Set up SPF, DKIM and DMARC for your sending domain
What SPF, DKIM and DMARC do, how to read the DNS check on Sender Accounts, and how to add the records for Google or Microsoft.
Last updated
Mailbox providers check three DNS records before they trust email from your domain. Victoria AI checks them for every connected mailbox and won't activate a campaign whose sending domain fails.
What SPF, DKIM and DMARC are
- SPF is a TXT record on your domain that lists the servers allowed to send its email. Your SPF must include Google's or Microsoft's servers, because Victoria AI sends through your mailbox provider.
- DKIM is a key your mailbox provider uses to sign each email, published as a DNS record. Receivers check the signature against it.
- DMARC is a TXT record at
_dmarcthat tells receivers what to do with mail that fails SPF and DKIM, and where to send reports.
You add all three where your domain's DNS is managed, which is usually the registrar you bought the domain from.
Read the DNS check on Sender Accounts
Each email row on Sender Accounts has a DNS chip. Select it to see the Authentication section: the domain, where its DNS is managed, when it was last checked, and a line for SPF, DKIM and DMARC.
| Chip | Meaning | Blocks activation |
|---|---|---|
| DNS ok | All three records pass. | No |
| DNS warnings | Something to improve: DKIM not found at a common selector, DMARC set to p=none, no MX records, or a personal mailbox domain. | No |
| DNS failing | No SPF record, more than one SPF record, SPF missing Google's or Microsoft's include, or no DMARC record. | Yes |
| DNS unchecked | The check couldn't reach DNS, or hasn't run yet. It retries daily. | No |
A DKIM warning can be ignored if your DKIM already uses a custom selector name. Every issue in the popover comes with the exact fix, including the record value for your domain. The check runs when a mailbox connects and every day after. After you change DNS, select Re-check DNS; changes can take up to an hour to show.
When the DNS host is recognized, the popover names it (for example GoDaddy or Cloudflare) with a How to add a record link to that host's own instructions.
DNS records for Google Workspace mailboxes
Add these at your DNS host. Replace yourdomain.com with your domain.
| Record | Type | Host / Name | Value |
|---|---|---|---|
| SPF | TXT | @ | v=spf1 include:_spf.google.com ~all |
| DKIM | TXT | google._domainkey | The key Google generates (see below) |
| DMARC | TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com |
To get the DKIM key: in Google Admin, go to Apps → Google Workspace → Gmail → Authenticate email, generate a key for your domain, add the TXT record it shows, then select Start authentication.
DNS records for Microsoft 365 mailboxes
| Record | Type | Host / Name | Value |
|---|---|---|---|
| SPF | TXT | @ | v=spf1 include:spf.protection.outlook.com -all |
| DKIM | CNAME | selector1._domainkey | The value Microsoft shows |
| DKIM | CNAME | selector2._domainkey | The value Microsoft shows |
| DMARC | TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com |
To get the DKIM values: in Microsoft 365 Defender, go to Email & collaboration → Policies & rules → Threat policies → DKIM, select your domain, create the two CNAME records it shows, then turn on signing.
Rules for the SPF record
- Keep one SPF record. A domain with two TXT records that start with
v=spf1fails, the same as having none. If you already have one, add the include to it rather than creating a second. - Put the include before the ending. For example,
v=spf1 include:_spf.google.com include:other.example ~all. - If your mail goes through a gateway such as Mimecast or Proofpoint, still add Google's or Microsoft's include. Victoria AI sends through your mailbox provider directly.
Move DMARC from p=none to enforcement
p=none only monitors. It passes the check with a warning, because mailbox providers trust domains that enforce a policy more. Once SPF and DKIM pass for everything that sends as your domain, change p=none to p=quarantine in the _dmarc record, and later to p=reject.
Add DNS records at GoDaddy
Sign in to GoDaddy, open your domain portfolio, select the domain, and open its DNS settings. Add a record, choose the type (TXT or CNAME), enter the host from the tables above (@ for the domain itself), paste the value, and save. To edit an existing SPF record, edit that TXT record instead of adding a new one.
Add DNS records at Cloudflare
In the Cloudflare dashboard, select the domain, then DNS → Records → Add record. Choose the type, enter the name (@ for the domain itself) and the content, and save. For the Microsoft DKIM CNAME records, set the proxy status to DNS only, because a proxied CNAME won't return the key.
Add DNS records at Namecheap
In your Namecheap account, open Domain List, select Manage next to the domain, then the Advanced DNS tab. Under host records, add a new record, choose the type, enter the host (@ for the domain itself, or _dmarc, google._domainkey and so on, without your domain name on the end) and the value, and save.
Add DNS records at Squarespace or Google Domains
Domains that were on Google Domains are now managed at Squarespace. In Squarespace, open Domains, select the domain, and open its DNS settings. Add a custom record, choose the type, enter the host and the value, and save. If the domain's DNS is managed somewhere else (for example its nameservers point to Cloudflare), add the records there instead; the DNS check names the right host.
Sender domain still failing after adding records
- Wait, then select Re-check DNS. DNS changes can take up to an hour to show.
- Check the host name. Many DNS hosts add your domain automatically, so
_dmarc.yourdomain.comtyped in full can become_dmarc.yourdomain.com.yourdomain.com. Enter only_dmarc. - Check you edited the right place. The popover says where DNS for your domain is managed. Records added anywhere else have no effect.
- Check for a second SPF record. Merge them into one.
When the chip reads DNS ok, the campaign's Email sender domains authenticated (SPF, DKIM, DMARC) check passes. DNS warnings and DNS unchecked show as a warning there but don't block activation. See Preflight checks.