How do I add SPF, DKIM and DMARC records in Crazy Domains?

Updated 9 October 2026 · 4 min read

Guest list Seal Rules

In Crazy Domains, you add SPF, DKIM and DMARC on your domain's DNS Settings tab in the Account Manager, using the ADD RECORD button. SPF and DMARC are TXT records, and DKIM is a CNAME or TXT record depending on your email service.

These three records work together. SPF lists the services allowed to send your email. DKIM adds a digital signature that proves an email came from your domain. DMARC tells receivers what to do when an email fails both, and sends you reports about it. Without them, Outlook, Microsoft 365 and Gmail have no way to confirm your email is genuine, so more of it ends up in junk.

Step 1: Check where your DNS is managed

Crazy Domains has more than one place to manage DNS. Which one counts depends on your domain's name servers (the servers that tell the internet where your DNS lives):

Name serversWhere you add records
ns1.crazydomains.com, ns2.crazydomains.comAccount Manager → Domain Manager → DNS Settings
ns1.dnspackage.com, ns2.dnspackage.com (Premium DNS)The same DNS Settings in the Account Manager (changes sync to the Premium DNS product)
ns1.syrahost.com, ns2.syrahost.comYour hosting control panel: cPanel (Zone Editor) for Linux hosting, Plesk for Windows hosting

You can see your name servers with any WHOIS lookup. If they point somewhere else entirely, such as Microsoft or your web designer's host, add the records there instead.

You don't need Premium DNS for any of this. Crazy Domains' own guide lists TXT and CNAME records as part of Standard DNS.

Step 2: Get the host name format right

This is where most mistakes happen. The two Crazy Domains screens want host names in different formats.

Account Manager (DNS Settings): the Sub Domain field takes only the part before your domain.

  • For the main domain, yourbusiness.com.au, leave it empty. Crazy Domains says empty is the same as @ elsewhere.
  • For DMARC, enter _dmarc.
  • For Microsoft 365 DKIM, enter selector1._domainkey (and selector2._domainkey for the second record).

cPanel (Zone Editor): the Name column takes the full name, such as _dmarc.yourbusiness.com.au.

If you put the full name into the Account Manager's Sub Domain field, you'll end up with a record at _dmarc.yourbusiness.com.au.yourbusiness.com.au, and receivers won't find it.

Step 3: Add or update your SPF record

  1. Open your domain's DNS Settings tab.
  2. Look for a TXT record on the main domain that starts with v=spf1. If there is one, select Edit and change it. Don't add a second. A domain can only have one SPF record, and two break SPF completely.
  3. If there's none, select ADD RECORD, choose TXT Record from Choose Type, and leave Sub Domain empty.
  4. In Content, enter your SPF record. For Microsoft 365:
v=spf1 include:spf.protection.outlook.com ~all
  1. Select SAVE RECORD.

If another service also sends email as you, add its include to the same line, before ~all. Use the exact value from that service's help pages. Keep the total under 10 DNS lookups. Each include: uses at least one.

Step 4: Add your DKIM records

Your email service creates the DKIM key, and you publish it. Each service that sends as you needs its own.

Microsoft 365 gives you two CNAME records in the Defender portal. For each one:

  1. Select ADD RECORD and choose CNAME Record.
  2. In Sub Domain, enter selector1._domainkey (then selector2._domainkey for the second).
  3. In Hostname, paste the value Microsoft shows. It ends in either .onmicrosoft.com or .dkim.mail.microsoft, depending on when your domain was added.
  4. Select SAVE RECORD.

Then go back to Microsoft 365 and switch on DKIM signing. Our guide to setting up DKIM in Microsoft 365 covers that part.

Other services (Xero, MYOB, your website's email service or a newsletter tool) may give you CNAME records or a TXT record. Add whatever type they show, with only the prefix in Sub Domain. Paste values exactly; one missing character breaks the key.

Step 5: Add a DMARC record

  1. Select ADD RECORD and choose TXT Record.
  2. In Sub Domain, enter _dmarc.
  3. In Content, enter:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au
  1. Select SAVE RECORD.

p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you actually read. Once the reports show all your genuine email passing, change p=none to p=quarantine.

Add SPF and DKIM first. A DMARC record on its own doesn't make your email pass anything.

Step 6: Check it worked

Crazy Domains says new records can take up to 48 hours to work, and up to 72 hours for cPanel. Once they've had time, send an email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for your own domain), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.

Checked against: Crazy Domains Help, Manage DNS records in Account Manager · Crazy Domains Help, Crazy Domains DNS · Crazy Domains Help, Standard and Premium Name Servers · Crazy Domains Help, Manage DNS Records in cPanel · RFC 7489, Domain-based Message Authentication, Reporting, and Conformance (DMARC).

Questions people ask

Do I need Crazy Domains Premium DNS to add TXT records?

No. Crazy Domains' guide to its name servers lists TXT and CNAME among the records Standard DNS supports. Premium DNS adds extras such as SRV records and forwarding. If TXT doesn't appear in the Choose Type list for your domain, ask Crazy Domains support.

What do I put in the Sub Domain field for my main domain?

Leave it empty. Crazy Domains says an empty Sub Domain field is the same as @ at other providers. For DMARC enter _dmarc, and for DKIM enter the selector name your email service gives you, such as selector1._domainkey.

I added the records but nothing changed. Why?

Check your name servers first. Records in your Account Manager only work if the domain uses ns1.crazydomains.com and ns2.crazydomains.com (or the Premium DNS name servers). If it uses ns1.syrahost.com and ns2.syrahost.com, your records live in cPanel or Plesk instead.

Should I start DMARC at p=quarantine or p=reject?

Start at p=none with a rua address so you get reports without changing what happens to your email. Once the reports show all your genuine email passing, move to p=quarantine.