How do I add SPF, DKIM and DMARC records in VentraIP?

Updated 9 October 2026 · 4 min read

Guest list Seal Rules

In VentraIP, you add SPF, DKIM and DMARC in VIPcontrol: go to My Services → Domains, click DNS next to your domain, and add each record at the top of the DNS records table. SPF and DMARC are TXT records, and DKIM is a CNAME or TXT record depending on your email service.

These three records work together. SPF lists the services allowed to send your email. DKIM adds a digital signature that proves an email came from your domain. DMARC tells receivers what to do when an email fails both, and sends you reports about it. Without them, more of your email ends up in junk.

Step 1: Check where your DNS is managed

Records you add in VIPcontrol only work if your domain's nameservers (the servers that tell the internet where your DNS lives) are VentraIP's.

Your domain usesWhere you add records
VentraIP DNS HostingVIPcontrol → My Services → Domains → DNS
Your VentraIP cPanel web hosting nameserversThe same DNS screen in VIPcontrol, or cPanel → Zone Editor
Custom nameservers, such as Cloudflare or another hostAt that provider, not VentraIP

You can see your nameservers with any WHOIS lookup. Your hosting nameservers are also in your hosting welcome email.

Don't switch DNS options just to add a record. VentraIP warns that turning on DNS Hosting, VentraIP Hosting or Custom Nameservers immediately replaces all your existing records, and your website and email can stop working.

Step 2: Get the host name right

In VIPcontrol, each new record has a Type drop-down, a Hostname field and a Value field (and a TTL you can leave as it is). The Hostname field takes only the part before your domain:

  • For the main domain, yourbusiness.com.au, leave Hostname blank. VentraIP says blank means the root domain. (Some VentraIP guides show this as @.)
  • For DMARC, enter _dmarc.
  • For Microsoft 365 DKIM, enter selector1._domainkey (and selector2._domainkey for the second record).

If you type the full name, such as _dmarc.yourbusiness.com.au, you may end up with a record at _dmarc.yourbusiness.com.au.yourbusiness.com.au, and receivers won't find it. Look at how your existing records appear in the table and match that. cPanel's Zone Editor shows records by their full name, so follow its format if you use cPanel instead.

Step 3: Add or update your SPF record

  1. Open your domain's DNS screen in VIPcontrol.
  2. Look for a TXT record on the main domain that starts with v=spf1. If there is one, click the pencil icon to edit it. Don't add a second. A domain can only have one SPF record, and two break SPF completely.
  3. If there's none, go to the top of the table, choose TXT as the Type and leave Hostname blank.
  4. In Value, enter your SPF record. For Microsoft 365:
v=spf1 include:spf.protection.outlook.com ~all
  1. Click the plus icon to add it.

The value depends on who sends your email:

Email serviceSPF value
Microsoft 365v=spf1 include:spf.protection.outlook.com ~all
Google Workspacev=spf1 include:_spf.google.com ~all
VentraIP Email Hostingv=spf1 +a +mx +include:spf.email-hosting.net.au ~all

If more than one service sends email as you, combine them into the same record, before ~all. Use the exact value from each service's help pages, and keep the total under 10 DNS lookups. Each include: uses at least one.

Step 4: Add your DKIM records

Your email service creates the DKIM key, and you publish it. Each service that sends as you needs its own.

Microsoft 365 gives you two CNAME records in the Defender portal. For each one:

  1. Choose CNAME as the Type.
  2. In Hostname, enter selector1._domainkey (then selector2._domainkey for the second).
  3. In Value, paste the value Microsoft shows. It ends in either .onmicrosoft.com or .dkim.mail.microsoft, depending on when your domain was added.
  4. Click the plus icon.

Then go back to Microsoft 365 and switch on "Sign messages for this domain with DKIM signatures". Our guide to setting up DKIM in Microsoft 365 covers that part.

Google Workspace gives you a TXT record in the Google Admin console (Apps → Google Workspace → Gmail → Authenticate email). Add it with google._domainkey as the Hostname, then click "Start authentication" in Google.

VentraIP Email Hosting shows its DKIM record in VIPcontrol. Go to My Services → Email Hosting, click Manage next to your email service and scroll down to the DKIM record. Add it as a TXT record, copying the hostname and value exactly as shown.

VIPcontrol also has DNS Presets (the Add App Preset button) for Microsoft 365, Google Workspace and VentraIP Email Hosting. A preset is a quick start, but DKIM keys are unique to your account. After applying one, check that you have exactly one SPF record and that your DKIM records are there.

Step 5: Add a DMARC record

  1. Choose TXT as the Type.
  2. In Hostname, enter _dmarc.
  3. In Value, enter:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au
  1. Click the plus icon.

p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you read. Once the reports show all your genuine email passing, change p=none to p=quarantine.

Add SPF and DKIM first. A DMARC record on its own doesn't make your email pass anything.

Step 6: Check it worked

VentraIP says VIPcontrol changes take around 2 to 8 hours to spread, and cPanel changes up to 24 hours. Then send an email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for your own domain), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.

Checked against: VentraIP Support Centre, Adding, removing, and managing DNS records within VIPcontrol · VentraIP Support Centre, Managing your Domains Nameservers & DNS with VentraIP · VentraIP Support Centre, Adding, removing, and managing DNS records in cPanel · VentraIP Support Centre, MX and SPF Records Required for Business Email Hosting · VentraIP Support Centre, Set up DKIM on dedicated email hosting · Microsoft Learn, How to use DKIM for email in your custom domain.

Questions people ask

Do I need VentraIP web hosting to add DNS records?

No. VentraIP says every domain registration includes DNS management in VIPcontrol. Your domain just has to use VentraIP's DNS Hosting or your VentraIP cPanel hosting nameservers.

What do I put in the Hostname field for my main domain?

Leave it blank. VentraIP's guide says a blank Hostname means the root domain, yourbusiness.com.au. For DMARC enter _dmarc, and for DKIM enter the selector name your email service gives you, such as selector1._domainkey.

I added the records but nothing changed. Why?

Check your nameservers first. If they point to another provider, such as Cloudflare, VIPcontrol's records aren't used, so add them there. Otherwise allow time, as VentraIP says changes take around 2 to 8 hours.

Should I start DMARC at p=quarantine or p=reject?

Start at p=none with a rua address, so you get reports without changing what happens to your email. Once the reports show all your genuine email passing, move to p=quarantine.