Skip to content
OmniLeadDocs
Sign in

Set up DNS records at your DNS host

Add SPF, DKIM and DMARC records at Cloudflare, GoDaddy, Namecheap or Squarespace (formerly Google Domains), step by step.

4 min readLast updated

This guide shows you exactly where to add SPF, DKIM and DMARC records at the four most common DNS hosts. If you're not sure what the records do, read SPF, DKIM and DMARC explained first. It takes about 15 minutes.

Find your DNS host

Your DNS host is where your domain's records are managed. It's often, but not always, the company you bought the domain from. If you moved your DNS to Cloudflare, for example, Cloudflare is your host even if you bought the domain elsewhere.

To check, look up your domain's name servers with any "NS lookup" tool:

Name servers containYour DNS host
cloudflare.comCloudflare
domaincontrol.comGoDaddy
registrar-servers.comNamecheap
squarespacedns.com or googledomains.comSquarespace (domains moved from Google Domains)

Collect your three records

Before you open your DNS host, get the values you'll add. Replace the examples with your own.

SPF: one TXT record on the root domain, with the include for your email provider.

Type
TXT
Host
@your root domain
Value
v=spf1 include:_spf.google.com ~all

DKIM: generated by your email provider. Google Workspace gives you one TXT record; Microsoft 365 gives you two CNAME records.

Type
TXT
Host
google._domainkey
Value
v=DKIM1; k=rsa; p=(the key from your provider)

DMARC: one TXT record at _dmarc. Start with p=none.

Type
TXT
Host
_dmarc
Value
v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.com

Add the records

Pick your DNS host. Repeat the steps once for each record.

  1. Open DNS records

    Sign in to the Cloudflare dashboard, select your domain, and go to DNS → Records.

  2. Click Add record

    The form opens at the top of the records list.

  3. Choose the type

    Set Type to TXT (or CNAME for Microsoft 365 DKIM records).

  4. Enter the name

    In Name, enter @ for SPF, the selector such as google._domainkey for DKIM, or _dmarc for DMARC. Cloudflare adds your domain automatically.

  5. Enter the content

    Paste the value into Content. Leave TTL on Auto.

  6. Turn off the proxy for CNAMEs

    For CNAME records, set Proxy status to DNS only (grey cloud). DKIM CNAMEs don't work through the proxy.

  7. Save

    Click Save.

Finish DKIM at your email provider

Most providers need one more click once the DKIM record is published:

  • Google Workspace: go back to Authenticate email in the Admin console and click Start authentication.
  • Microsoft 365: in the DKIM settings for your domain, turn on Sign messages for this domain with DKIM signatures.
  • Zoho Mail: click Verify next to the DKIM selector.

Check your records in OmniLead

  1. Open mailbox settings

    Go to Settings → Mailboxes.

  2. Recheck

    Click Recheck on the mailbox card for this domain.

  3. Confirm all three pass

    SPF, DKIM and DMARC should show Pass. If one shows Missing, wait a little and check again.

Mailbox card with SPF, DKIM and DMARC all passing

DNS changes usually appear within minutes, but can take up to 48 hours depending on the TTL of older records.

Common mistakes

ProblemFix
Two SPF recordsMerge them into one v=spf1 record
SPF record has the domain in the host, such as yourcompany.com.yourcompany.comUse @ as the host; most hosts add the domain for you
DKIM value was cut offCopy the full value again; some hosts need it pasted in one piece
DMARC record at the root instead of _dmarcMove it to host _dmarc
Cloudflare CNAME proxiedSet Proxy status to DNS only
Quotes around the value causing errorsRemove extra quotes; most hosts add them automatically

What's next