SPF, DKIM and DMARC by provider
The records each provider needs, the selectors it signs with, and what to check once they are published.
Providers
- Google Workspace SPF, DKIM and DMARC
The three records Google Workspace needs, and how to check they are live.
- Microsoft 365 SPF, DKIM and DMARC
Both DKIM selectors, the right CNAME target, and the records Exchange Online needs.
- SendGrid SPF, DKIM and DMARC
What SendGrid domain authentication publishes, and why your root SPF usually stays untouched.
- Mailchimp SPF, DKIM and DMARC
Two CNAMEs and a DMARC record — and one SPF include you can probably delete.
- Klaviyo SPF, DKIM and DMARC
Delegate a sending subdomain to Klaviyo — by NS or by CNAME — and let it publish SPF and DKIM for you.
Sending through something else? The full deliverability test detects your providers and probes their selectors automatically. Mail sent by your website rather than a provider is a different problem.
Already seeing an error?
Fix this from ChatGPT or Claude
MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:
“example.com is on Google Workspace. Check its SPF, DKIM and DMARC and give me the records to add.”
- Claude: Settings → Connectors → Add custom connector, then paste
https://mcp.mailvakt.com/mcp. - Cursor and other MCP clients: add the same address as an MCP server. Setup details.
Checks are free and need no account. Sign in only to collect DMARC reports for a domain.