SPF, DKIM & DMARC Generator & Live Validator
Generate compliant email authentication DNS records and audit any live domain in real time to maximize inbox delivery and meet strict Google, Yahoo, and Microsoft requirements.
Configure authorized sending mail servers
Select your email providers or add dedicated IP addresses to build a compliant SPF record without syntax errors or DNS lookup overflow.
Why SPF, DKIM, and DMARC authentication is mandatory
Since 2024 and with tightened standards in 2026, leading global email providers (Google Workspace, Gmail, Yahoo Mail, and Microsoft 365) strictly reject unauthenticated domains. Messages missing SPF or DMARC are blocked at SMTP connection or flagged directly into spam folders.
Deploying all three protocols establishes a defense perimeter against domain spoofing and phishing attacks targeting your customers, while cementing enterprise inbox reputation and high open rates.
Security Matrix: SPF vs DKIM vs DMARC
| Protocol | Mechanism & Purpose | DNS Zone Location | Gmail / Yahoo Requirement |
|---|---|---|---|
| SPF (RFC 7208) | Specifies an authorized whitelist of IP addresses and relays permitted to send mail for your domain. | @ (Root TXT record) | Mandatory |
| DKIM (RFC 6376) | Signs headers and message body with asymmetric cryptography to verify authenticity and prevent tampering. | selector._domainkey (TXT) | Mandatory |
| DMARC (RFC 7489) | Enforces domain alignment between From header and SPF/DKIM, mandating rejection of unauthorized mail. | _dmarc.yourdomain.com (TXT) | Mandatory |
Frequently asked questions about email authentication
What happens if I configure SPF but omit DMARC?
Your messages risk landing in Gmail and Yahoo spam folders. DMARC tells receiving servers how to handle emails that fail SPF or DKIM authentication.
Why is there a strict 10 DNS lookup limit for SPF?
RFC 7208 enforces a maximum of 10 DNS queries for external lookup mechanisms ("include", "a", "mx", "ptr"). Exceeding 10 results in a "PermError" and causes mail servers to reject your emails.
Which selector should I use for DKIM?
A selector identifies the specific public key in DNS. In Wyrebase cPanel, it is "default". Other systems use distinct keys like "google" for Google Workspace or "k1" for Mailchimp.
Where do I paste these records in my hosting?
In your domain DNS zone editor (in Wyrebase cPanel > Zone Editor, or in Cloudflare) as TXT records with their corresponding host names.

