In VentraIP, you add SPF, DKIM and DMARC in VIPcontrol: go to My Services → Domains, click DNS next to your domain, and add each record at the top of the DNS records table. SPF and DMARC are TXT records, and DKIM is a CNAME or TXT record depending on your email service.
These three records work together. SPF lists the services allowed to send your email. DKIM adds a digital signature that proves an email came from your domain. DMARC tells receivers what to do when an email fails both, and sends you reports about it. Without them, more of your email ends up in junk.
Step 1: Check where your DNS is managed
Records you add in VIPcontrol only work if your domain's nameservers (the servers that tell the internet where your DNS lives) are VentraIP's.
| Your domain uses | Where you add records |
|---|---|
| VentraIP DNS Hosting | VIPcontrol → My Services → Domains → DNS |
| Your VentraIP cPanel web hosting nameservers | The same DNS screen in VIPcontrol, or cPanel → Zone Editor |
| Custom nameservers, such as Cloudflare or another host | At that provider, not VentraIP |
You can see your nameservers with any WHOIS lookup. Your hosting nameservers are also in your hosting welcome email.
Don't switch DNS options just to add a record. VentraIP warns that turning on DNS Hosting, VentraIP Hosting or Custom Nameservers immediately replaces all your existing records, and your website and email can stop working.
Step 2: Get the host name right
In VIPcontrol, each new record has a Type drop-down, a Hostname field and a Value field (and a TTL you can leave as it is). The Hostname field takes only the part before your domain:
- For the main domain, yourbusiness.com.au, leave Hostname blank. VentraIP says blank means the root domain. (Some VentraIP guides show this as @.)
- For DMARC, enter
_dmarc. - For Microsoft 365 DKIM, enter
selector1._domainkey(andselector2._domainkeyfor the second record).
If you type the full name, such as _dmarc.yourbusiness.com.au, you may end up with a record at _dmarc.yourbusiness.com.au.yourbusiness.com.au, and receivers won't find it. Look at how your existing records appear in the table and match that. cPanel's Zone Editor shows records by their full name, so follow its format if you use cPanel instead.
Step 3: Add or update your SPF record
- Open your domain's DNS screen in VIPcontrol.
- Look for a TXT record on the main domain that starts with
v=spf1. If there is one, click the pencil icon to edit it. Don't add a second. A domain can only have one SPF record, and two break SPF completely. - If there's none, go to the top of the table, choose TXT as the Type and leave Hostname blank.
- In Value, enter your SPF record. For Microsoft 365:
v=spf1 include:spf.protection.outlook.com ~all
- Click the plus icon to add it.
The value depends on who sends your email:
| Email service | SPF value |
|---|---|
| Microsoft 365 | v=spf1 include:spf.protection.outlook.com ~all |
| Google Workspace | v=spf1 include:_spf.google.com ~all |
| VentraIP Email Hosting | v=spf1 +a +mx +include:spf.email-hosting.net.au ~all |
If more than one service sends email as you, combine them into the same record, before ~all. Use the exact value from each service's help pages, and keep the total under 10 DNS lookups. Each include: uses at least one.
Step 4: Add your DKIM records
Your email service creates the DKIM key, and you publish it. Each service that sends as you needs its own.
Microsoft 365 gives you two CNAME records in the Defender portal. For each one:
- Choose CNAME as the Type.
- In Hostname, enter
selector1._domainkey(thenselector2._domainkeyfor the second). - In Value, paste the value Microsoft shows. It ends in either
.onmicrosoft.comor.dkim.mail.microsoft, depending on when your domain was added. - Click the plus icon.
Then go back to Microsoft 365 and switch on "Sign messages for this domain with DKIM signatures". Our guide to setting up DKIM in Microsoft 365 covers that part.
Google Workspace gives you a TXT record in the Google Admin console (Apps → Google Workspace → Gmail → Authenticate email). Add it with google._domainkey as the Hostname, then click "Start authentication" in Google.
VentraIP Email Hosting shows its DKIM record in VIPcontrol. Go to My Services → Email Hosting, click Manage next to your email service and scroll down to the DKIM record. Add it as a TXT record, copying the hostname and value exactly as shown.
VIPcontrol also has DNS Presets (the Add App Preset button) for Microsoft 365, Google Workspace and VentraIP Email Hosting. A preset is a quick start, but DKIM keys are unique to your account. After applying one, check that you have exactly one SPF record and that your DKIM records are there.
Step 5: Add a DMARC record
- Choose TXT as the Type.
- In Hostname, enter
_dmarc. - In Value, enter:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au
- Click the plus icon.
p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you read. Once the reports show all your genuine email passing, change p=none to p=quarantine.
Add SPF and DKIM first. A DMARC record on its own doesn't make your email pass anything.
Step 6: Check it worked
VentraIP says VIPcontrol changes take around 2 to 8 hours to spread, and cPanel changes up to 24 hours. Then send an email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for your own domain), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.
Checked against: VentraIP Support Centre, Adding, removing, and managing DNS records within VIPcontrol · VentraIP Support Centre, Managing your Domains Nameservers & DNS with VentraIP · VentraIP Support Centre, Adding, removing, and managing DNS records in cPanel · VentraIP Support Centre, MX and SPF Records Required for Business Email Hosting · VentraIP Support Centre, Set up DKIM on dedicated email hosting · Microsoft Learn, How to use DKIM for email in your custom domain.