For businesses

Free SPF, DKIM and DMARC checker and setup guide for Indian domains

SPF, DKIM and DMARC are three DNS records that prove emails from your domain are really from you, so scammers can't easily send fake invoices in your name and Gmail doesn't send your mail to spam. You can check all three for free with our website scanner, then add the missing records in your domain's DNS panel using the examples below.

By the Secuvexa team, I.T. Experts, Gujarat · Updated

SPF, DKIM and DMARC are three free DNS records that tell Gmail, Outlook and Yahoo which servers may send email for your domain, and what to do with emails that fail the check. Without them, anyone can send a fake invoice or "change of bank account" email that looks like it came from accounts@yourcompany.in. Run our free scanner to see which of the three your domain has, then use the copy-paste examples below for your DNS panel.

SPF, DKIM and DMARC explained simply

RecordWhat it does (simple version)Where it lives
SPFA guest list: "only these mail services may send email for my domain".TXT record on your main domain (@)
DKIMA tamper-proof seal: your mail service signs every email, and receivers check the signature with a public key in your DNS.TXT (sometimes CNAME) record at selector._domainkey
DMARCThe instruction: "if an email claiming to be from me fails SPF/DKIM, do nothing / send to spam / reject it, and send me reports".TXT record at _dmarc

SPF and DKIM alone don't stop spoofing of the "From" address that people actually see. DMARC connects them to that visible address, which is why it matters most.

Why this matters now: Gmail, Yahoo and Outlook rules

Since February 2024, Google's email sender guidelines require everyone sending to Gmail addresses to have SPF or DKIM, valid reverse DNS, TLS, and a spam complaint rate below 0.3%. Anyone sending more than 5,000 messages a day to personal Gmail accounts must also have SPF and DKIM, a DMARC record (a p=none policy is enough), "From" domain alignment, and one-click unsubscribe on marketing mail. Yahoo announced matching rules, and Microsoft began enforcing similar rules for Outlook.com and Hotmail from 5 May 2025. According to Red Sift's bulk sender guide, Gmail moved from warnings to outright rejection of non-compliant bulk mail from November 2025.

Even if you send only a few hundred emails a day, missing records mean more of your quotations and invoices land in spam.

Why it matters in India

Fake-invoice and "our bank account has changed" emails are a common way Indian businesses lose money. DMARC is one of the few free, technical controls against them. Adoption is uneven: a Red Sift study reported by BetaNews (February 2025) found India was the only major country where DMARC adoption did not increase during 2024. Red Sift's adoption guide shows large listed Indian companies doing well, but notes that private-sector adoption is still in its infancy. In our experience, most small business domains have SPF at best and no DMARC at all.

How to check your SPF, DKIM and DMARC

  1. Enter your website address in our free website security scanner. The report shows whether SPF and DMARC exist, whether SPF is valid (only one record, not too many lookups) and how strict your DMARC policy is, with plain-English fixes.
  2. To check DKIM yourself, send an email from your domain to a Gmail address, open it, click the three dots → Show original. You should see SPF: PASS, DKIM: PASS and DMARC: PASS.

Step 1: find where your DNS is managed

This is where most people get stuck. Your DNS is managed wherever your domain's nameservers point, which is not always where you bought the domain. If you bought the domain at GoDaddy or BigRock but your nameservers point to Hostinger or your cPanel host, you must add the records at the host. Panel menus change from time to time, but currently:

  • GoDaddy: Sign in → My Products → your domain → DNS → Add New Record. Type: TXT.
  • Hostinger (hPanel): Domains → select your domain → DNS / Nameservers → manage DNS records → choose TXT.
  • BigRock: Manage Orders → List/Search Orders → click your domain → DNS Management → Manage DNS → TXT Records → Add TXT Record.
  • cPanel hosting: cPanel → Zone Editor (and Email Deliverability for email records).

In the "Name/Host" box, use @ for your main domain (some panels want the field left blank) and _dmarc for the DMARC record. Don't type your full domain name unless the panel asks for it.

Step 2: add the right SPF and DKIM for your email provider

Google Workspace

  • SPF (TXT, host @): v=spf1 include:_spf.google.com ~all — this is the value in Google's SPF setup guide.
  • DKIM: Google Admin console → Apps → Google Workspace → Gmail → Authenticate email → Generate new record. Add the TXT record it gives you (host usually google._domainkey), wait, then click Start authentication.

Zoho Mail

  • Zoho has separate data centres, and most Indian accounts (those that log in at mail.zoho.in) are on the India one. Copy the SPF value shown in your Zoho Mail Admin Console under your domain's email configuration. For India accounts this is an India-specific include such as v=spf1 include:zoho.in ~all (some newer setups show include:zohomail.in; both are published by Zoho). Zoho's global help page shows include:zohomail.com, which is for accounts on its global zoho.com data centre.
  • DKIM: Admin Console → Domains → your domain → Email Configuration → DKIM → add a selector (for example zmail), add the TXT record at zmail._domainkey, then click Verify and enable it.

cPanel email (email that comes with your hosting)

  • Open cPanel → Email Deliverability. It shows the suggested SPF and DKIM records for your server and a Repair or Manage button. If your DNS is on the same host, it can fix them for you. If DNS is elsewhere (for example GoDaddy), copy the suggested values there.
  • The cPanel SPF usually includes your server's IP address, for example v=spf1 +a +mx +ip4:203.0.113.10 ~all (your IP will be different).

Using more than one service?

Combine everything into one SPF record. Example for Google Workspace plus a newsletter tool: v=spf1 include:_spf.google.com include:servers.mcsv.net ~all. Two separate v=spf1 records will make SPF fail. SPF also allows a maximum of 10 DNS lookups, so remove services you no longer use. Don't forget your website's contact form, billing software or CRM if they send email "from" your domain; each needs to be in SPF or sign with DKIM.

Step 3: add DMARC and roll it out safely

Add a TXT record with host _dmarc:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.in; fo=1

Create the dmarc-reports@ mailbox (or use an existing one on the same domain). Then tighten the policy in stages:

  1. Weeks 1–4: p=none — nothing is blocked. Read the daily reports (a free DMARC report viewer helps) and find every service that sends mail as you.
  2. Fix anything failing — add missing services to SPF or set up DKIM for them.
  3. Next: p=quarantine; pct=25 — a quarter of failing mail goes to spam. Increase to pct=100 over a few weeks if nothing genuine breaks.
  4. Finally: p=reject — fake emails using your domain are refused. This is the goal.
Don't jump straight to p=reject. If your billing software or website form isn't in SPF/DKIM, your own invoices will start bouncing.

Domains you don't use for email

If a domain never sends email, lock it down completely: SPF v=spf1 -all and DMARC v=DMARC1; p=reject;. Scammers like unused domains because nobody is watching them.

Once your records are in place, re-run the scanner to confirm. If staff or customers are receiving fake emails or links, our guide to checking links helps them spot the scam. If your website itself has been sending spam, see is my website hacked?

Frequently asked questions

Can I have two SPF records on one domain?

No. A domain must have only one SPF (v=spf1) TXT record. If you use two services, such as Google Workspace and Zoho Campaigns, combine them into one record with two include: entries.

Will adding DMARC stop my emails from being delivered?

Not if you start with p=none. That policy only collects reports and does not block anything. Move to quarantine and reject only after the reports show all your genuine senders pass.

Do small businesses that send few emails need DMARC?

Yes. Google's strict DMARC rule is for bulk senders, but any domain can be spoofed. A DMARC record is free and makes fake emails in your company name much easier for Gmail and others to block.

How long do DNS changes take?

Usually a few minutes to an hour on GoDaddy, Hostinger and BigRock, but some changes can take up to 24–48 hours to be seen everywhere.

What is the difference between ~all and -all in SPF?

~all (soft fail) tells receivers that unlisted servers are probably not you; -all (hard fail) says they are definitely not you. Many providers suggest ~all while you are setting up and DMARC then decides what happens to failing mail.

This guide is general information, not legal advice. If you have lost money to fraud, call 1930 immediately or report at cybercrime.gov.in.