← Back to Knowledge Base
Email · July 21, 2026 · 6 min read

Secure Your Email Domain with SPF, DKIM, and DMARC Records in cPanel

cPanel dashboard with secure email domain shielded from spam and phishing attacks

As a business owner, you’re likely no stranger to the importance of email communication. But have you taken the necessary steps to secure your email domain? Implementing SPF, DKIM, and DMARC records is crucial for preventing spam, phishing, and email spoofing. In this article, we’ll walk you through the process of configuring these records in cPanel, so you can protect your email domain and maintain a positive online reputation.

In this article, we’ll cover the basics of SPF, DKIM, and DMARC records, their importance, and how to configure them in cPanel. We’ll also provide best practices for maintaining these records and troubleshooting common issues.

Understanding the Importance of SPF, DKIM, and DMARC

What is SPF and How Does it Work?

SPF (Sender Policy Framework) records specify which mail servers are permitted to send emails on behalf of a domain. This helps prevent spam and phishing by ensuring that only authorized mail servers can send emails from your domain.

Benefits of Implementing SPF Records

Implementing SPF records helps prevent email spoofing, reduces the risk of spam and phishing, and improves email deliverability.

SPF Record Format and Syntax

The recommended SPF record format is “v=spf1 a mx include:domain.com -all”, which allows only the specified mail servers to send emails on behalf of the domain.

Configuring SPF Records in cPanel

Creating a New SPF Record

To create a new SPF record in cPanel, follow these steps:

  1. Login to your cPanel account.
  2. Click on the “Email” icon and then click on “SPF Records”.
  3. Click on the “Create a New SPF Record” button.
  4. Enter the SPF record format, including the mail servers you want to authorize.
  5. Click the “Create Record” button.

Editing an Existing SPF Record

To edit an existing SPF record in cPanel, follow these steps:

  1. Login to your cPanel account.
  2. Click on the “Email” icon and then click on “SPF Records”.
  3. Locate the SPF record you want to edit and click on the “Edit” button.
  4. Make the necessary changes to the SPF record format.
  5. Click the “Save Record” button.

Including External Mail Servers in SPF Records

The “include” directive in SPF records can be used to include external mail servers, such as those provided by third-party email services.

DKIM Records

What is DKIM and How Does it Work?

DKIM (DomainKeys Identified Mail) records authenticate emails by adding a digital signature that verifies the sender and ensures the email’s content wasn’t altered during transit.

Benefits of Implementing DKIM Records

Implementing DKIM records helps prevent email spoofing, reduces the risk of spam and phishing, and improves email deliverability.

DKIM Record Format and Syntax

DKIM records typically have a selector and a public key, with the selector being a string that identifies the key and the public key being a long string of characters.

Configuring DKIM Records in cPanel

Creating a New DKIM Record

To create a new DKIM record in cPanel, follow these steps:

  1. Login to your cPanel account.
  2. Click on the “Email” icon and then click on “DKIM Records”.
  3. Click on the “Create a New DKIM Record” button.
  4. Enter the DKIM record format, including the selector and public key.
  5. Click the “Create Record” button.

Editing an Existing DKIM Record

To edit an existing DKIM record in cPanel, follow these steps:

  1. Login to your cPanel account.
  2. Click on the “Email” icon and then click on “DKIM Records”.
  3. Locate the DKIM record you want to edit and click on the “Edit” button.
  4. Make the necessary changes to the DKIM record format.
  5. Click the “Save Record” button.

DMARC Records

What is DMARC and How Does it Work?

DMARC (Domain-based Message Authentication, Reporting, and Conformance) records build upon SPF and DKIM, providing a framework for email receivers to determine if an email is legitimate and how to handle failed authentication.

Benefits of Implementing DMARC Records

Implementing DMARC records helps prevent email spoofing, reduces the risk of spam and phishing, and improves email deliverability.

DMARC Record Format and Syntax

DMARC records specify the policy for handling failed authentication, including the action to take when an email fails SPF or DKIM checks.

Configuring DMARC Records in cPanel

Creating a New DMARC Record

To create a new DMARC record in cPanel, follow these steps:

  1. Login to your cPanel account.
  2. Click on the “Email” icon and then click on “DMARC Records”.
  3. Click on the “Create a New DMARC Record” button.
  4. Enter the DMARC record format, including the policy and action for handling failed authentication.
  5. Click the “Create Record” button.

Testing and Verifying SPF, DKIM, and DMARC Records

After configuring SPF, DKIM, and DMARC records, it’s essential to test and verify that they’re correctly set up and functioning as intended.

Common Issues and Troubleshooting Tips

SymptomCauseFix
Emails are being marked as spamSPF or DKIM records are not correctly set upVerify that SPF and DKIM records are correctly configured and test them using tools like SPF and DKIM testers
Emails are being rejected by the recipient’s serverDMARC policy is set to reject emails that fail authenticationCheck the DMARC record and adjust the policy to allow emails that fail authentication to be delivered to the recipient’s spam folder instead of being rejected

Best Practices for Maintaining SPF, DKIM, and DMARC Records

  • Regularly review and update SPF, DKIM, and DMARC records to ensure they’re correctly set up and functioning as intended.
  • Test SPF, DKIM, and DMARC records using tools like SPF and DKIM testers to ensure they’re correctly configured.
  • Monitor email deliverability and adjust SPF, DKIM, and DMARC records as needed to improve email deliverability.

Conclusion

Configuring SPF, DKIM, and DMARC records is an essential step in securing your email domain and preventing email spoofing, spam, and phishing. By following the steps outlined in this article, you can protect your email domain and maintain a positive online reputation.

Frequently Asked Questions

What is the purpose of SPF, DKIM, and DMARC records?
SPF, DKIM, and DMARC records work together to secure your email domain by authenticating senders, verifying email content, and preventing spam and phishing attacks.
Can I configure SPF, DKIM, and DMARC records manually?
While it’s possible to configure SPF, DKIM, and DMARC records manually, cPanel provides a simple interface to automate the process and minimize errors.
How do I test my SPF, DKIM, and DMARC records?
You can test your SPF, DKIM, and DMARC records using online tools or by sending test emails to verify that they’re correctly set up and functioning as intended.
What happens if I don’t configure SPF, DKIM, and DMARC records?
Without SPF, DKIM, and DMARC records, your email domain may be vulnerable to spam and phishing attacks, which can harm your reputation and compromise your security.
Can I use third-party email services with SPF, DKIM, and DMARC records?
Yes, you can use third-party email services with SPF, DKIM, and DMARC records by including their mail servers in your SPF records and configuring DKIM and DMARC accordingly.
How often should I update my SPF, DKIM, and DMARC records?
You should update your SPF, DKIM, and DMARC records whenever you make changes to your email infrastructure or whenever you notice issues with email delivery.