Deliverability
Set up SPF, DKIM and DMARC
SPF, DKIM and DMARC are DNS records that prove your emails really come from your domain. Without them, more of your emails land in spam. You add them where your domain's DNS is hosted (your registrar, Cloudflare, Google Workspace, Microsoft 365…).
Outsquid checks these records for every connected mailbox's domain and shows the result on the Mailboxes page and on each mailbox's Deliverability tab. Gmail and Outlook.com addresses are skipped: Google and Microsoft run those domains. To check any domain without signing in, use the free SPF, DKIM and DMARC checker.
SPF
SPF lists the servers allowed to send email for your domain. It's one TXT record on the domain itself. For Google Workspace:
v=spf1 include:_spf.google.com ~all
For Microsoft 365, use include:spf.protection.outlook.com. If you send
through more than one service, combine them into a single SPF record.
How Outsquid rates it: Pass when the record ends in ~all or -all.
Partial when it exists but doesn't end in one of those. Fail when there is
no SPF record, when there's more than one, when it ends in +all (which
allows anyone to send as you), or when it needs more than 10 DNS lookups.
DKIM
DKIM signs each email so receivers can tell it wasn't changed and came from
your domain. Your email provider generates the key; you publish it as a TXT
record at <selector>._domainkey.yourdomain.com.
- Google Workspace: Admin console → Apps → Gmail → Authenticate email.
- Microsoft 365: Microsoft Defender portal → Email authentication → DKIM.
How Outsquid rates it: Outsquid looks for a DKIM key at the selectors
common providers use — among them google, default, mail, selector1 and
selector2 (Microsoft 365), k1–k3, s1, s2, zoho and mandrill. If
your provider uses a different selector, Outsquid may show Fail even though
DKIM works — your provider's own check is the source of truth.
DMARC
DMARC tells receivers what to do with emails that fail SPF and DKIM, and where
to send reports. It's a TXT record at _dmarc.yourdomain.com. Start with
monitoring, then tighten:
v=DMARC1; p=none; rua=mailto:[email protected]
Once your legitimate email passes, move to p=quarantine, then p=reject.
How Outsquid rates it: Pass with p=quarantine or p=reject, Partial
with p=none, Fail when there's no DMARC record.
After you change DNS
DNS changes can take from a few minutes to 48 hours to spread. Outsquid re-checks every hour; to check right away, open the mailbox's Deliverability tab and click Re-check.