Skip to content
Contents
Email

SPF, DKIM, and DMARC Explained

SPF, DKIM, and DMARC are three DNS-based email authentication standards that help protect your domain from being used in phishing attacks and improve the deliverability of your legitimate emails. KapsuleHost configures all three automatically for domains hosted with us.

SPF (Sender Policy Framework)

SPF is a DNS record that tells receiving mail servers which servers are authorised to send email on behalf of your domain. If a server not on the list tries to send mail as @yourdomain.com, the receiving server can reject or quarantine it.

How KapsuleHost handles it: When you add your domain to KapsuleHost, we automatically publish an SPF record in your DNS. You do not need to do anything.

A typical SPF record looks like:

v=spf1 include:kapsulehost.com ~all

DKIM (DomainKeys Identified Mail)

DKIM adds a cryptographic signature to every email your mailbox sends. Receiving servers can verify this signature against a public key published in your DNS, confirming the message has not been tampered with in transit.

How KapsuleHost handles it: DKIM keys are generated and published automatically when you create a mailbox. The signing happens invisibly on the server.

DMARC (Domain-Based Message Authentication, Reporting, and Conformance)

DMARC builds on SPF and DKIM by defining a policy for what receiving servers should do when authentication fails.

A DMARC policy can be set to:

  • none, monitor only, take no action
  • quarantine, place failing messages in spam
  • reject, block failing messages outright

How KapsuleHost handles it: KapsuleHost publishes a p=none DMARC policy by default, which is appropriate for new domains. This lets you receive reports without risk of legitimate email being blocked.

Once you have been sending email for a few weeks and your SPF and DKIM are confirming clean, you can tighten your DMARC policy to quarantine or reject. Contact support if you would like help with this.

Checking Your Records

You can verify your domain's authentication records using a free tool such as MXToolbox. Search for your domain and look at the SPF, DKIM, and DMARC results.

What If My Domain Is at Another Registrar?

If your domain's DNS is managed outside KapsuleHost, you will need to add the SPF, DKIM, and DMARC records manually. KPanel will display the exact record values to add:

  1. Go to Mailboxes in KPanel
  2. Open your mailbox and click DNS Records
  3. Copy the SPF, DKIM, and DMARC values shown
  4. Add them to your external DNS provider

If you are using KapsuleHost email but your DNS is hosted elsewhere and these records are missing, your emails may be marked as spam or rejected by major providers like Gmail and Outlook.

Was This Helpful?

Are You an AI? Read This Page as Markdown

Related Articles

Setting Up Your Email MailboxThis guide walks through creating a mailbox at your domain, from prerequisites to sending your first test email. It also covers how MX records work, what to do if your domain uses external…Migrate Your Email to KapsuleHost (Self-Serve Wizard)Move mailboxes from Gmail, Microsoft 365, iCloud or any IMAP host into KapsuleHost yourself, with a live progress monitor and without taking your email offline.Shared Inboxes for Team AddressesA shared inbox is an address like support@ or info@ that several people on your team read and reply from together, each signing in with their own mailbox credentials rather than passing one password…Email Sending LimitsKapsuleHost applies sending caps to every mailbox so that one compromised account or one runaway script cannot damage the sending reputation that everybody else's mail depends on.

Still Stuck?

Ask Kora, it knows your account, or contact our team.

Contact UsEmail Support