SPF and DKIM prove to Gmail, Outlook, Yahoo and other providers that email from your domain really comes from you. Without them, your messages are far more likely to land in spam or be rejected. This guide shows you how to set up SPF and DKIM for a domain on Instant Access Internet Services, using cPanel's Email Deliverability tool -- in most cases it's one click.
What SPF and DKIM do
- SPF (Sender Policy Framework) is a DNS record listing the servers allowed to send mail for your domain.
- DKIM (DomainKeys Identified Mail) adds a digital signature to each message. Receiving servers check it against a public key published in your DNS, which proves the message wasn't forged or altered.
Together they make DMARC possible, which major providers now expect from anyone sending regular mail. See How to Add a DMARC Record to Your Domain once SPF and DKIM are valid.
How to check your SPF and DKIM status
- Log in to cPanel and go to Email > Email Deliverability.
- Find your domain in the list. The status shows either Valid or Problems exist.
- Click Manage next to the domain to see the details for DKIM, SPF and Reverse DNS (PTR).
If everything shows as valid, you don't need to do anything else here.
How to fix SPF and DKIM automatically
If your domain uses our nameservers (see Our Nameservers: How to Point Your Domain to Your Hosting), cPanel can install the correct records for you:
- In Email Deliverability, click Repair next to the domain that shows Problems exist.
- Review the suggested changes in the window that opens, then confirm.
- Wait a minute, then reload the page. The status should change to Valid.
Or click Manage and use Install the Suggested Record in each section that has a problem. If DKIM shows no key at all, click Generate Local DKIM Key first.
Adding other senders to SPF (Microsoft 365, Google Workspace, newsletters)
Your domain can only have one SPF record. If other services send mail as your domain -- Microsoft 365, Google Workspace, Mailchimp, a CRM or an online shop -- they must be added to that one record, not in a second one.
- Go to Email > Email Deliverability and click Manage next to your domain.
- In the SPF section, click Customize.
- Under Additional Settings, add the service's include value to the Include List. Use exactly what the service tells you, for example:
- Microsoft 365:
spf.protection.outlook.com - Google Workspace:
_spf.google.com
- Microsoft 365:
- If a service gives you IP addresses instead, add them under IP Address Settings.
- Check the Preview of the Updated Record, then click Install a Customized SPF Record.
Be careful with Exclude All Other Hosts ("-all" Entry). It tells receivers to reject mail from any server not listed. Only turn it on when you're sure every service that sends as your domain is included.
If you've moved all your email to Microsoft 365 or Google Workspace, also see How to Use Microsoft 365 or Google Workspace Email with Your Domain.
If your DNS is hosted somewhere else
If your domain's nameservers aren't ours (for example, DNS is managed at your registrar or Cloudflare), cPanel can't change the records for you. Instead:
- Click Manage next to your domain.
- In the DKIM section, click Copy to copy the suggested record's name and value. Do the same for SPF.
- Add them as TXT records at your DNS provider. If you already have an SPF record there, merge the values into that one record rather than adding a second.
- Come back after the DNS change has had time to spread (see DNS Propagation: Why Domain Changes Take Time and How to Check) and check the status again.
The DKIM value is long. Some DNS providers need it split into chunks of 255 characters -- use the Split view if yours complains.
Troubleshooting
SPF says "Problems exist" after I added Microsoft 365 or Google
Check you don't have two SPF records. In Domains > Zone Editor (How to Use the cPanel Zone Editor (A, CNAME, MX and TXT Records)), look for TXT records starting with v=spf1. There must be only one. Delete the extra one and add its includes to the remaining record.
Reverse DNS (PTR) shows a problem
The PTR record belongs to the server's IP address and is managed by us, not in your cPanel. Open a ticket if it shows an error.
My mail still goes to spam
SPF and DKIM are the foundation, but not the whole story. Add DMARC (How to Add a DMARC Record to Your Domain) and read Why Your Emails Go to Spam (and How to Fix It) for the other common causes.
Related guides
- How to Add a DMARC Record to Your Domain
- Why Your Emails Go to Spam (and How to Fix It)
- How to Use Microsoft 365 or Google Workspace Email with Your Domain
- How to Use the cPanel Zone Editor (A, CNAME, MX and TXT Records)
- Our Nameservers: How to Point Your Domain to Your Hosting
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
