How do I add SPF, DKIM and DMARC records in Cloudflare?

Updated 9 October 2026 · 4 min read

Guest list Seal Rules

In Cloudflare, you add SPF, DKIM and DMARC on your domain's DNS Records page with the Add record button: SPF and DMARC are TXT records, and DKIM is a CNAME or TXT record from your email service. Any DKIM CNAME must be set to DNS only, because a proxied one hides your key from the servers checking your email.

SPF lists the services allowed to send your email. DKIM adds a digital signature that proves an email came from your domain. DMARC tells receivers what to do when an email fails both, and sends you reports. Without them, Outlook, Microsoft 365 and Gmail can't confirm your email is genuine.

Step 1: Check Cloudflare runs your DNS

Records in Cloudflare only count if your domain uses Cloudflare's nameservers (the servers that tell the internet where your DNS lives). Cloudflare assigns two when you add a domain, and shows them on the domain's Overview page. They end in ns.cloudflare.com.

If a WHOIS lookup shows other nameservers, your DNS is managed somewhere else and the records go there. And if your web host added your domain to Cloudflare for you, Cloudflare says to manage DNS through that host.

The records you need

RecordTypeNameContentProxy status
SPFTXT@v=spf1 include:spf.protection.outlook.com ~allNot shown (TXT is always DNS only)
DKIM (Microsoft 365)CNAMEselector1._domainkeyCopied from the Defender portalDNS only
DKIM (Microsoft 365)CNAMEselector2._domainkeyCopied from the Defender portalDNS only
DMARCTXT_dmarcv=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.auNot shown

@ means yourbusiness.com.au itself. For everything else, enter only the part before your domain. The SPF line above is for Microsoft 365; other services give you their own include.

Step 2: Add or update your SPF record

  1. In the Cloudflare dashboard, select your domain and go to DNS → Records.
  2. Look for a TXT record on your main domain that starts with v=spf1. If there is one, select Edit and change it. A domain can only have one SPF record, and two break SPF completely.
  3. If there's none, select Add record, choose TXT as the Type and enter @ as the Name.
  4. Paste your SPF record into Content.
  5. Leave TTL on Auto and select Save.

If you've ever used Cloudflare Email Routing, it added its own SPF record, v=spf1 include:_spf.mx.cloudflare.net ~all. Merge it into one line with your email service's include, or replace it if you no longer use Email Routing. Email Routing also needs Cloudflare's MX records, so it can't run alongside Microsoft 365 receiving your email.

If another service also sends as you, add its include before ~all, keeping the total under 10 DNS lookups.

Step 3: Add your DKIM records as DNS only

Microsoft 365 gives you two CNAME records in the Defender portal, under Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM. For each one:

  1. Select Add record and choose CNAME.
  2. Enter selector1._domainkey as the Name (then selector2._domainkey).
  3. Paste the value Microsoft shows into Target. It ends in either .onmicrosoft.com or .dkim.mail.microsoft.
  4. Switch Proxy status off so it shows DNS only (a grey cloud, not an orange one).
  5. Select Save.

Then switch on DKIM signing in the Defender portal. Our guide to setting up DKIM in Microsoft 365 covers that part.

Why DNS only matters. A proxied CNAME is flattened: Cloudflare answers with its own IP addresses instead of the name you pointed to. Receivers can't find your DKIM key, so DKIM fails. Cloudflare's own docs say email records should be DNS only, and Cloudflare sometimes warns about, or blocks, proxying a DKIM CNAME.

Paid plans also have a setting on the DNS Settings page called CNAME flattening for all CNAME records. Cloudflare warns it can break CNAMEs that other services check, because the CNAME itself is no longer returned. Leave it off, or make sure your DKIM records aren't flattened.

Other services may give you CNAME records or a TXT record. Add the type they show, with only the prefix in Name, keep any CNAME on DNS only, and paste values exactly.

Step 4: Add a DMARC record

  1. Select Add record and choose TXT.
  2. Enter _dmarc as the Name.
  3. Enter this in Content:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au
  1. Select Save.

p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you read. Once the reports show all your genuine email passing, change p=none to p=quarantine.

Cloudflare's DMARC Management

Cloudflare offers DMARC Management on all plans. Its docs place it under Email → DMARC Management; if the menu has moved, search the dashboard for "DMARC". When you enable it, Cloudflare checks for a DMARC record. If there's none, it offers to add one. If there is one, it adds a Cloudflare address as an extra rua entry, so Cloudflare can collect and summarise your reports. Its Email record overview also lists your SPF, DKIM and DMARC records.

You don't need it, but it does no harm. Just keep one DMARC record.

Step 5: Check it worked

Cloudflare's Auto TTL is 5 minutes, so new records usually work quickly. Give it at least that long, then send an email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for your own domain), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.

Checked against: Cloudflare Docs, Manage DNS records · Cloudflare Docs, Proxy status · Cloudflare Docs, Set up CNAME flattening · Cloudflare Docs, Troubleshooting email issues · Cloudflare Docs, Time to Live (TTL) · Cloudflare Docs, Enable DMARC Management · Cloudflare Docs, Email Routing DNS records · Microsoft Learn, How to use DKIM for email in your custom domain.

Questions people ask

Should my DKIM CNAME records be Proxied or DNS only?

DNS only (grey cloud). Cloudflare says records used for things other than web traffic, like CNAMEs that prove domain ownership, shouldn't be proxied. A proxied CNAME answers with Cloudflare's own addresses instead of pointing to your DKIM key, so receivers can't check your signature.

Do I need a paid Cloudflare plan to add these records?

No. TXT and CNAME records work on every plan, and Cloudflare says DMARC Management is available on all plans too. The setting to flatten all CNAME records is the paid-plan feature you want to leave off for DKIM.

Cloudflare already has an SPF record I don't recognise. What is it?

If it contains include:_spf.mx.cloudflare.net, Cloudflare Email Routing added it. Keep only one SPF record. If you no longer use Email Routing, replace it with your email service's record. If you do, merge both includes into one line.

How quickly do Cloudflare changes work?

Cloudflare's default TTL, Auto, is 5 minutes, so new records usually show up quickly. Receivers that looked up an older version may remember it until that version's TTL runs out.