SpamCipher Help Center

How to set up SPF, DKIM and DMARC for your domain

Add the records that let Gmail and Outlook trust mail from your own domain

Updated 10 October 2026

SPF, DKIM and DMARC are DNS records that prove mail from your domain really comes from you. Without them your mailboxes still send, but their mail lands in spam far more often. SpamCipher shows exactly which records your domain is missing, you add them where your domain's DNS is managed, and a test message confirms they work.

Note: You only need this for your own domain, such as [email protected]. An address that ends in @gmail.com or @outlook.com is signed by Google or Microsoft, so there is nothing to set up.
Note: SpamCipher does not give you a DKIM key. The key belongs to the service that sends your mail, such as Google Workspace or Microsoft 365, so you turn DKIM on there.
Note: If your domain's DNS is on Cloudflare, you can choose Set it up automatically instead. You paste a Cloudflare API token and SpamCipher adds the records for you.

Before you start

  • A mailbox on your domain connected in SpamCipher, for the final test message
  • Access to where your domain's DNS is managed, such as your domain registrar or Cloudflare
  • Admin access to your email provider, such as Google Admin, to turn on DKIM
  • About 15 minutes, plus up to an hour for DNS changes to show

Open your domain in SpamCipher

Step 1: Open Email Accounts

  • In the left menu, point to the paper plane icon to open Outreach.
  • Click Email Accounts.

Step 2: Open Authenticate domain

  • Click Authenticate domain in the top right, next to + Add new.
  • A panel opens with the domains your mailboxes send from.

Step 3: Choose your domain

  • Click your domain in the list. Each domain shows how far it is set up, for example Records pending.
  • If your domain is not listed, type it under Add another domain and click Add.

Step 4: Choose to set it up yourself

  • The panel lists what your domain still needs, such as an SPF record, DKIM and a DMARC record.
  • Click Set it up myself.
  • Set it up automatically only works when your domain's DNS is on Cloudflare.

Add the records where your DNS is managed

Step 5: Copy the records

  • The panel shows only what is missing, numbered in the order to do it.
  • For each record, copy the Name and the Value with the Copy buttons. Type is the kind of record to create, usually TXT.
  • For DKIM, the panel shows steps in your email provider instead, because the provider holds the key.
Note: Copy each value exactly as shown. If the panel says Replace, your domain already has that record, so change its value instead of adding a second one.

Step 6: Turn on DKIM in your email provider

This step happens outside SpamCipher.

  • Follow the DKIM steps the panel shows for your provider. For Google Workspace, open Google Admin at admin.google.com and go to Apps, Google Workspace, Gmail, Authenticate email.
  • Choose your domain. If no record is shown, click Generate new record, then copy the TXT record Google shows.
  • After you add that record in the next step, come back and click Start authentication. Google only signs your mail after this click.
Note: Microsoft 365 uses Microsoft Defender and two CNAME records instead. The panel shows the steps for the provider your mailbox uses.

Step 7: Add the records at your DNS host

This step happens outside SpamCipher.

  • Sign in where your domain's DNS is managed. This is usually where you bought the domain, or Cloudflare.
  • Add each record from SpamCipher with the Type, Name and Value you copied, and add the DKIM record from your email provider the same way.
  • A Name of @ means the domain itself. If your DNS host asks for the full name, use the one SpamCipher shows under the record.
Note: DNS changes can take up to an hour to show.

Check that it works

Step 8: Check the records

  • Come back to this panel and click I've done it. Check.
  • SpamCipher looks up your DNS. If a record is still missing, it says which one.
  • When everything is found, the panel moves on to a test message. Click Send a test message, and one of your mailboxes on the domain sends a short email to SpamCipher. It usually arrives within two minutes.
Note: When SPF, DKIM and DMARC all pass in that test message, your domain shows as Authenticated on Email Accounts.

Troubleshooting

It says a record is still not found

DNS changes can take up to an hour to show, so wait a few minutes and click the check button again. If it still fails, compare the Name and Value at your DNS host with the ones in SpamCipher, and make sure your domain has only one SPF record.

Set it up automatically is greyed out

Automatic setup only works when your domain's DNS is on Cloudflare. Choose Set it up myself and add the records at your DNS host instead.

It says no active mailbox sends from my domain yet

The final check sends a real email from your domain. Connect a mailbox on the domain on Email Accounts first, then check again.

The test message never arrived

Make sure the mailbox can still send, for example that it is not paused or disconnected, then send the test message again.

The test says Not yet

The panel lists what failed. Click Back to the setup, fix that record or turn on DKIM in your email provider, and check again.

Can I check all my records at once?

Yes. Open Domain Health under Deliverability in the left menu, type your domain and click Run full scan. A full scan uses 10 credits.