Help center

Deliverability

Set up SPF, DKIM and DMARC

SPF, DKIM and DMARC are DNS records that prove your emails really come from your domain. Without them, more of your emails land in spam. You add them where your domain's DNS is hosted (your registrar, Cloudflare, Google Workspace, Microsoft 365…).

Outsquid checks these records for every connected mailbox's domain and shows the result on the Mailboxes page and on each mailbox's Deliverability tab. Gmail and Outlook.com addresses are skipped: Google and Microsoft run those domains. To check any domain without signing in, use the free SPF, DKIM and DMARC checker.

SPF

SPF lists the servers allowed to send email for your domain. It's one TXT record on the domain itself. For Google Workspace:

v=spf1 include:_spf.google.com ~all

For Microsoft 365, use include:spf.protection.outlook.com. If you send through more than one service, combine them into a single SPF record.

How Outsquid rates it: Pass when the record ends in ~all or -all. Partial when it exists but doesn't end in one of those. Fail when there is no SPF record, when there's more than one, when it ends in +all (which allows anyone to send as you), or when it needs more than 10 DNS lookups.

DKIM

DKIM signs each email so receivers can tell it wasn't changed and came from your domain. Your email provider generates the key; you publish it as a TXT record at <selector>._domainkey.yourdomain.com.

  • Google Workspace: Admin console → Apps → Gmail → Authenticate email.
  • Microsoft 365: Microsoft Defender portal → Email authentication → DKIM.

How Outsquid rates it: Outsquid looks for a DKIM key at the selectors common providers use — among them google, default, mail, selector1 and selector2 (Microsoft 365), k1–k3, s1, s2, zoho and mandrill. If your provider uses a different selector, Outsquid may show Fail even though DKIM works — your provider's own check is the source of truth.

DMARC

DMARC tells receivers what to do with emails that fail SPF and DKIM, and where to send reports. It's a TXT record at _dmarc.yourdomain.com. Start with monitoring, then tighten:

v=DMARC1; p=none; rua=mailto:[email protected]

Once your legitimate email passes, move to p=quarantine, then p=reject.

How Outsquid rates it: Pass with p=quarantine or p=reject, Partial with p=none, Fail when there's no DMARC record.

After you change DNS

DNS changes can take from a few minutes to 48 hours to spread. Outsquid re-checks every hour; to check right away, open the mailbox's Deliverability tab and click Re-check.

Last updated 2026-10-02Still stuck? Contact support