DNS authentication: SPF, DKIM and DMARC
MailFleet checks every sending domain's SPF, DKIM and DMARC records and shows the result on the Mailboxes page's Domains tab, the Deliverability page's Authentication tab and a campaign's Final Review — missing SPF or DKIM blocks deploying, and a record DNS didn't answer for reads "couldn't check", never missing.
Where: Mailboxes → Domains tab (a dot per record, DMARC with its policy, and Check DNS); Deliverability → Authentication tab (or the Authentication cell of the stats card); campaign → Final Review → "DNS"
How to do it
- Open Deliverability and click the Authentication tab, or the Authentication cell in the stats card (it counts your fully authenticated domains, and how many couldn't be checked). Each sending domain shows SPF, DKIM and DMARC: a green tick when the record was found, a red cross when DNS answered that it isn't there, or a grey ? with "couldn't check" when the lookup didn't answer. DMARC shows its policy (p=none, p=quarantine or p=reject).
- What To Fix lists one line per missing record: add an SPF TXT record (v=spf1 … including your mail provider), enable DKIM signing at your mail provider and publish its selector record, and add a DMARC TXT record at _dmarc.yourdomain (start with p=none to monitor). Only the missing-DMARC line has Copy Record: it copies v=DMARC1; p=none, to add as a TXT record at _dmarc.yourdomain. SPF and DKIM values come from your mail provider, so there is nothing to copy for them.
- "Fully Authenticated" means SPF, DKIM and DMARC were all found and DMARC is at quarantine or reject; at p=none the row lists a tightening suggestion instead. A free-mail domain (gmail.com, outlook.com and the like) reads "Managed by Google" (or its provider): the provider runs its records, so there's nothing to fix. Domains with something to fix are listed first, then ones that couldn't be checked, then the rest.
- A record whose lookup timed out or failed reads "couldn't check", and the row says "Couldn't check DKIM and DMARC — DNS didn't answer in time. Re-check All in a few minutes." (naming the records). It gets no fix line and no Copy Record, and it counts neither as authenticated nor as missing.
- Before deploying a campaign, open its Final Review — the "DNS" line lists any domain missing records; missing SPF or DKIM must be fixed before "Deploy campaign" is enabled, DMARC is recommended only. A domain whose DNS didn't answer in time is listed as "couldn't check" and doesn't block — reload to check again.
Good to know
- Deliverability's Authentication tab looks a domain up again once its answer is 10 minutes old (or had a part that couldn't be checked), so Re-check All within 10 minutes of a lookup shows the same answer; a lookup still running after a few seconds reads "couldn't check" and finishes in the background, ready for the next Re-check. It uses the same DNS checker as the Mailboxes page (the list, the Domains tab and each mailbox's page) and Final Review, which read results cached for 6 hours — only 2 minutes when a lookup didn't answer — and "Check DNS" on the Domains tab looks a domain up fresh.
- DKIM is looked for under common selectors (google, selector1, selector2, default, s1, k1, and when none of those has a key, k2, k3, dkim, s2, mail, zoho, fm1, fm2, fm3, smtp, mx, zmail, mandrill and protonmail). It counts as found when any selector has a key, and as missing only when every selector lookup answered that there's none. If your provider signs with an unusual selector, DKIM may show as missing even though it is set — the page says so.
- DMARC shows its policy (p=none / quarantine / reject). At p=none the advice is "DMARC is at p=none — tighten to quarantine or reject once SPF and DKIM align."
- On the Mailboxes list, a mailbox on a domain missing a record shows "DMARC missing" or "SPF missing" / "DKIM missing" beside its health and counts toward Needs Action. Only an answer from DNS that the record isn't there counts as missing: a lookup that timed out or failed shows "—" / "Couldn't check", doesn't count toward Needs Action and doesn't block a deploy.
- Domains come from your connected mailboxes' addresses; there is nothing to add by hand. Up to 50 domains (A–Z) are checked on the Deliverability page, and the tab says so when you have more.