How to set up SPF, DKIM and DMARC for my domain

What do SPF, DKIM and DMARC do?

Record Purpose
SPF Lists the servers allowed to send email for your domain
DKIM Adds a signature that receiving servers can verify
DMARC Tells receivers what to do when SPF or DKIM checks fail

These records improve authentication, but they do not guarantee that every message will reach the inbox.

Find where your DNS is managed

Add the records wherever your domain's DNS is hosted.

  • If your domain uses dns1.webway.host and dns2.webway.host, manage the records through your Webway hosting panel.
  • If the domain uses Cloudflare or another DNS provider, add the records there instead.
  • Adding records only in cPanel or DirectAdmin has no public effect when another provider controls the DNS.

Do not change nameservers merely to add email authentication records.

Set up SPF in cPanel

  1. Sign in to cPanel.
  2. Open Email.
  3. Select Email Deliverability.
  4. Find the affected domain.
  5. Review the SPF status.
  6. Use the suggested repair option if cPanel manages the domain's DNS.
  7. If DNS is external, copy the suggested SPF name and value to the external provider.

A domain must have only one SPF record beginning with v=spf1. If an SPF record already exists, do not add a second one. Combine all legitimate sending services into one record.

Set up DKIM in cPanel

  1. Open Email Deliverability.
  2. Find the domain.
  3. Review its DKIM status.
  4. Repair the record if DNS is managed locally.
  5. If DNS is external, copy the complete DKIM record to that provider.

The hostname may resemble default._domainkey. Always use the exact selector and value shown by cPanel.

Set up SPF in DirectAdmin

  1. Sign in to DirectAdmin.
  2. Open DNS Management for the domain.
  3. Check for an existing TXT record beginning with v=spf1.
  4. DirectAdmin adds an SPF record for new domains. If it's missing, add one; if it exists, edit it rather than adding a second.

DNS Management is under Account Manager → DNS Management.

Do not create a second SPF record if one already exists.

Set up DKIM in DirectAdmin

  1. Open E-mail Manager → E-mail Accounts. DKIM is on by default; the page shows a DISABLE DKIM button when it is. If it shows an enable button instead, click it.
  2. Open Account Manager → DNS Management.
  3. Find the DKIM TXT record, usually named x._domainkey.
  4. If DNS is external, copy its hostname and complete value to the external provider.

Add a starter DMARC record

Start with a monitoring policy. This gathers reports without asking receivers to quarantine or reject messages.

Field Value
Name _dmarc
Type TXT
Value v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.co.za; pct=100

Replace yourdomain.co.za with your domain and make sure the reporting address exists.

If you do not want aggregate reports, use:

v=DMARC1; p=none; pct=100

After confirming that every legitimate sender passes SPF or DKIM, you can consider a stricter policy: p=quarantine or p=reject.

Do not publish a strict policy until all legitimate services have been checked. A strict record can cause valid email from websites, billing systems or mailing platforms to be rejected.

If you use Cloudflare or external DNS

  1. Sign in to the DNS provider.
  2. Add the SPF TXT record.
  3. Add the complete DKIM record.
  4. Add the DMARC TXT record.
  5. Remove any duplicate SPF or DMARC records.
  6. Wait for DNS propagation.
  7. Recheck the records in your hosting panel or a public DNS checker.

Cloudflare does not proxy TXT records. Enter the hostnames and values exactly as supplied by the hosting panel.

Check every service that sends email

Your authentication policy must account for email sent by:

  • Webway mailboxes
  • Your website
  • Contact-form plugins
  • Microsoft 365 or Google Workspace
  • Newsletter services
  • CRM or invoicing systems
  • Support platforms
  • Other third-party senders

Ask each external provider for its required SPF or DKIM records.

Still stuck?

Open a support ticket and include:

  • Your domain name
  • Whether you use cPanel or DirectAdmin
  • Your current nameservers
  • Where your DNS is managed
  • The complete SPF, DKIM and DMARC records
  • Every service that sends email for the domain
  • Any warning shown under Email Deliverability or DNS Management
  • A recent rejection or bounce message with its headers

Did this answer it?