Tools/SPF, DKIM & DMARC Generator & Live Validator
EMAIL SECURITY & DELIVERABILITY

SPF, DKIM & DMARC Generator & Live Validator

Generate compliant email authentication DNS records and audit any live domain in real time to maximize inbox delivery and meet strict Google, Yahoo, and Microsoft requirements.

Configure authorized sending mail servers

Select your email providers or add dedicated IP addresses to build a compliant SPF record without syntax errors or DNS lookup overflow.

Formatted SPF TXT Record2 / 10 DNS
v=spf1 +a +mx include:relay.wyrebase.com -all
Host Name / Subdomain:@
Record Type:TXT
Suggested TTL:3600 (1 hour)
SPF Golden Rule:Never publish more than one SPF record per domain. If using multiple services, combine all mechanisms inside a single TXT record while staying within the 10 DNS lookup limit.

Why SPF, DKIM, and DMARC authentication is mandatory

Since 2024 and with tightened standards in 2026, leading global email providers (Google Workspace, Gmail, Yahoo Mail, and Microsoft 365) strictly reject unauthenticated domains. Messages missing SPF or DMARC are blocked at SMTP connection or flagged directly into spam folders.

Deploying all three protocols establishes a defense perimeter against domain spoofing and phishing attacks targeting your customers, while cementing enterprise inbox reputation and high open rates.

Security Matrix: SPF vs DKIM vs DMARC

ProtocolMechanism & PurposeDNS Zone LocationGmail / Yahoo Requirement
SPF (RFC 7208)Specifies an authorized whitelist of IP addresses and relays permitted to send mail for your domain.@ (Root TXT record)Mandatory
DKIM (RFC 6376)Signs headers and message body with asymmetric cryptography to verify authenticity and prevent tampering.selector._domainkey (TXT)Mandatory
DMARC (RFC 7489)Enforces domain alignment between From header and SPF/DKIM, mandating rejection of unauthorized mail._dmarc.yourdomain.com (TXT)Mandatory

Frequently asked questions about email authentication

What happens if I configure SPF but omit DMARC?

Your messages risk landing in Gmail and Yahoo spam folders. DMARC tells receiving servers how to handle emails that fail SPF or DKIM authentication.

Why is there a strict 10 DNS lookup limit for SPF?

RFC 7208 enforces a maximum of 10 DNS queries for external lookup mechanisms ("include", "a", "mx", "ptr"). Exceeding 10 results in a "PermError" and causes mail servers to reject your emails.

Which selector should I use for DKIM?

A selector identifies the specific public key in DNS. In Wyrebase cPanel, it is "default". Other systems use distinct keys like "google" for Google Workspace or "k1" for Mailchimp.

Where do I paste these records in my hosting?

In your domain DNS zone editor (in Wyrebase cPanel > Zone Editor, or in Cloudflare) as TXT records with their corresponding host names.