{{ROBOTS}}
validmailbox
{{AD_TOP}}

SPF, DKIM and DMARC record generator

Pick your mail host, paste your DKIM key, and get three correctly formatted TXT records plus a zone file block. Lookup limits and policy mistakes are flagged before you publish.

SPF

Every other service that sends as this domain.

IPv4 and IPv6 are detected automatically.

DKIM

Paste the key as your provider shows it. PEM headers, line breaks and a leading p= are stripped.

DMARC

What these three records do

Email authentication answers one question for the receiving server: is this message really from the domain it claims? SPF, DKIM and DMARC answer it in three different ways, and a receiver wants all three to agree. Since 2024 both Google and Yahoo require all three from anyone sending bulk mail to their users, so this is no longer optional configuration for a serious sender.

SPF: which servers may send

A Sender Policy Framework record is a TXT record on the domain itself that lists authorised sending sources, using include mechanisms for services and ip4 or ip6 mechanisms for your own servers. It ends with a policy: ~all soft fails anything not listed, -all hard fails it, and ?all is neutral. Two rules break SPF more often than anything else. First, a domain may publish exactly one SPF record; two records is a permanent error and the check fails entirely. Second, evaluating the record may cost at most ten DNS lookups, and each include counts, including the ones nested inside your provider's record. The generator counts your lookups and warns you as you approach the limit.

DKIM: a signature on the message

DomainKeys Identified Mail attaches a cryptographic signature to each outgoing message. The private key lives with your mail provider; the public key is published in DNS at selector._domainkey.yourdomain.com. The selector is an arbitrary label that lets one domain hold several keys at once, which is how you rotate a key or run two providers in parallel. The record value declares the version, the key algorithm and the key itself. Providers differ in how they publish it: Google Workspace and Zoho give you a TXT record to paste, while SendGrid, Amazon SES and Microsoft 365 typically ask for CNAME records that point at keys they manage for you.

DMARC: what to do when the others fail

DMARC ties SPF and DKIM to the visible From address through alignment, and tells receivers what to do when neither aligns. It is published at _dmarc.yourdomain.com. The policy starts at p=none, which changes nothing about delivery but starts the flow of aggregate reports to your rua address. Those reports are the whole point of the none stage: they show every source sending as your domain, including the CRM, the invoicing tool and the helpdesk you forgot about. Once every legitimate source passes, move to quarantine, then to reject. Relaxed alignment accepts a subdomain match, which is usually what you want; strict requires an exact match.

Publishing and verifying

Add each record in your DNS panel as a TXT record. Some panels want the full host name and some want only the label, appending the domain themselves, so check how an existing record is stored before you save. Propagation usually takes minutes but can take up to the previous record's TTL. Verify with dig TXT yourdomain.com and dig TXT _dmarc.yourdomain.com, or the equivalent lookup tool, rather than assuming the panel saved what you typed.

Generated locally

Every record on this page is assembled in your browser from what you type. No domain, key or report address is sent to a server or stored.

{{AD_RAIL}}
{{AD_BOTTOM}}