Setup guides
DMARC setup, written for the panel you actually use
The records are the same everywhere. The control panels are not, and that is where people lose afternoons. Pick your DNS host or mail platform.
GoDaddy
6 minAdd a DMARC record in GoDaddy DNS, avoid the doubled-domain Name field trap, enable DKIM, and verify with a real DNS lookup instead of trusting the panel.
Read the guide →Microsoft 365 / Outlook (Exchange Online)
7 minSet up DMARC and DKIM on Microsoft 365. The Defender portal steps, the two CNAMEs you cannot copy from a template, and how to verify it worked.
Read the guide →Google Workspace
6 minGoogle Workspace signs your mail with gappssmtp.com by default, so DMARC quietly rests on SPF alone. Here is the exact Admin console and DNS fix.
Read the guide →Cloudflare DNS
7 minAdd SPF, DKIM and DMARC in Cloudflare's DNS Records tab. Covers the Name field trap, TXT quoting errors, CNAME flattening, and how to verify with dig.
Read the guide →Namecheap
6 minStep-by-step DMARC, SPF and DKIM setup in Namecheap Advanced DNS, including the Host field trap that silently breaks records and how to delegate access safely.
Read the guide →Shopify-managed domains
6 minSet up SPF, DKIM and DMARC on a domain bought through Shopify. Exact admin path, the Name field trap, sender email authentication, and how to verify it.
Read the guide →Squarespace
6 minEmail authentication setup for Squarespace domains, including those migrated from Google Domains. Exact field names, the Name field trap, and how to verify.
Read the guide →Before you start
Three things that decide whether this goes well
- 01The order matters more than the records. SPF first, DKIM second, DMARC last. Publishing an enforcing policy before the first two work will start rejecting your own invoices.
- 02Start DMARC at p=none. It changes nothing about delivery and switches on reporting, which is the only way to find the sending tools you forgot about.
- 03Read reports for two to four weeks. Then move to quarantine, then reject. Anyone who tells you to skip this has not had to explain to a client why their receipts stopped arriving.
Free tool
Check what you have now
See exactly which of SPF, DKIM, DMARC and BIMI your domain publishes today, and what each result means. No signup.
Copy these
DMARC record examples
Replace yourdomain.com with your own domain and send reports somewhere you will actually read. Everything else can stay exactly as written.
Start here. Reporting only, changes nothing about delivery.
- Name
- _dmarc
- Value
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
After two to four weeks of clean reports. Failures go to spam.
- Name
- _dmarc
- Value
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc@yourdomain.com
Full enforcement. Required before BIMI will display your logo.
- Name
- _dmarc
- Value
v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com
SPF for Google Workspace. One SPF record per domain, never two.
- Name
- @
- Value
v=spf1 include:_spf.google.com ~all
What each tag does
- v
- Always DMARC1. It is the only valid value and it must come first.
- p
- The policy: none, quarantine or reject. This is the tag you change as you roll out.
- rua
- Where aggregate reports are sent. Without it you are flying blind, which is the whole reason to start at p=none.
- pct
- Percentage of failing mail the policy applies to. Useful for easing into quarantine. Omit it and you get 100.
- sp
- Policy for subdomains. Leave it out and subdomains inherit p.
- ruf
- Forensic reports. Most providers do not send them and they can carry personal data, so most people should skip it.
Your DNS host and your mail platform are usually different