SPF · DKIM · DMARC
Set up SPF, DKIM and DMARC on Postmark
Postmark signs and sends your mail, but alignment lives in your DNS — publish the DKIM key, point the return-path CNAME at Postmark, and confirm both verify.
Before you start
What Postmark needs from your DNS.
Postmark is a sending platform, not your mailbox host, so it authenticates differently from a provider like Google Workspace. Postmark already passes SPF for you: every message leaves over its own return-path domain, which carries Postmark's sending IPs. That is why the support docs tell you not to add include:spf.mtasv.net to your root domain — it does nothing for your domain's alignment and only spends one of your ten SPF lookups.
The two records that matter are DKIM and a custom return-path. DKIM is a TXT record Postmark generates per domain under Sender Signatures; publish it and Postmark signs every outbound message. The return-path is a CNAME pointing at pm.mtasv.net, and it is the piece most people skip — without it your mail passes SPF against Postmark's domain, not yours, so DMARC never sees SPF align.
DMARC sits on top of both and is the same _dmarc TXT record for every sender. Since Gmail and Yahoo began requiring SPF, DKIM and DMARC for bulk senders in February 2024, a Postmark domain that signs with DKIM and aligns its return-path is what keeps you in the inbox rather than the spam folder.
The records to publish
Copy these into your DNS.
Add each record at your DNS provider — the company where your domain is registered, not Postmark. Then run the checker to confirm every one resolves.
SPF record
value generated by Postmark
Postmark handles SPF automatically through its own return-path, so there is no Postmark value to add here. Do not publish include:spf.mtasv.net at your root — Postmark states it will not tie back to your return-path and gives you no alignment. Keep the single SPF record your mailbox provider already needs, and rely on the return-path CNAME below for DMARC SPF alignment.
DKIM record
value generated by Postmark
Postmark generates the key per domain under Sender Signatures → DNS Settings. The host is a date-stamped selector such as 20230601123456pm._domainkey and the value is a long v=DKIM1; k=rsa; p=... string. Publish exactly what the portal shows, then click Verify in Postmark — signing does not start until it verifies. Keys are 1024-bit by default.
Return-Path record
pm.mtasv.net
This CNAME moves the return-path onto your own domain, which is what gives you SPF alignment for DMARC. The default host is pm-bounces but you may name it anything, provided it matches the value set in the Postmark portal. Do not proxy or flatten it — it must resolve as a plain CNAME.
DMARC record
v=DMARC1; p=none; rua=mailto:[email protected]
Identical for every provider and always on the root domain. Start at p=none to watch your reports, then raise to quarantine and reject once DKIM and the return-path both align. Point rua at an address you actually read.
Step by step
The whole setup, in order.
- 1 Add and verify your domain in Postmark. In the Postmark portal open Sender Signatures, add the domain you send from, and open its DNS Settings. Postmark generates the DKIM and return-path records for that specific domain here — you cannot copy them from another account.
- 2 Publish the DKIM TXT record. At your DNS host, add the TXT record Postmark shows at its date-stamped selector (ending ._domainkey). Paste the v=DKIM1; k=rsa; p=... value exactly; if your panel splits the long key across quoted strings, that is fine as long as it stays one record.
- 3 Publish the return-path CNAME. Add a CNAME at pm-bounces (or whatever host the portal shows) pointing to pm.mtasv.net. This is what aligns SPF with your domain for DMARC. Leave any proxy or CDN toggle off so it resolves as a real CNAME.
- 4 Leave SPF alone, then add DMARC. Do not add spf.mtasv.net to your root SPF; Postmark does not need it. Publish the _dmarc TXT record above at p=none so you break nothing while you read the reports.
- 5 Verify in Postmark, then confirm here. Back in DNS Settings, click Verify so Postmark starts signing. DNS can take up to 48 hours to propagate; once it has, run a full check here to confirm the DKIM selector resolves, the return-path aligns, and DMARC is graded.
Where it goes wrong
The mistakes specific to Postmark.
Confirm it worked
Do not trust it until you have checked it.
DNS takes a few minutes to propagate. Once it has, run a full check: it reads all three records live, counts your SPF lookups, confirms the Postmark DKIM selector resolves, and grades your DMARC policy — the exact things that decide whether Gmail and Outlook trust your mail.
Common questions
About Postmark, specifically.
Set it once. Know it stays set.
A DKIM key rotates, a vendor changes its SPF, an IP gets listed — and your carefully-configured domain quietly breaks. Monitoring watches all of it and tells you the day it changes.