KNOWLEDGEBASE · EMAIL
cPanel Email Deliverability Tool – SPF and DKIM Records
Last updated 2022-06-20
As you may know, if mail service is unauthenticated you can face the following issues:
-
- emails you send are delivered to Spam/Junk folders
- emails you send bounce with "SPF record failure" error
- your Inbox gets numerous "Failed delivery" bouncebacks of the emails you never sent
In the first case, the recipient mail server looks up the SPF record for your domain, and if it is not added/does not match the actual outgoing server IP address, such a mail delivery will fail. Such a checking mechanism is implemented in order to make sure email comes from a legitimate sender and verified sender.
- SPF record
The main idea of SPF record is that an owner of the domain name publishes the information about IP addresses that are authorized to send mail from this domain name. The receiving server compares the information in the envelope sender address with the information published by the domain name owner. If these details match then the e-mail is delivered.
NOTES:
- SPF is not added to the domain DNS zone automatically. Thus, it is required to configure the proper record from the Email Deliverability menu.
- Sometimes cPanel automatically fetches incorrect server outgoing IP address. This happens when we have to change outgoing mail IP due to poor mail reputation or blacklists. Get in touch with us and we will gladly re-check if the correct IP is added to your SPF record.
- SPF record has its own specific syntax. It is strongly recommended to get familiar with SPF record syntax documentation if you are going to customize the record manually.
- SPF record is added to your domain DNS zone as TXT record. There are cases when you need to add another TXT record to verify your domain name ownership for some service. It is not recommended to modify existing SPF record, it is better to add a new one instead.
- DKIM Record
Once TXT record which contains DKIM has been added to DNS zone, a special code is added to the headers of outgoing e-mails. Receiving servers compare these headers with the information in DNS zone and if it matches then the e-mail is delivered.
NOTE: DomainKeys(DK) and DomainKeys Identified Mail (DKIM) are separate things.
DomainKeys(DK) are not available on our shared servers as DK implementation was converted to DKIM and extended in a number of ways as of cPanel 11.32 and later releases.
Some of the differences between DomainKeys and DKIM include:
- multiple signature algorithms (as opposed to just one available with DomainKeys)
- more options with regard to canonicalization, that validates both header and body
- the ability to delegate signing to third parties
- the ability for DKIM to self-sign the DKIM-Signature header field – to protect against its being modified
- the ability for wildcard option on some parameters
- the ability to support signature timeouts in DNS
These simple actions will let you be sure that no one is able to send spam on your behalf and your e-mail will not be delivered to spam folders.
- This option is unavailable if the system does not control the domain's DNS records. Thus, you will be able to use the Repair option only in case your domain name is pointed to our Shared hosting nameservers.
- You cannot simultaneously update two or more domains whose records exist on the same zone. The bulk records update is possible only in case domains' records exist on separate zones.
- Reloading the interface does not interrupt the repair process.
2. IP Address Settings - this section allows you to add additional IP Address blocks to your SPF record. The system automatically includes your server's main IPv4 or IPv6 addresses in these lists:
Note. However, these functions will not work if the domain or subdomain is not using our DNS manager and our nameservers. So you will need to copy those suggested records and manually update your DNS records on DNS manager of the provider’s nameservers you use.
Tell us what has to stay up.
A short conversation with an engineer. No quote-bot, no callback queue. We'll tell you honestly if we're not the right fit.