Channels

Land in the inbox: SPF, DKIM & DMARC

Authenticate your sending domain so your helpdesk email is trusted — and use the built-in checker to verify it.

Channels
Land in the inbox: SPF, DKIM & DMARC

Even with a great SMTP provider, mail can land in spam if your domain isn't authenticated. Three DNS records do the work, and Admin → Deliverability audits them for you.

SPF DKIM DMARC
The three records receivers check before trusting your mail

The three records

  • SPF — a TXT record listing which servers may send as your domain. End it with ~all (softfail) or -all (hardfail), never +all.
  • DKIM — a cryptographic signature added by your provider; you publish the public key at selector._domainkey.yourdomain.
  • DMARC — a TXT record at _dmarc.yourdomain that ties SPF+DKIM together and tells receivers what to do with failures. Start at p=none (monitor), then tighten to p=quarantine and p=reject.

Verify with the built-in checker

  1. Open Admin → Deliverability.
  2. Enter your sending domain (it prefills from your support address) and run the audit. Each record is scored pass/warn/fail with the exact fix.
  3. If DKIM isn't found, add your provider's selector (e.g. selector1, google) and re-run.

Analyse a real message

Send yourself a test, open the message's raw headers (in Gmail: Show original), paste them into the header analyzer, and confirm spf=pass, dkim=pass, dmarc=pass.

Tips

  • DNS changes take up to your record's TTL to propagate — re-run the audit after a while.
  • Each SMTP provider documents its exact SPF include and DKIM selector; use those values.