SPF, DKIM and DMARC are three free DNS records that tell Gmail, Outlook and Yahoo which servers may send email for your domain, and what to do with emails that fail the check. Without them, anyone can send a fake invoice or "change of bank account" email that looks like it came from accounts@yourcompany.in. Run our free scanner to see which of the three your domain has, then use the copy-paste examples below for your DNS panel.
SPF, DKIM and DMARC explained simply
| Record | What it does (simple version) | Where it lives |
|---|---|---|
| SPF | A guest list: "only these mail services may send email for my domain". | TXT record on your main domain (@) |
| DKIM | A tamper-proof seal: your mail service signs every email, and receivers check the signature with a public key in your DNS. | TXT (sometimes CNAME) record at selector._domainkey |
| DMARC | The instruction: "if an email claiming to be from me fails SPF/DKIM, do nothing / send to spam / reject it, and send me reports". | TXT record at _dmarc |
SPF and DKIM alone don't stop spoofing of the "From" address that people actually see. DMARC connects them to that visible address, which is why it matters most.
Why this matters now: Gmail, Yahoo and Outlook rules
Since February 2024, Google's email sender guidelines require everyone sending to Gmail addresses to have SPF or DKIM, valid reverse DNS, TLS, and a spam complaint rate below 0.3%. Anyone sending more than 5,000 messages a day to personal Gmail accounts must also have SPF and DKIM, a DMARC record (a p=none policy is enough), "From" domain alignment, and one-click unsubscribe on marketing mail. Yahoo announced matching rules, and Microsoft began enforcing similar rules for Outlook.com and Hotmail from 5 May 2025. According to Red Sift's bulk sender guide, Gmail moved from warnings to outright rejection of non-compliant bulk mail from November 2025.
Even if you send only a few hundred emails a day, missing records mean more of your quotations and invoices land in spam.
Why it matters in India
Fake-invoice and "our bank account has changed" emails are a common way Indian businesses lose money. DMARC is one of the few free, technical controls against them. Adoption is uneven: a Red Sift study reported by BetaNews (February 2025) found India was the only major country where DMARC adoption did not increase during 2024. Red Sift's adoption guide shows large listed Indian companies doing well, but notes that private-sector adoption is still in its infancy. In our experience, most small business domains have SPF at best and no DMARC at all.
How to check your SPF, DKIM and DMARC
- Enter your website address in our free website security scanner. The report shows whether SPF and DMARC exist, whether SPF is valid (only one record, not too many lookups) and how strict your DMARC policy is, with plain-English fixes.
- To check DKIM yourself, send an email from your domain to a Gmail address, open it, click the three dots → Show original. You should see
SPF: PASS,DKIM: PASSandDMARC: PASS.
Step 1: find where your DNS is managed
This is where most people get stuck. Your DNS is managed wherever your domain's nameservers point, which is not always where you bought the domain. If you bought the domain at GoDaddy or BigRock but your nameservers point to Hostinger or your cPanel host, you must add the records at the host. Panel menus change from time to time, but currently:
- GoDaddy: Sign in → My Products → your domain → DNS → Add New Record. Type: TXT.
- Hostinger (hPanel): Domains → select your domain → DNS / Nameservers → manage DNS records → choose TXT.
- BigRock: Manage Orders → List/Search Orders → click your domain → DNS Management → Manage DNS → TXT Records → Add TXT Record.
- cPanel hosting: cPanel → Zone Editor (and Email Deliverability for email records).
In the "Name/Host" box, use @ for your main domain (some panels want the field left blank) and _dmarc for the DMARC record. Don't type your full domain name unless the panel asks for it.
Step 2: add the right SPF and DKIM for your email provider
Google Workspace
- SPF (TXT, host
@):v=spf1 include:_spf.google.com ~all— this is the value in Google's SPF setup guide. - DKIM: Google Admin console → Apps → Google Workspace → Gmail → Authenticate email → Generate new record. Add the TXT record it gives you (host usually
google._domainkey), wait, then click Start authentication.
Zoho Mail
- Zoho has separate data centres, and most Indian accounts (those that log in at
mail.zoho.in) are on the India one. Copy the SPF value shown in your Zoho Mail Admin Console under your domain's email configuration. For India accounts this is an India-specific include such asv=spf1 include:zoho.in ~all(some newer setups showinclude:zohomail.in; both are published by Zoho). Zoho's global help page showsinclude:zohomail.com, which is for accounts on its globalzoho.comdata centre. - DKIM: Admin Console → Domains → your domain → Email Configuration → DKIM → add a selector (for example
zmail), add the TXT record atzmail._domainkey, then click Verify and enable it.
cPanel email (email that comes with your hosting)
- Open cPanel → Email Deliverability. It shows the suggested SPF and DKIM records for your server and a Repair or Manage button. If your DNS is on the same host, it can fix them for you. If DNS is elsewhere (for example GoDaddy), copy the suggested values there.
- The cPanel SPF usually includes your server's IP address, for example
v=spf1 +a +mx +ip4:203.0.113.10 ~all(your IP will be different).
Using more than one service?
Combine everything into one SPF record. Example for Google Workspace plus a newsletter tool: v=spf1 include:_spf.google.com include:servers.mcsv.net ~all. Two separate v=spf1 records will make SPF fail. SPF also allows a maximum of 10 DNS lookups, so remove services you no longer use. Don't forget your website's contact form, billing software or CRM if they send email "from" your domain; each needs to be in SPF or sign with DKIM.
Step 3: add DMARC and roll it out safely
Add a TXT record with host _dmarc:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.in; fo=1
Create the dmarc-reports@ mailbox (or use an existing one on the same domain). Then tighten the policy in stages:
- Weeks 1–4:
p=none— nothing is blocked. Read the daily reports (a free DMARC report viewer helps) and find every service that sends mail as you. - Fix anything failing — add missing services to SPF or set up DKIM for them.
- Next:
p=quarantine; pct=25— a quarter of failing mail goes to spam. Increase topct=100over a few weeks if nothing genuine breaks. - Finally:
p=reject— fake emails using your domain are refused. This is the goal.
Domains you don't use for email
If a domain never sends email, lock it down completely: SPF v=spf1 -all and DMARC v=DMARC1; p=reject;. Scammers like unused domains because nobody is watching them.
Once your records are in place, re-run the scanner to confirm. If staff or customers are receiving fake emails or links, our guide to checking links helps them spot the scam. If your website itself has been sending spam, see is my website hacked?
Frequently asked questions
Can I have two SPF records on one domain?
No. A domain must have only one SPF (v=spf1) TXT record. If you use two services, such as Google Workspace and Zoho Campaigns, combine them into one record with two include: entries.
Will adding DMARC stop my emails from being delivered?
Not if you start with p=none. That policy only collects reports and does not block anything. Move to quarantine and reject only after the reports show all your genuine senders pass.
Do small businesses that send few emails need DMARC?
Yes. Google's strict DMARC rule is for bulk senders, but any domain can be spoofed. A DMARC record is free and makes fake emails in your company name much easier for Gmail and others to block.
How long do DNS changes take?
Usually a few minutes to an hour on GoDaddy, Hostinger and BigRock, but some changes can take up to 24–48 hours to be seen everywhere.
What is the difference between ~all and -all in SPF?
~all (soft fail) tells receivers that unlisted servers are probably not you; -all (hard fail) says they are definitely not you. Many providers suggest ~all while you are setting up and DMARC then decides what happens to failing mail.
This guide is general information, not legal advice. If you have lost money to fraud, call 1930 immediately or report at cybercrime.gov.in.