Cloudflare, CDN & Edge

Email Deliverability Deep-Dive: SPF, DKIM, DMARC, BIMI on Cloudflare DNS

By Domain India Team · DomainIndia EngineeringPublished 11 min read
Knowledge base article
Contents (16 sections)

When genuine email lands in spam, the cause is usually missing or broken authentication records in DNS. This guide walks through SPF, DKIM, DMARC, MTA-STS and BIMI, with the exact steps to add each record in Cloudflare DNS, and explains what each one does and does not do.

Key takeaways

SPF, DKIM and DMARC are the three records every sending domain needs; Gmail, Yahoo and Microsoft require them from bulk senders. MTA-STS protects mail coming to you, and BIMI can show your logo in some inboxes once DMARC is enforced. If your DNS is on Cloudflare, records that your mail host generates are not added there automatically: copy them into Cloudflare yourself.

1. Why emails land in spam

Since 2024, Gmail and Yahoo have required senders of more than about 5,000 messages a day to their users to have:

  • SPF and DKIM on the sending domain;
  • a DMARC record (p=none at minimum) that aligns with the From address;
  • one-click unsubscribe for marketing mail;
  • a low spam-complaint rate.

Microsoft applies similar rules to high-volume senders to Outlook.com. Smaller senders still need SPF or DKIM at the very least, and a full set of records is the safest baseline for everyone.

2. The five layers

LayerPurposeDNS recordPriority
SPFWhich servers may send as your domainTXTMust have
DKIMCryptographic signature on each messageTXT (or CNAME)Must have
DMARCWhat receivers do when SPF or DKIM failsTXTMust have
MTA-STSForces TLS on mail sent to youTXT + HTTPS fileNice to have
BIMIYour logo in supporting inboxesTXT + SVG logoOptional

3. SPF (Sender Policy Framework)

SPF lists the servers allowed to send mail for your domain. Example for a domain that uses Google Workspace for mailboxes and Mailgun for newsletters:

text
v=spf1 include:_spf.google.com include:mailgun.org ~all

Add it in Cloudflare:

  1. Open DNS.
    In the Cloudflare dashboard, choose your domain, then DNS › Records.
  2. Add a TXT record.
    Name @, content your SPF string (with the includes for YOUR senders), TTL Auto.
  3. Save and check.
    Run dig TXT yourcompany.com +short and look for one v=spf1 line.

Key rules:

  • Publish only one SPF record per domain. Two records make SPF fail; merge the includes into one.
  • ~all (soft fail) is the usual choice. -all (hard fail) is stricter and fine once you are sure every sender is listed.
  • SPF allows at most 10 DNS lookups; each include counts. Remove senders you no longer use before reaching for flattening tools.

4. DKIM (DomainKeys Identified Mail)

Your mail server signs each message with a private key, and receivers check the signature against the public key you publish in DNS.

Google Workspace

  1. Generate the key.
    In the Google Admin console, open Apps › Google Workspace › Gmail › Authenticate email and generate a 2048-bit record.
  2. Copy the record.
    The name is google._domainkey and the value starts v=DKIM1; k=rsa; p=….
  3. Add it to Cloudflare
    as a TXT record with that name and value.
  4. Start authentication.
    Wait for DNS to update, then click Start authentication in the Admin console.

Mailgun, SendGrid, Amazon SES and similar

Each service shows its own records, often two or three TXT or CNAME records. Add all of them exactly as shown. If a service asks for a CNAME, set it to DNS only (grey cloud) in Cloudflare.

Your own mail server on a VPS

On a Postfix server you can generate a key with OpenDKIM:

bash
sudo apt install opendkim opendkim-tools
sudo mkdir -p /etc/opendkim/keys/yourcompany.com
cd /etc/opendkim/keys/yourcompany.com
sudo opendkim-genkey -b 2048 -s default -d yourcompany.com
sudo cat default.txt

Publish the value as a TXT record named default._domainkey, then configure Postfix to sign outgoing mail. See setting up a mail server on your VPS. Before you run your own mail server on a Domain India VPS, ask support about outbound port 25 and reverse DNS (PTR) for your IP.

Check the record with dig TXT default._domainkey.yourcompany.com +short, then send a test message to a Gmail address and open Show original: it should say DKIM: PASS.

5. DMARC (Domain-based Message Authentication, Reporting and Conformance)

DMARC tells receivers what to do with mail that fails SPF and DKIM alignment, and where to send reports. Start in monitoring mode:

text
_dmarc.yourcompany.com  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"
  • p=none: only monitor; don't reject anything.
  • rua: where daily aggregate reports go. Use a mailbox you can read, or a DMARC reporting service.

Run p=none for a few weeks. The reports show every service sending as your domain and whether it passes. Many reporting services (Postmark, dmarcian, Valimail and others) have free tiers that turn the XML into readable summaries. Once every genuine sender passes, tighten the policy:

text
_dmarc.yourcompany.com  TXT  "v=DMARC1; p=quarantine; rua=mailto:[email protected]"

p=quarantine sends failing mail to spam; p=reject refuses it outright. A domain may have only one DMARC record, so edit the existing one rather than adding a second. For a fuller walkthrough, see setting up DMARC.

Don't start at p=reject

If one of your senders isn't covered by SPF or DKIM yet, an enforced policy sends its mail to spam or bounces it: invoices and password resets can vanish. Move from none to quarantine to reject over several weeks, reading the reports at each step.

6. MTA-STS and TLS reporting

MTA-STS tells other mail servers to deliver to you only over verified TLS, which blocks downgrade attacks on incoming mail. It needs two DNS records and one policy file.

MTA-STS record:

text
_mta-sts.yourcompany.com  TXT  "v=STSv1; id=20260924000000"

Change the id value every time you change the policy file.

TLS reporting (TLS-RPT) record, so you receive reports of TLS failures:

text
_smtp._tls.yourcompany.com  TXT  "v=TLSRPTv1; rua=mailto:[email protected]"

Policy file at https://mta-sts.yourcompany.com/.well-known/mta-sts.txt, here for Google Workspace:

text
version: STSv1
mode: testing
mx: smtp.google.com
mx: aspmx.l.google.com
mx: *.aspmx.l.google.com
max_age: 604800

The mx lines must match every MX host in your DNS; a wildcard covers only one label. Start with mode: testing, read the TLS reports, then switch to mode: enforce. The mta-sts subdomain must serve the file over HTTPS with a valid certificate: point it at a web server that hosts the file, or serve it from a Cloudflare Worker.

7. BIMI (Brand Indicators for Message Identification)

BIMI lets supporting inboxes show your logo next to your messages. It works only on top of the records above.

Requirements:

  • SPF and DKIM passing, and DMARC at p=quarantine or p=reject for all of your mail;
  • your logo as an SVG Tiny PS file, served over HTTPS;
  • a TXT record at default._bimi.yourcompany.com;
  • for Gmail and Apple Mail, a mark certificate from a certificate authority.
Mailbox providerWithout a certificateWith a mark certificate
Yahoo Mail and AOLPossible, for senders with enough volume and a good reputationYes
GmailNoYes, with a VMC or a CMC
Apple MailNoYes, with a VMC
Outlook and Microsoft 365No BIMI supportNo BIMI support

A Verified Mark Certificate (VMC) needs a registered trademark for the logo; a Common Mark Certificate (CMC) needs proof that you have used the logo publicly for a period of time. Both are sold per year by a small number of certificate authorities and cost far more than a website SSL certificate. Domain India does not sell them.

The record, without and with a certificate:

text
default._bimi.yourcompany.com  TXT  "v=BIMI1; l=https://yourcompany.com/bimi/logo.svg; a=;"
default._bimi.yourcompany.com  TXT  "v=BIMI1; l=https://yourcompany.com/bimi/logo.svg; a=https://yourcompany.com/bimi/vmc.pem"

BIMI does not improve deliverability by itself; the SPF, DKIM and enforced DMARC it requires are what help. For logo preparation, certificates and costs, see our complete guide to BIMI and VMC.

8. A complete example

A small business with Google Workspace mailboxes, Mailgun for newsletters and DNS on Cloudflare:

text
; SPF (apex)
@                    TXT  "v=spf1 include:_spf.google.com include:mailgun.org ~all"

; DKIM from Google Workspace
google._domainkey    TXT  "v=DKIM1; k=rsa; p=MIIBIjAN..."

; DKIM from Mailgun (use the selector Mailgun shows you)
mx._domainkey        TXT  "k=rsa; p=MIGfMA0..."

; DMARC
_dmarc               TXT  "v=DMARC1; p=quarantine; rua=mailto:[email protected]"

9. If your email is hosted with Domain India

Your mail host creates the SPF and DKIM values; where they are published depends on where your DNS is.

  • cPanel hosting: DKIM is on by default for new accounts. Email › Email Deliverability in cPanel shows the SPF and DKIM values your domain needs and can repair them when your DNS is on our servers. Most domains on our cPanel servers already have a DMARC record with p=none, which you can edit.
  • DirectAdmin hosting: DKIM uses the selector x and most domains already have a key; see checking and managing DKIM in DirectAdmin.
  • Business Email: signs every message with DKIM and provides SPF and DMARC records for your domain.
  • DNS on Cloudflare: nothing is copied there for you. Copy the exact SPF, DKIM and DMARC values from your control panel (or from Business Email) into Cloudflare as TXT records, and keep the MX and mail-related records set to DNS only. See complete Cloudflare setup.

10. Monitoring deliverability

  • Google Postmaster Tools (postmaster.google.com): spam rate and authentication results for mail to Gmail users.
  • MXToolbox (mxtoolbox.com): checks SPF, DKIM, DMARC and blocklists.
  • Mail-Tester (mail-tester.com): send one message to a test address and get a score with a detailed report.
  • A DMARC reporting service: turns aggregate reports into readable summaries.

Targets: keep the Gmail spam rate below 0.1% and never let it reach 0.3%; aim for nearly all your mail passing DMARC; aim for 9 or 10 out of 10 on Mail-Tester. See also how to test email deliverability for your own website.

11. Keep transactional and marketing mail apart

Send transactional mail (receipts, password resets) from addresses such as [email protected], and marketing mail from a subdomain such as news.yourcompany.com through your newsletter service. A separate subdomain keeps a marketing complaint spike from damaging the reputation of the mail your customers are waiting for.

Process bounces and complaints from your provider's webhooks: suppress hard-bounced addresses and honour unsubscribes straight away. A bounce rate above a few per cent damages your reputation quickly, so clean your list regularly.

12. Common pitfalls

Two SPF records
SPF fails for both. Merge every include into one record.
New sender, old SPF
When you add a newsletter, CRM or billing service, add its include and DKIM records before you send.
DKIM selector mismatch
The selector in DNS must match the one in the message signature (google._domainkey, x._domainkey and so on).
DMARC at p=reject too early
Genuine mail bounces. Stage through none, quarantine and reject.
Non-compliant BIMI logo
The logo must be SVG Tiny PS. Validate it with a BIMI checker before publishing.
Mail records proxied in Cloudflare
Records used for mail must be DNS only, not proxied (orange cloud).

Frequently asked questions

Can I skip BIMI and MTA-STS?

Yes. SPF, DKIM and DMARC are the records that matter for delivery. BIMI only adds a logo in supporting inboxes, and MTA-STS protects mail sent to you rather than mail you send.

Does Cloudflare Email Routing help deliverability?

Email Routing forwards incoming mail to another mailbox. It does not send mail for you, so the deliverability of your outgoing mail depends on the SPF, DKIM and DMARC setup of the service that actually sends it.

My email is hosted with Domain India but my DNS is on Cloudflare. What do I do?

Copy the SPF, DKIM and DMARC values shown in your control panel (Email Deliverability in cPanel) or by Business Email into Cloudflare as TXT records, with the proxy off. Records created on our servers are not added to Cloudflare automatically.

Does BIMI need a paid certificate?

For Gmail and Apple Mail, yes. Gmail accepts a Verified Mark Certificate or a Common Mark Certificate, and Apple Mail needs a Verified Mark Certificate. Yahoo Mail can show a BIMI logo without a certificate for senders with enough volume and a good reputation.

DMARC reports are flooding my inbox. What should I do?

Send the rua address to a DMARC reporting service, many of which have free tiers, or to a dedicated mailbox. They combine the daily XML files into readable summaries.

Do Gmail, Yahoo and Outlook need different settings?

No. SPF, DKIM and DMARC work the same for all of them. Their bulk-sender rules and filtering differ in detail, so test with addresses at each provider.

Ready to fix your email? Check your records with how to test email deliverability, take DMARC to enforcement with setting up DMARC, or open a support ticket if a record in your control panel won't validate.

Email that passes authentication

Domain India Business Email signs every message with DKIM and provides SPF and DMARC records for your domain.

See Business Email

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app