What they are for
Large mail providers reject, or file as junk, a message whose sender cannot be verified. Three DNS records provide that proof.
| What it says | Without it | |
|---|---|---|
| SPF | Which servers may send for your domain | Your mail lands in junk |
| DKIM | That the message was not altered on the way, through a signature | A relayed message — mailing list, forward — loses its proof |
| DMARC | What to do with a message that fails the other two | Each recipient decides alone |
SPF
The full value is in the table at the bottom of this page.
A domain publishes one SPF only. If you already have one — for a newsletter tool, for
instance — do not create a second record: two SPF records cancel each other out. Add our
mechanism to the existing one, before the final -all or ~all:
include:_spf.pexysgroup.com
DKIM
The DKIM key is specific to your domain. It is produced when your mailboxes are created and we send you the record at that point: it cannot appear on a page shared by everyone.
DMARC
The value in the table asks recipients to quarantine whatever fails.
If other services send for your domain and you are not sure you have declared them all in
your SPF, start with v=DMARC1; p=none;: nothing is blocked, and you tighten it later.
Check
In the client area, on the Domains page, the Check DNS button tells you whether the SPF is in place, whether it is the only one, and whether it does authorise us.
The values
Replace your-domain.ch with yours. “@” stands for the domain itself.