Your site sends a password reset, a sign-up confirmation or a newsletter, and it never arrives, or it arrives in spam. The cause is rarely the wording. Mail providers decide whether to trust a message mainly by checking three records published in your domain's DNS. If they are missing or wrong, even a perfectly ordinary message is treated as a possible forgery.
What the three records do
| Record | What it says | Where it lives |
|---|---|---|
| SPF | "These servers are allowed to send mail for this domain." | A TXT record on the domain itself, starting v=spf1 |
| DKIM | "Messages from this domain carry a signature. Here is the key to check it." | A TXT record at default._domainkey on cPanel |
| DMARC | "If a message fails those checks, here is what to do with it, and where to send reports." | A TXT record at _dmarc |
SPF and DKIM are the checks. DMARC ties them to the address the reader actually sees in the From line and tells receivers how strict to be.
Step 1: let cPanel check the first two
Open Email Deliverability in cPanel. Each domain is listed as Valid or with problems. If the domain's DNS is run by the same server, press Repair and cPanel writes the correct SPF and DKIM records itself.
If your DNS is hosted somewhere else, for example at your registrar or at Cloudflare, cPanel cannot change it. Press Manage, copy the suggested name and value for each record, and add them as TXT records at the place that does run your DNS.
Step 2: get SPF right
A typical record:
v=spf1 +a +mx +ip4:203.0.113.10 ~all
It lists who may send, and ends with what to think of everyone else. Three rules prevent most SPF problems:
- Only one SPF record per domain. Two records make both invalid. If you also send through another service, merge its
include:into the one record. - Include every service that sends as you. A newsletter platform, a help desk, a shop: each publishes the
include:to add. - Stay under ten lookups. Every
include,aandmxcosts a DNS lookup, and receivers stop at ten. Remove services you no longer use.
Step 3: add a DMARC record
cPanel does not create this one for you. Add a TXT record named _dmarc with a value like:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
p=none means "take no action, just report". Receivers then send summary reports to the address given, showing which servers are sending as your domain and whether they pass. Leave it at none for a few weeks, fix anything legitimate that is failing, then tighten to p=quarantine and eventually p=reject. Jumping straight to reject is how people block their own mail.
Step 4: make the From address match
The checks only help if the domain in the visible From line is the one the records belong to. Send from a real mailbox on your domain, such as news@yourdomain.com, and send it through that mailbox's own mail server with its username and password (SMTP), not through a bare PHP mail call. Mail sent by a script without authentication often carries the server's hostname instead of your domain, and fails alignment.
Step 5: test it
- Send a message from the site to a Gmail address you control.
- Open it, choose Show original from the message menu.
- At the top, SPF, DKIM and DMARC should each say PASS, with your domain beside them.
A FAIL tells you which record to revisit. "SOFTFAIL" on SPF means the sending server is not in your record.
Extra rules for newsletters
Since 2024, Gmail and Yahoo apply stricter requirements to anyone sending in bulk. In summary: SPF, DKIM and DMARC must all be in place, every marketing message needs a working one-click unsubscribe, and the rate at which recipients mark you as spam has to stay very low. In practice that means sending only to people who asked, confirming new sign-ups with a link (double opt-in), and removing addresses that bounce.
Things DNS cannot fix
- Sending limits. Shared hosts cap messages per hour. A newsletter beyond the cap is queued or discarded. Pace the send, or use a dedicated sending service.
- A shared address with a poor reputation. On shared hosting you send from the same address as your neighbors. If one of them spams, everyone suffers until the host cleans it up.
- Content that looks like spam. One large image and no text, link shorteners, and misleading subject lines all count against you.
Common questions
How long do DNS changes take?
Usually minutes, sometimes a few hours, depending on the record's time-to-live setting. Re-run the Gmail test after waiting.
Do I need all three if I send only a few messages?
SPF and DKIM, yes; they take minutes and affect every message. DMARC with p=none costs nothing and gives you visibility, so add it too.
Mail to one provider bounces, everything else works.
Read the bounce message. It normally includes the reason and a link. Providers that block by server address will name the address; pass that to your host.