How to set up SPF and DKIM for Sendmarc

Sendmarc Team6 min read

Sendmarc is an email sending service used by product and marketing teams to deliver transactional and campaign email at scale. Before Sendmarc can send on behalf of your domain, you need to prove ownership and grant permission by publishing two DNS records: an SPF record and a DKIM record.

This guide walks through the full setup end-to-end using example.com as the sending domain. It should take about ten minutes, plus DNS propagation time.

Prerequisites

  • A Sendmarc account with the Domain Admin role.
  • Access to the DNS zone for the domain you intend to send from (for example, Cloudflare, Route53, or your registrar's DNS panel).
  • A dedicated subdomain is recommended for transactional mail, such as mail.example.com. This guide uses the root apex domain to keep things simple.

1. Add your sending domain

Sign in to Sendmarc and open Sending Domains from the left sidebar. Click Add domain in the top-right corner, enter your domain (for example example.com), and press Continue.

Sendmarc Sending Domains screen showing a list of domains with verification status.
The Sending Domains view lists every domain configured on your account and its current verification status.

Sendmarc will provision the domain in Pending state and generate the SPF and DKIM records you need to publish next.

2. Configure SPF

SPF (Sender Policy Framework) tells receiving mail servers which hosts are allowed to send email on behalf of your domain. Add the following TXT record at the root of your DNS zone:

Type
TXT
Host
@
Value
v=spf1 include:_spf.sendmarc.com ~all
TTL
3600

If you already publish an SPF record for another provider, do not add a second record. A domain may only have one SPF record. Instead, merge the Sendmarc include into your existing record:

v=spf1 include:_spf.google.com include:_spf.sendmarc.com ~all

3. Configure DKIM

DKIM (DomainKeys Identified Mail) lets receivers verify that a message was signed by an authorized sender and has not been tampered with in transit. Sendmarc generates a 2048-bit key pair for you and publishes the public key under the selector smc1. Add the following TXT record:

Type
TXT
Host
smc1._domainkey
Value
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQ7ZH1yQ4rq3n8u2eN0zxV3kqfW 2ATz9Xh0Iu1Wg5yq+cS3rN9mL0K7pQvB2Yj8Xh0Iu1Wg5yq+cS3rN9mL0K7pQvB 2Yj8Xh0Iu1Wg5yq+cS3rN9mL0K7pQvB2YjIDAQAB
TTL
3600
Sendmarc DNS Records panel listing the SPF and DKIM TXT records to publish.
The DNS Records panel shows the exact host and value for every record Sendmarc needs. Use the copy icon to grab each value.

Some DNS providers strip the value at 255 characters. If yours does, split the DKIM value into two quoted strings on the same record — most DNS UIs will handle this transparently, but check your provider's docs.

4. Verify in Sendmarc

Once both records are saved at your DNS provider, return to the DNS Records panel in Sendmarc and click Verify records. Sendmarc queries the authoritative name servers directly, so results are usually available within thirty seconds, though a full DNS propagation can take up to twenty-four hours.

You can also verify from the command line:

$ dig +short TXT example.com
"v=spf1 include:_spf.sendmarc.com ~all"

$ dig +short TXT smc1._domainkey.example.com
"v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQ..."
Sendmarc verification success screen showing SPF and DKIM as passing.
A verified domain shows both SPF and DKIM as Passing and is ready to send production traffic.

Troubleshooting

“SPF record not found” after publishing

Confirm the record was added to the correct zone and that the host field is @ (the apex), not the fully-qualified domain. Some DNS UIs interpret example.com literally and produce example.com.example.com.

Multiple SPF records detected

A domain may only publish one SPF record. Merge every provider's include into a single v=spf1 record.

DKIM value truncated

If verification fails and the retrieved value ends mid-key, your DNS provider trimmed the string. Split the value into two quoted strings or use a provider that supports long TXT records natively.

Verification hangs on Pending

Wait for the TTL of any previous record to expire, then retry. If you recently lowered the TTL, allow the old cached value to age out before verifying again.

Next steps

Once SPF and DKIM are passing, publish a DMARC record at _dmarc.example.com with a p=none policy and aggregate reports pointing to Sendmarc. This lets you monitor authentication results across every receiver before tightening the policy to quarantine or reject.