In Wix, you add SPF, DKIM and DMARC by going to Domains in your Wix account, opening the Domain Actions menu next to your domain and choosing Manage DNS Records. This only works if your domain is connected to Wix by name servers; if it's connected by pointing, the records go in at your domain host instead.
SPF lists the services allowed to send your email. DKIM adds a digital signature that proves an email came from your domain. DMARC tells receivers what to do when an email fails both, and sends you reports. Without them, Outlook, Microsoft 365 and Gmail can't confirm your email is genuine, so more of it lands in junk.
The records are for whichever service sends your email, such as Microsoft 365 or Google Workspace, not for Wix itself.
Step 1: Check how your domain is connected
Wix connects a domain in one of two ways, and they decide where your DNS records live:
| Connection | Who hosts your DNS | Where you add the records |
|---|---|---|
| Name servers (the domain uses Wix's name servers, which end in wixdns.net) | Wix | Wix: Domains → Domain Actions → Manage DNS Records |
| Pointing (the domain keeps its own name servers and points to Wix) | Your domain host, such as GoDaddy or Crazy Domains | Your domain host's DNS settings |
If you bought your domain from Wix, its DNS is normally managed in Wix too. Wix says that with pointing, it can't help you manage your DNS records because they're hosted elsewhere. You can still add every record below; just do it at your domain host.
What Wix's DNS editor can and can't do
- It handles the record types you need: TXT and CNAME (plus A, MX, SPF, SRV and NS).
- Host names such as
_dmarcandselector1._domainkeyare fine. Wix's own DKIM guide has you enter the selector in Host Name. - There's a separate SPF row. Don't use it. Wix says the SPF record type is no longer used by all platforms, so add SPF in the TXT (Text) section.
- Microsoft's Wix guide says Wix doesn't support DNS entries for subdomains. If a service wants a separate sending subdomain, ask Wix support first.
Wix recommends leaving TTL (how long other servers remember a record) at the default.
The records you need
| Record | Section in Wix | Host Name | Value |
|---|---|---|---|
| SPF | TXT (Text) | Leave blank | v=spf1 include:spf.protection.outlook.com ~all |
| DKIM (Microsoft 365) | CNAME (Aliases) | selector1._domainkey | Copied from the Defender portal |
| DKIM (Microsoft 365) | CNAME (Aliases) | selector2._domainkey | Copied from the Defender portal |
| DMARC | TXT (Text) | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au |
The SPF value is for Microsoft 365; other services give you their own include. In Host Name, enter only the part before your domain.
Step 2: Add or update your SPF record
- Go to Domains in your Wix account.
- Select the Domain Actions icon next to your domain, then Manage DNS Records.
- Look in the TXT (Text) section for a record that starts with
v=spf1. If there is one, hover over it, select Edit and change the value. A domain can only have one SPF record. - If there's none, select + Add Record in the TXT (Text) section and leave Host Name blank.
- Paste your SPF record into Value and select Save.
If another service also sends as you, add its include to the same line, before ~all.
Step 3: Add your DKIM records
Microsoft 365 gives you two CNAME records in the Defender portal, under Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM. For each one:
- Select + Add Record in the CNAME (Aliases) section, then Got it in the pop-up.
- Enter
selector1._domainkeyin Host Name (thenselector2._domainkey). - Paste Microsoft's value into Value. It ends in either
.onmicrosoft.comor.dkim.mail.microsoft. - Select Save, then Save Changes in the pop-up.
Then switch on DKIM signing in the Defender portal. Our guide to setting up DKIM in Microsoft 365 covers that part.
Google Workspace and some other services give you DKIM as a TXT record instead. Add it in the TXT (Text) section, with the selector (such as google._domainkey) in Host Name and the key in Value. Paste it exactly; one missing character breaks the key.
Step 4: Add a DMARC record
First, look for an existing record at _dmarc. If you've authenticated your domain for Wix Email Marketing, Wix says that also sets up a DMARC record, and a domain can only have one.
If there's none:
- Select + Add Record in the TXT (Text) section.
- Enter
_dmarcin Host Name. - Enter this in Value:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au
- Select Save.
p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you read. Once the reports show all your genuine email passing, change p=none to p=quarantine.
Step 5: Check it worked
Microsoft says DNS changes typically take about 15 minutes, and Wix says to allow up to 48 hours. Once they've had time, send an email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for your own domain), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.
Checked against: Wix Help, Managing DNS Records in Your Wix Account · Wix Help, Adding or Updating TXT Records in Your Wix Account · Wix Help, Adding or Updating CNAME Records in Your Wix Account · Wix Help, Adding or Updating SPF Records in Your Wix Account · Wix Help, Adding a DKIM (TXT) Record · Wix Help, Pointing vs. Name Servers Domain Connection Methods · Wix Help, Connecting Email Purchased Outside of Wix · Wix Help, Connecting Your GoDaddy Domain to Wix · Wix Help, Email Marketing, Authenticating Your Custom Email Domain · Microsoft Learn, Connect your DNS records at Wix to Microsoft 365.