Guide · Setting up

MX, SPF, DKIM and DMARC: the DNS records a mail domain needs

Every receiving mail server checks the same four records before it trusts a message from your domain. This guide says what each record states, and what a check should look for.

Four records, four questions

A receiving server asks four things about a domain: where does its mail arrive, which hosts may send for it, can this message’s signature be verified, and what should be done with a message that fails. The four DNS records answer them, one each.

The MX record: where mail arrives

An MX record names the host that accepts mail for the domain, with a preference number; the lowest is tried first. Alcitron Mail’s MX carries preference 10 and points at the service’s mail host. Publish it at the domain itself.

SPF: which hosts may send

SPF is a single TXT record beginning v=spf1 that lists the hosts allowed to send for the domain. RFC 7208 publishes it as a TXT record only, allows one record per domain, and limits an evaluation to ten DNS-querying terms. A business that also sends through another provider keeps that provider’s include: in the same record rather than adding a second.

DKIM: a signature that can be verified

DKIM lets the owner of a signing domain take responsibility for a message with a cryptographic signature. The receiver fetches the public key from DNS, in a TXT record at a name of the form selector._domainkey.domain. The key is created with the domain and the record to publish is shown in the client area.

DMARC: what to do on failure

DMARC is a TXT record at _dmarc.domain that tells receivers how to treat a message that fails the checks above: p=none asks for no action, quarantine for the message to be treated as suspicious, and reject for it to be refused. A reasonable course is to begin with none, read the reports, and tighten.

Checking that DNS carries them

Publishing is not the same as being seen. The client area compares what DNS answers with what the domain needs: the MX host among the exchanges, one SPF record that includes the mail host, the same DKIM key, and a DMARC policy at least as strict as the suggested one. A stricter policy of your own is accepted; so is an SPF record that also lists another provider.

A short list

  1. Publish all four, not three.
  2. Keep one SPF record, with every sending provider in it.
  3. Use the suggested one-hour TTL while making changes, so a correction spreads within the day.
  4. Read the status in the client area before testing with a real message.

Questions

Can a domain have two SPF records?

No. A domain should have one SPF record; a second provider is added to it with an include rather than a second record.

Where is the DKIM key published?

In a DNS TXT record at selector._domainkey followed by the domain. The client area shows the exact name and value.

What does the DMARC policy none do?

It asks receivers to take no specific action on messages that fail, which makes it the safe starting point while reports are read.

Sources

The documents this guide’s statements rest on. Each link opens in a new page.

  1. RFC 7208: Sender Policy Framework (SPF)
  2. RFC 6376: DomainKeys Identified Mail (DKIM) Signatures
  3. RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)