Check SPF, DKIM and email deliverability
Diagnose email-authentication DNS problems without replacing valid records blindly.
Where Tools → Email → Email Deliverability → Manage
Before you start
- Identify all services that send mail for your domain, including newsletters and website forms.
- Know where authoritative DNS is hosted.
Steps
-
1
Open Email Deliverability and find the domain with a warning.
-
2
Review DKIM, which signs outgoing mail, and SPF, which identifies authorised senders. Use the exact Name and Value supplied for your domain.
-
3
Use repair/install only if this server controls authoritative DNS and the proposed records include your real senders. Otherwise update the external DNS provider.
-
4
Do not create a second SPF policy at the same name. Ask your provider to combine senders correctly. Add DMARC through Zone Editor according to your mail provider’s policy guidance.
-
5
Recheck after caches expire. Reverse DNS/PTR problems normally require the sending-IP provider, not a new ordinary record in your zone.
-
6
Click Manage beside it to inspect the recommended records.
Use Manage to investigate the domain’s validation status.
Check it worked
- Confirm the authentication checks validate once public DNS is correct.
- Send externally and inspect authentication results where available. Valid SPF/DKIM does not guarantee inbox placement.