SPF, DKIM & DMARC Setup
SPF, DKIM and DMARC together tell receiving mail servers which servers are
allowed to send mail for your domain, sign outgoing mail so it can't be
tampered with in transit, and tell receivers what to do when a message fails
those checks. Getting the trio right avoids mail landing in spam — and,
once DMARC is set to reject, stops most spoofing of your domain.
Where to find these wizards
Open your zone (Zones → [your domain] → Records) and use the Wizards bar above the record table. Each wizard opens a modal, builds the correct record content for you, and creates it in one step.

1. SPF
SPF (Sender Policy Framework) lists which mail servers may send as your domain, as a single TXT record at the zone apex.

The wizard writes one TXT record on @. If you add more senders
later (e.g. a new mailing tool), edit that same record — a domain must
have only one SPF record, so don't create a second one.
2. DKIM
DKIM adds a cryptographic signature to outgoing mail, published as a TXT record
under a selector subdomain (e.g. default._domainkey.example.com).
The selector and public key come from your mail provider (Google Workspace,
Microsoft 365, your mail server's DKIM key generator, etc.) — the wizard
doesn't generate keys, it publishes the ones you already have.

3. DMARC
DMARC tells receivers what to do when SPF or DKIM fails, and where to send
aggregate reports. It's a TXT record on _dmarc.

Roll out DMARC in stages, don't jump straight to enforcement:
- p=none — monitor only. Point
ruaat a mailbox or reporting tool and watch for a few weeks. - p=quarantine — once reports show only your real mail servers, start sending failures to spam.
- p=reject — once you're confident nothing legitimate is failing, block spoofed mail outright.
Verify from the command line
Once the records are live, confirm them directly against PrimeDNS's nameservers:
dig @ns1.primedns.net example.com TXT +short
dig @ns1.primedns.net default._domainkey.example.com TXT +short
dig @ns1.primedns.net _dmarc.example.com TXT +short
Or fetch them via the API:
curl "https://api.primedns.net/v1/dns/records?domain=example.com" \
-H "X-API-Key: pdns_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" | grep -A2 TXT
Troubleshooting
- Two SPF records — mail servers only read one; merge them into a single TXT with all senders instead of creating a second record.
- DMARC reports not arriving — if
ruapoints at a mailbox on a different domain, that domain needs its own authorization record (_report._dmarc.yourdomain.comTXT) or reports will be silently dropped by the receiving side. - DKIM signature fails — usually the selector or key was copied with a line break or trailing space; re-paste from your provider's raw value.