TechnicalCollectible prompt
SPF, DKIM and DMARC so your email gets delivered
Act as an email deliverability engineer. Set up SPF, DKIM and DMARC for {{website_url}} so our emails reach inboxes and nobody can send as us. Services that send email from our domain: {{integrations}}. Ask me for our DNS provider and to paste the current DNS records before suggesting changes.
1. Inventory every sender: mailbox provider, transactional email from the site, newsletter tool, CRM, invoicing and help desk. A forgotten sender is the usual reason legitimate mail breaks later.
2. SPF: exactly one TXT record including each sender, under the 10 DNS lookup limit, ending in a soft fail until DMARC reports look clean. Move senders to subdomains if we hit the limit.
3. DKIM: turn it on in every sender with 2048-bit keys, add the records they give us, and confirm each signs with our domain, not theirs.
4. DMARC, in stages:
- Start with p=none and aggregate reports sent to an address or reporting service we actually read
- Confirm SPF or DKIM alignment for every sender in the reports
- After 2 to 4 weeks of clean reports, move to quarantine, then reject
5. Subdomains: send marketing from a subdomain, such as news., so its reputation can't hurt password resets.
6. Receiving: make sure MX records exist, so replies and bounces don't vanish.
7. Bulk sender rules: if we email many Gmail or Yahoo addresses, confirm one-click unsubscribe and a spam complaint rate under 0.1%, never reaching 0.3%.
Never set p=reject before every sender passes, and never delete a record you don't understand; ask me.
Finish with the exact records to add or change in a table (type, host, value, why), the order to apply them, and how to verify with a test email and its headers.
Technicalnvoka.com/library/nvoka-email-domain-setup-spf-dkim-dmarcScan to open
Technical
SPF, DKIM and DMARC so your email gets delivered
Set up your domain's email records so site emails land in inboxes and nobody can spoof you.
Curated by Nvoka
Claude CodeCursorCodexWindsurf
Make it yours
Fill in the blanks and change any word. Only your copy changes, never the card.
Fill in the blanks
0 of 2 filledYour prompt
Act as an email deliverability engineer. Set up SPF, DKIM and DMARC for {{website_url}} so our emails reach inboxes and nobody can send as us. Services that send email from our domain: {{integrations}}. Ask me for our DNS provider and to paste the current DNS records before suggesting changes.
1. Inventory every sender: mailbox provider, transactional email from the site, newsletter tool, CRM, invoicing and help desk. A forgotten sender is the usual reason legitimate mail breaks later.
2. SPF: exactly one TXT record including each sender, under the 10 DNS lookup limit, ending in a soft fail until DMARC reports look clean. Move senders to subdomains if we hit the limit.
3. DKIM: turn it on in every sender with 2048-bit keys, add the records they give us, and confirm each signs with our domain, not theirs.
4. DMARC, in stages:
- Start with p=none and aggregate reports sent to an address or reporting service we actually read
- Confirm SPF or DKIM alignment for every sender in the reports
- After 2 to 4 weeks of clean reports, move to quarantine, then reject
5. Subdomains: send marketing from a subdomain, such as news., so its reputation can't hurt password resets.
6. Receiving: make sure MX records exist, so replies and bounces don't vanish.
7. Bulk sender rules: if we email many Gmail or Yahoo addresses, confirm one-click unsubscribe and a spam complaint rate under 0.1%, never reaching 0.3%.
Never set p=reject before every sender passes, and never delete a record you don't understand; ask me.
Finish with the exact records to add or change in a table (type, host, value, why), the order to apply them, and how to verify with a test email and its headers.