attaches a cryptographic signature to each outgoing message. The private
key lives with your mail provider; the public key is published in DNS at
selector._domainkey.yourdomain.com. The selector is an arbitrary label that lets one
domain hold several keys at once, which is how you rotate a key or run two providers in parallel. The
record value declares the version, the key algorithm and the key itself. Providers differ in how they
publish it: Google Workspace and Zoho give you a TXT record to paste, while SendGrid, Amazon SES and
Microsoft 365 typically ask for CNAME records that point at keys they manage for you.
DMARC: what to do when the others fail
DMARC ties SPF and DKIM to the visible From address through alignment, and tells receivers what to do
when neither aligns. It is published at _dmarc.yourdomain.com. The policy starts at
p=none, which changes nothing about delivery but starts the flow of aggregate reports to
your rua address. Those reports are the whole point of the none stage: they show every source sending
as your domain, including the CRM, the invoicing tool and the helpdesk you forgot about. Once every
legitimate source passes, move to quarantine, then to reject. Relaxed alignment accepts a subdomain
match, which is usually what you want; strict requires an exact match.
Publishing and verifying
Add each record in your DNS panel as a TXT record. Some panels want the full host name and some want
only the label, appending the domain themselves, so check how an existing record is stored before you
save. Propagation usually takes minutes but can take up to the previous record's TTL. Verify with
dig TXT yourdomain.com and dig TXT _dmarc.yourdomain.com, or the equivalent
lookup tool, rather than assuming the panel saved what you typed.
Generated locally
Every record on this page is assembled in your browser from what you type. No domain, key or report address is sent to a server or stored.