Free Tool · Nothing Stored

📧 SPF / DKIM / DMARC Generator

Build the DNS records that authenticate your domain's email — stop spoofing and keep your messages out of the spam folder. Everything runs in your browser; nothing is stored.

Build your record ↓
Tick the services you send mail through — their include is added automatically.
Separate multiple values with a space, e.g. ip4:1.2.3.4 mx
DNS Record (TXT)
TypeTXT Host / Name@ Valuev=spf1 ~all
⚠️ A domain should have only one SPF record. If you already have one, merge the includes into it — never create a second line.
Assigned by your email provider, e.g. google, selector1
The DKIM key is generated by your mail server (DirectAdmin, Google, M365) — this tool formats it into a valid DNS record for you.
DNS Record (TXT)
TypeTXT Host / Namedefault._domainkey Valuev=DKIM1; k=rsa; p=
Daily summary reports are sent to this address. Optional.
DNS Record (TXT)
TypeTXT Host / Name_dmarc Valuev=DMARC1; p=none

This tool processes everything in your browser — no domain or key data is ever sent or stored anywhere.

Email Authentication

Why set up SPF, DKIM and DMARC

Together they are the email authentication standards that receivers like Gmail and Outlook use to decide whether your mail is trustworthy or forged.

SPF — who can send

Lists the servers and services allowed to send mail on your domain's behalf. Receivers reject or distrust mail sent from anywhere else.

DKIM — tamper-proof signature

Attaches a digital signature to every message. Receivers check it against the public key in your DNS to confirm the mail is really yours and unmodified.

DMARC — policy and reports

Tells receivers what to do when mail fails SPF/DKIM and sends reports back, so you can see who is sending mail in your domain's name.

The payoff

More of your business email reaches the inbox, less lands in spam, and criminals can't impersonate your brand by email.

FAQ

Frequently asked questions

What is the difference between SPF, DKIM and DMARC?

SPF declares which servers may send email for your domain. DKIM adds a digital signature verifying the message was not altered. DMARC is the policy telling receivers what to do when mail fails SPF/DKIM, and sends reports back. The three work together to stop spoofing and keep your email in the inbox.

Should I use -all or ~all in SPF?

-all (hardfail) firmly rejects mail from servers not listed — safest, but risky if your record is incomplete. ~all (softfail) marks it suspicious but still accepts it. Start with ~all while testing, then switch to -all once every legitimate sending server is listed.

Should DMARC start at p=none or p=reject?

Always start at p=none. It collects reports without rejecting any mail, so you can see who sends in your domain's name. Once reports show SPF/DKIM passing for every legitimate source, move to p=quarantine and finally p=reject.

Where do I add SPF/DKIM/DMARC?

All three are TXT records in your domain's DNS zone. On hosting with DirectAdmin you add them under DNS Management. DMARC uses the host name _dmarc, and DKIM uses selector._domainkey as defined by your email provider.

✓ Included with Business Email

Professional Email + DNS, managed in one place on DirectAdmin

AsiaGB business email comes with hosting where SPF, DKIM and DMARC live together, plus a Thai support team that helps you get every record landing in the inbox.

See business email