To set up email authentication for Zoho Mail, you add an SPF record that includes Zoho's servers for your region, a DKIM TXT record that Zoho generates in the Admin Console, and a DMARC record, all at the company that hosts your DNS. Then you verify each one in the Admin Console and switch on DKIM signing, so Outlook, Microsoft 365, Gmail and Yahoo can confirm your email really comes from yourbusiness.com.au.
Three records do three jobs:
- SPF is a list of the servers allowed to send email for your domain.
- DKIM is a digital signature on every email, checked against a key in your DNS.
- DMARC tells receivers what to do when SPF and DKIM both fail, and sends you reports.
Before you start
You need:
- An administrator login for Zoho Mail. Only an Administrator or Super Administrator can open the Admin Console.
- Access to your DNS. DNS is the public set of records for your domain. It's usually managed where you bought the domain, such as VentraIP, Crazy Domains or GoDaddy, or with Cloudflare.
Zoho's help says that if your domain is registered with one company but its name servers point to another, only records added where the name servers point will work. Add everything there.
Step 1: Find out which Zoho region you're in
Zoho keeps your account in one data centre, such as the US, Australia, Europe or India. Each one sends from its own servers, so the SPF value can differ. The quickest clue is the address you use to sign in.
| If you sign in at | Admin Console | SPF include to look for |
|---|---|---|
| zoho.com | mailadmin.zoho.com | include:zohomail.com |
| zoho.com.au | mailadmin.zoho.com.au | include:zohomail.com.au |
| zoho.eu | mailadmin.zoho.eu | include:zohomail.eu |
| zoho.in | mailadmin.zoho.in | include:zohomail.in |
Zoho's help pages publish only the US value, include:zohomail.com, and note that some record values vary by data centre. The other values in the table follow the same pattern, but treat them as a guide. The Admin Console always shows the exact value for your account (Step 2), and that's the one to use.
You can also reach the Admin Console from your mailbox: click your profile picture in the top-right corner and choose Admin Console.
Step 2: Add your SPF record
- In the Admin Console, select Domains in the left pane and choose yourbusiness.com.au.
- Open Email Configuration and select SPF. This is where Zoho shows the SPF details for your domain. If you can't see the value, click Send to DNS admin and send Zoho's SPF instructions to your own address.
- At your DNS host, add a TXT record:
| Type | Host name | Value |
|---|---|---|
| TXT | @ | v=spf1 include:zohomail.com ~all |
Replace zohomail.com with the value for your region. Some DNS hosts want the host name left blank instead of @.
A domain can only have one SPF record. If you already have one, don't add a second. Edit the existing record and add Zoho's include before the ~all at the end. For example, if your website or invoicing service is already listed:
v=spf1 include:zohomail.com include:otherservice.com ~all
Two SPF records break SPF for both. Zoho's help warns your email can then be treated as spam.
Go back to Email Configuration → SPF and click Verify SPF Record.
Step 3: Create your DKIM key
- In the Admin Console, select Domains and choose yourbusiness.com.au.
- In the Email Configuration tab, select DKIM.
- Click Add to add a selector. A selector is just a name for this key. Zoho's example is
zoho. - Choose a key length of 1024 or 2048 bits. 2048 is the stronger choice.
- Click Add. Zoho shows a TXT record value next to the selector. Copy all of it.
Don't click Verify yet. The record has to be in your DNS first.
Step 4: Add the DKIM record to your DNS
| Type | Host name | Value |
|---|---|---|
| TXT | zoho._domainkey | the full value Zoho shows (starts with v=DKIM1) |
If you chose a different selector, use it in place of zoho.
Watch the host name. Most DNS hosts add your domain to the end automatically, so you type only zoho._domainkey. If yours wants the full name, type zoho._domainkey.yourbusiness.com.au. Typing the full name into a host that adds it for you ends up with the domain twice, and Zoho won't find the record.
Paste the whole value with no line breaks or missing characters. A cut-off key is a common reason DKIM fails.
Step 5: Verify and switch on DKIM
- Go back to Email Configuration → DKIM in the Admin Console.
- Click Verify next to your selector.
- When it's verified, Zoho asks whether to enable DKIM now or later. Enable it now.
Once enabled, Zoho signs all email sent from yourbusiness.com.au. If verifying fails, give DNS more time. Zoho says changes can take 12 to 24 hours, depending on your TTL (how long DNS servers cache a record).
Zoho's help notes that DKIM only signs email sent from Zoho directly to other mail servers. If your Zoho email is routed through an outbound gateway or another mail filter, Zoho doesn't sign it.
Step 6: Add a DMARC record
Zoho can build a DMARC record for you. In the Admin Console, select Domains, choose your domain, then in the Email Configuration tab select DMARC. Choose Do nothing to the email (Phase 1), enter an aggregate report address, and click Generate.
That gives you a record like this, which you add at your DNS host:
| Type | Host name | Value |
|---|---|---|
| TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com.au |
Change the rua address to a mailbox you read. p=none starts DMARC in monitoring mode, so nothing changes for your email yet. Zoho recommends rolling it out in phases: once your reports show all your genuine email passing, move to p=quarantine, then p=reject.
A domain must have exactly one DMARC record. If you already have one, edit it rather than adding another. Two records make DMARC fail completely.
Back in the Admin Console, click Verify.
Step 7: Check it worked
The Admin Console tells you the records exist. It doesn't tell you how Outlook or Microsoft 365 treat a real email. For that, send an email from your Zoho mailbox to someone outside your organisation and check that:
- SPF passes for yourbusiness.com.au.
- DKIM passes, signed by yourbusiness.com.au.
- DMARC passes, lined up through SPF, DKIM or both.
The free test does this in one step. Send an email from Zoho to your private test address and you get a verdict for Outlook.com, Microsoft 365, Gmail, Google Workspace and Yahoo, with the exact record to fix if something is wrong.
What this doesn't cover
These steps cover email sent from your Zoho Mail mailboxes. If Xero, MYOB, your website or a newsletter service also sends as yourbusiness.com.au, each one needs its own include in your single SPF record and its own DKIM, set up inside that service.
MX records, which decide where your incoming email is delivered, are a separate job and aren't covered here.
Checked against: Zoho Mail Help, Sender Policy Framework (SPF) · Zoho Mail Help, DKIM - DomainKeys Identified Mail · Zoho Mail Help, DMARC overview · Zoho Mail Help, Configure email delivery (MX records) · Zoho Mail Help, Admin Console overview.