← Docs

SPF, DKIM and DMARC together tell receiving mail servers which servers are allowed to send mail for your domain, sign outgoing mail so it can't be tampered with in transit, and tell receivers what to do when a message fails those checks. Getting the trio right avoids mail landing in spam — and, once DMARC is set to reject, stops most spoofing of your domain.

Where to find these wizards

Open your zone (Zones → [your domain] → Records) and use the Wizards bar above the record table. Each wizard opens a modal, builds the correct record content for you, and creates it in one step.

Records view with the Wizards bar showing SPF, DKIM, DMARC and other one-click record wizards

1. SPF

SPF (Sender Policy Framework) lists which mail servers may send as your domain, as a single TXT record at the zone apex.

SPF wizard modal with mail servers field, policy selector and generated TXT content preview

The wizard writes one TXT record on @. If you add more senders later (e.g. a new mailing tool), edit that same record — a domain must have only one SPF record, so don't create a second one.

2. DKIM

DKIM adds a cryptographic signature to outgoing mail, published as a TXT record under a selector subdomain (e.g. default._domainkey.example.com). The selector and public key come from your mail provider (Google Workspace, Microsoft 365, your mail server's DKIM key generator, etc.) — the wizard doesn't generate keys, it publishes the ones you already have.

DKIM wizard modal with selector and public key fields
Tip: if your provider gives you two DKIM keys ("dual signing" for key rotation), publish both as separate selector records — the wizard supports one record per run, so run it twice.

3. DMARC

DMARC tells receivers what to do when SPF or DKIM fails, and where to send aggregate reports. It's a TXT record on _dmarc.

DMARC wizard modal with policy selector and report email field

Roll out DMARC in stages, don't jump straight to enforcement:

  1. p=none — monitor only. Point rua at a mailbox or reporting tool and watch for a few weeks.
  2. p=quarantine — once reports show only your real mail servers, start sending failures to spam.
  3. p=reject — once you're confident nothing legitimate is failing, block spoofed mail outright.

Verify from the command line

Once the records are live, confirm them directly against PrimeDNS's nameservers:

dig @ns1.primedns.net example.com TXT +short
dig @ns1.primedns.net default._domainkey.example.com TXT +short
dig @ns1.primedns.net _dmarc.example.com TXT +short

Or fetch them via the API:

curl "https://api.primedns.net/v1/dns/records?domain=example.com" \
  -H "X-API-Key: pdns_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" | grep -A2 TXT

Troubleshooting

  • Two SPF records — mail servers only read one; merge them into a single TXT with all senders instead of creating a second record.
  • DMARC reports not arriving — if rua points at a mailbox on a different domain, that domain needs its own authorization record (_report._dmarc.yourdomain.com TXT) or reports will be silently dropped by the receiving side.
  • DKIM signature fails — usually the selector or key was copied with a line break or trailing space; re-paste from your provider's raw value.