Setup guides

SPF, DKIM and DMARC, per provider.

The exact records to publish for the platform you send from — copy-paste ready, with the gotchas each one is known for. Then confirm it in the checker.

Choose your platform

11 providers covered.

Google Workspace → The three DNS records that make Gmail trust your Google Workspace mail — copy them in, switch authentication on, and confirm it landed. Microsoft 365 → The DNS records that make Outlook and Gmail trust your Microsoft 365 mail — publish the SPF line, the two DKIM CNAMEs and DMARC, switch DKIM on in the Defender portal, then confirm it landed. SendGrid → SendGrid authenticates a sending subdomain with CNAMEs it generates for you — publish them, add DMARC, click Verify, then confirm it landed. Mailgun → The DNS records that make Mailgun a verified sender for your domain — publish them on your sending subdomain, click Verify, and confirm they resolve. Brevo → The records that let Brevo send as your domain — publish the Brevo code and DKIM it generates, add DMARC, then have Brevo verify. Klaviyo → Klaviyo authenticates a branded sending subdomain, not your whole domain — add the CNAMEs it generates, keep your existing SPF untouched, and own your DMARC. Mailchimp → Mailchimp does not replace your mail host — it sends alongside it. Add its SPF include, publish the two DKIM CNAMEs, set DMARC, then click Authenticate. Amazon SES → The DNS records that make Gmail trust mail you send through Amazon SES — three DKIM CNAMEs, a MAIL FROM subdomain for SPF, and DMARC on your root. Postmark → Postmark signs and sends your mail, but alignment lives in your DNS — publish the DKIM key, point the return-path CNAME at Postmark, and confirm both verify. Zoho Mail → The three DNS records that make inboxes trust your Zoho Mail — publish them, verify the selector, switch DKIM on, and confirm it landed. OVH → The DNS records that make receivers trust mail from your OVHcloud MX Plan — publish the SPF, switch DKIM on in the Control Panel, add DMARC, then confirm it landed.