Skip to content
UK web hosting, domain names, email, website security and online services.

Set up SPF, DKIM and DMARC records Print

  • security, domain, dns, email-authentication, email
  • 0

These records help receiving systems authenticate mail and apply domain policy.

Applies to: Email authentication and DNS security

SPF, DKIM, DMARC, DNSSEC and CAA solve different problems. Deploy them deliberately, validate syntax before tightening policy and keep an emergency rollback record for every production DNS change.

Before you start

  • Confirm that you are authorised to manage the domain and identify its authoritative DNS provider.
  • Export or record the complete current DNS zone and previous TTL values before making changes.
  • Allow for DNS caching and avoid making unrelated DNS changes during the same maintenance window.

Step-by-step

  1. Obtain exact values from the email provider.
  2. Publish one combined SPF record.
  3. Publish the DKIM selector supplied.
  4. Begin DMARC with monitoring and review reports before enforcement.

Confirm the result

  • Every authoritative nameserver returns the intended record, value and TTL.
  • An external test confirms that the dependent website, certificate or mail flow is using the new DNS answer after caches expire.

Common problems

SymptomLikely causeWhat to do
Some networks show the new result while others show the old one.Recursive DNS caches have not expired or authoritative nameservers do not return consistent data.Check the authoritative answer first, compare all listed nameservers and wait for the previous TTL before making another change.
The domain returns NXDOMAIN or SERVFAIL.The zone is missing, delegation is wrong, DNSSEC is broken or an authoritative server is not responding.Verify delegation at the registry, confirm the zone exists on every authoritative server and remove stale DS records only through a controlled DNSSEC rollback.

When to contact Tudor Internet

Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:

  • The full domain name
  • The current and intended registrar or nameservers
  • Any registry or transfer error shown
  • Whether website or email service is currently live
Do not send passwords, private keys, full payment-card details, one-time authentication codes or unredacted identity documents in an ordinary support reply.

Related articles

Last reviewed: 2026-07-18.


Was this answer helpful?

« Back