Zoho Mail SPF, DKIM and DMARC: the records to add and where Zoho shows them
The SPF value Zoho Mail requires, where the DKIM selector and key come from in the Admin Console, the DMARC record to publish, and how to verify all three.
On this page
A Zoho Mail domain needs three TXT records: an SPF record at the root of the domain with Zoho's include, a DKIM record whose selector and key you generate in the Zoho Mail Admin Console, and a DMARC record at _dmarc that starts at p=none with a reporting address. Zoho's SPF help (opens in a new tab) gives the SPF value as v=spf1 include:zohomail.com -all, with ~all accepted as a soft-fail alternative. Zoho's DKIM help (opens in a new tab) has you add a selector, publish the generated key as a TXT record and then verify and enable it, and Zoho's DMARC help (opens in a new tab) asks for SPF and DKIM to be in place before you publish the DMARC policy. The sections below give each record, the Admin Console path, and the checks.
The three records at a glance
| Record | Host | Value | Where it comes from |
|---|---|---|---|
| SPF | @ |
v=spf1 include:zohomail.com -all (or ~all) |
Zoho's SPF help (opens in a new tab) |
| DKIM | <selector>._domainkey |
the key Zoho generates for that selector | Zoho's DKIM help (opens in a new tab): Admin Console, Domains, Email Configuration, DKIM |
| DMARC | _dmarc |
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com |
Zoho's DMARC help (opens in a new tab) or the DMARC generator |
Under Zoho's documentation, TXT records only count at the provider where your name servers point, and DNS changes can take 12 to 24 hours to take effect depending on the TTL. After adding each record at your DNS host, you still have to verify it in the Admin Console.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.
SPF for Zoho Mail
SPF (Sender Policy Framework) lists the servers allowed to send email for your domain. Zoho's SPF help (opens in a new tab) publishes the record as a TXT record with host @ and value v=spf1 include:zohomail.com -all; zohomail.com is a host name that includes the set of IP addresses Zoho's service sends from, and -all means no other server sends for the domain. Zoho also accepts ~all, a soft fail, if other servers send as the same domain. Checked against live DNS, zohomail.com publishes v=spf1 include:spf.zohomail.com -all, and spf.zohomail.com carries the IPv4 ranges.
If you use several Zoho services, Zoho's help gives v=spf1 include:one.zoho.com -all to avoid SPF lookup failures. Checked against live DNS, one.zoho.com publishes its own SPF record with three further includes.
Keep a single SPF record. Zoho's help allows only one, warns that multiple records interrupt the SPF check and can land mail in spam, and tells you to remove the other SPF records if Zoho Mail is your only sender. RFC 7208 (opens in a new tab) states the same rule for every domain: a domain must not have multiple records that an authorization check would select. Other senders join the same record as additional includes ahead of include:zohomail.com, as Zoho's own examples show, and Zoho's help repeats the limit of 10 DNS lookups.
Zoho's China help site (opens in a new tab) gives a different SPF value: v=spf1 include:zoho.com -all.
To verify, Zoho's help has you log in to the Admin Console as an administrator or super administrator, open Domains, go to Email Configuration, select SPF and click Verify SPF Record.
DKIM in the Zoho Mail Admin Console
DKIM (DomainKeys Identified Mail) signs outgoing mail so receivers can confirm it was not changed. Zoho's DKIM help (opens in a new tab) describes three steps: generate a key under a selector in Zoho Mail, create a TXT record at your DNS host, then validate the selector and enable DKIM. The path is Admin Console, Domains, choose the domain, Email Configuration, DKIM.
Click Add, give the selector a name (Zoho's example is zoho), choose 1024 or 2048 bits, and click Add. Zoho generates the TXT record and shows it next to the selector. Create a TXT record named <selector>._domainkey.<yourdomain>, for example zoho._domainkey.example.com; Zoho notes that hosts such as GoDaddy, Wix, Squarespace and Namecheap append the domain automatically, so there you enter zoho._domainkey. Paste the entire value from the TXT Record Value field. RFC 6376 (opens in a new tab) defines that name: all DKIM keys live under _domainkey, and the receiver queries the selector from the signature's s= tag under _domainkey in the domain from its d= tag.
Then click Verify next to the selector. Once verified, Zoho prompts you to enable DKIM immediately or later; once enabled, Zoho signs all outgoing mail from the domain with the default selector. Publishing the key and switching signing on are two different steps, so a key in DNS alone does not mean mail is signed.
Two limits from Zoho's documentation: DKIM is supported only for mail generated in Zoho and delivered directly to external servers, not for domains using email routing or outbound gateways; and any server that alters the message in transit can invalidate the signature at the receiving end. If a receiver reports dkim=fail, the reason in brackets tells you which fix applies; see DKIM fail.
DMARC
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do with mail that fails SPF and DKIM and where to send reports. Zoho's DMARC help (opens in a new tab) asks you to configure SPF and DKIM before publishing DMARC, recommends a phased rollout from p=none to quarantine to reject, and warns that mail sent for your domain by third-party services appears unauthenticated and may be rejected under the published policy. At p=none mail is delivered as usual and reports go to the address in the record.
Start with a monitoring record built in the DMARC generator, published as a TXT record at _dmarc.example.com:
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
RFC 7489 (opens in a new tab) defines p=none as a request for no specific delivery action and rua as the addresses for aggregate feedback; subdomains follow p unless sp sets a different policy. Zoho's Admin Console can also generate a DMARC record under Domains, Email Configuration, DMARC, with the three phases offered as options and a field for the aggregate report address; the generated record then goes into your DNS as a TXT record and is verified from the console. Zoho's documentation adds that only one DMARC record may exist for the domain, that two records cause a permanent error, and that without a record DMARC processing stops and the mail is delivered without source verification.
If a checker reports that no record was found, see No DMARC record found. For what p=none does and does not do, and the safe order to move to quarantine or reject, see DMARC policy not enabled.
Check your domain
The free SPF, DKIM and DMARC check reads the public DNS records of the domain you enter and flags a missing SPF record, ~all, a record near the 10-lookup limit, a missing DMARC record or one at p=none without a reporting address. For DKIM it looks for keys under commonly used selectors; if your selector is not among them, the key is there but the check cannot see it. The Admin Console shows the selector you chose. A DNS finding shows how the domain is set up, not where a particular message landed.
Sources
- Zoho Mail help: SPF configuration (opens in a new tab)
- Zoho Mail help (China): SPF configuration (opens in a new tab)
- Zoho Mail help: DKIM configuration (opens in a new tab)
- Zoho Mail help: DMARC policy (opens in a new tab)
- RFC 7208 section 3.2: one SPF record per domain (opens in a new tab)
- RFC 6376 section 3.6.2: the DKIM key name (opens in a new tab)
- RFC 7489 section 6.3: DMARC record tags (opens in a new tab)
Tools for this
-
SPF, DKIM and DMARC check
Check the email records a domain publishes today and see what to fix first.
-
DMARC record generator
Build a DMARC record step by step, from monitoring to reject.
Frequently asked questions
Which Zoho SPF include do I use?
Zoho's help gives include:zohomail.com for Zoho Mail, and include:one.zoho.com when you send through several Zoho services. Zoho's China help site gives include:zoho.com.
Why does Zoho say DKIM is not verified after I added the record?
Zoho only marks the selector verified after you click Verify in the Admin Console, and DNS changes can take 12 to 24 hours to take effect depending on the TTL. Check that the record name is selector._domainkey.yourdomain and that the whole key value was pasted.
Do I need DMARC if Zoho already handles SPF and DKIM?
Yes. SPF and DKIM authenticate the mail; DMARC tells receivers what to do when both fail and where to send reports. Zoho asks you to configure SPF and DKIM first and then publish DMARC, starting with p=none.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.