Troubleshooting Email Delivery Issues (SPF, DKIM, DMARC)
If you have recently set up a business email but find that your outgoing messages are landing in your clients' spam folders—or bouncing entirely—the issue is almost certainly related to your domain's DNS authentication records. Major email providers like Gmail and Outlook now strictly enforce SPF, DKIM, and DMARC protocols. This guide shows you how to implement them correctly.
1. Setting up SPF (Sender Policy Framework)
SPF is a DNS record that publicly lists all the IP addresses and mail servers that are authorized to send email on behalf of your domain. If an email arrives at Gmail claiming to be from your domain, but the server that sent it isn't listed in your SPF record, Gmail will flag it as spoofed.
To configure SPF for Titan Mail on Domzivo:
- Go to the Domains section in your dashboard and click Manage DNS for your domain.
- Add a new TXT Record.
- Set the Host/Name to
@(which means the root domain). - Set the Value to:
v=spf1 include:spf.titan.email ~all
2. Configuring DKIM (DomainKeys Identified Mail)
DKIM adds a cryptographic signature to every outgoing email. The receiving server uses the public key published in your DNS to verify that the email was actually sent by you and wasn't altered in transit.
To configure DKIM:
- Go to your Email Control Panel and locate the DKIM Settings.
- The system will generate a unique public key for you.
- Go back to your DNS manager and add a new TXT Record.
- Set the Host/Name to exactly what Titan specifies (usually something like
titan1._domainkey). - Paste the long cryptographic string provided into the Value field.
3. Enforcing DMARC (Domain-based Message Authentication)
DMARC is the final layer. It tells the receiving server exactly what to do if an email fails the SPF or DKIM checks. Without a DMARC policy, Google and Yahoo will heavily throttle your delivery rates.
To set up a basic DMARC policy that monitors failures without outright blocking them:
- Add a new TXT Record.
- Set the Host/Name to
_dmarc - Set the Value to:
v=DMARC1; p=none; rua=mailto:[email protected];
Propagation Warning: After adding or modifying these DNS records, it can take up to 24 hours for the global DNS network to fully recognize the changes. Do not run delivery tests immediately after clicking save. Wait a few hours, then use a tool like Mail-Tester.com to verify your score.