SPF, DKIM and DMARC: Stop Business Email Going to Spam
You send a quote to a customer and it lands in their spam folder. They never see it, you look unprofessional, and business quietly suffers. The most common fixable cause is missing email authentication: three DNS records called SPF, DKIM, and DMARC that prove your email really comes from you. This article explains what each one does and how to set them up.
What these three records do
Think of them as three forms of ID your email shows at the door of the recipient’s mail server.
- SPF (Sender Policy Framework) lists which servers are allowed to send email for your domain. If a spammer tries to send as you from their own server, SPF exposes the forgery because their server is not on your list.
- DKIM (DomainKeys Identified Mail) adds a digital signature to every email you send. The recipient’s server checks the signature against a public key in your DNS. A valid signature proves the message was not altered in transit.
- DMARC tells receiving servers what to do when SPF or DKIM checks fail: let the message through anyway, send it to spam, or reject it outright. It also asks for reports, so you can see who is sending email claiming to be you.
Together, they answer the recipient server’s three questions: are you allowed to send this, is it genuine, and what should I do if it is not. Mailbox providers increasingly require all three, and Gmail and others now reject or spam-filter mail from domains without them.
Step 1: Find where your DNS is managed
These records live in your domain’s DNS. If your domain uses InterProWebHost nameservers, you manage DNS in your hosting account. If your DNS is elsewhere, you will add the records there instead. The steps below assume your DNS is with us; the record values are the same wherever you add them.
Step 2: Enable SPF and DKIM in cPanel
Log in to cPanel and open Email Deliverability. This page shows your domains and the status of their SPF and DKIM records. For each domain you send mail from, use the page’s controls to install the recommended SPF and DKIM records. cPanel generates the correct values for your server automatically, which avoids the typos that break hand-written records. After installing, the page should show both as valid. Note that DNS changes can take some time to be visible everywhere, so if a checker still shows them missing after an hour, wait a little longer before troubleshooting.
Step 3: Add a DMARC record
DMARC is a TXT record you add to your DNS. Start with a monitoring policy that asks receivers to send you reports without rejecting anything yet. A common starter record, added as a TXT record at the name _dmarc for your domain, looks like this: v=DMARC1; p=none; rua=mailto:you@yourdomain.com, using your own address for the reports. Let it run for a few weeks and read the reports: they show which servers send mail as your domain, including any you forgot about, like a newsletter service or your website’s contact forms. Once the legitimate senders are all accounted for, tighten the policy toward quarantine and eventually reject. Move gradually; jumping straight to reject can block legitimate mail you overlooked.
Do not forget your other senders
Your SPF record must include every service that sends email as your domain: your hosting account, Titan business email if you use it, your website’s forms, and any newsletter or CRM service. Each legitimate sender needs to be in SPF and, where supported, signing with DKIM. This is the step most businesses miss. Walk through every way your business sends email and account for each one, or open a support ticket and list your sending services so we can check the records cover them all.
How to verify it worked
Send a test email from your business address to a Gmail account and open the message’s original headers. Gmail shows the SPF, DKIM, and DMARC results for the message. All three should pass. There are also free online tools that check a domain’s records directly; use one to confirm all three records are published correctly. If your mail still lands in spam after authentication passes, the cause is elsewhere: see Why Your Business Email Goes to Spam.
Still stuck? Open a support ticket with your domain name and a list of the services you send email from. We will check your records and tell you exactly what is missing.