How do I configure SPF, DKIM, and DMARC for email deliverability?
Setting up SPF, DKIM, and DMARC tells mailbox providers that your emails are legitimate — and they're now required by Gmail, Outlook, Yahoo, and other major providers for all bulk senders. Follow these steps to confirm your sending domain is ready, add the correct DNS records, and register your domain in Targeted Email.
Step 1: Confirm you have a sending domain you own
Targeted Email requires that you send from an email address that uses a domain name your organization owns. You cannot use freemail services like Gmail, Hotmail, Yahoo, or AOL as your From Address, as mailbox providers will identify this as spam and quarantine it.
If your organization doesn't yet have a domain, you can purchase one through services like GoDaddy or Namecheap. Once your domain is set up, return to these steps to complete your configuration.
Sending from more than one domain is not recommended. It can split your sending reputation and complicate your authentication setup. Stick to a single domain whenever possible.
Step 2: Understand what each record does
Before logging into your DNS host, it helps to know what you're configuring and why:
-
SPF (Sender Policy Framework) — A list of servers authorized to send email on behalf of your domain. Mailbox providers check this to confirm your message is coming from a trusted source.
-
DKIM (DomainKeys Identified Mail) — A digital signature attached to each outgoing message. Providers verify this signature against a key published in your DNS to confirm the message hasn't been tampered with.
-
DMARC (Domain-based Message Authentication, Reporting & Conformance) — Tells mailbox providers what to do if a message fails SPF or DKIM (ignore, quarantine, or reject it), and sends you reports on who's sending from your domain.
All three work together. Missing any one of them puts your mail at risk of being filtered or rejected.
Step 3: Access your DNS host
You'll add these records through your DNS host; the same place where you manage your website domain. Common hosts include GoDaddy, Cloudflare, and Squarespace.
If you're not sure who manages your domain, you can look it up at whois.com. Alternatively, you can run the domain check in Targeted Email → Settings → Deliverability (even before setting up your records) — the results will show the name of your hosting provider.
Your domain administrator (often IT staff or your website manager) will need to add or update these records. Bonterra Support cannot directly change DNS records on your behalf.
Step 4: Configure your SPF record
-
In your DNS host, look for an existing TXT record that begins with v=spf1. This is your SPF record.
-
If a record already exists, add our include statement — include:_spfprod.ngpvan.com — before the ~all at the end.
-
If no SPF record exists yet, create a new TXT record with the following values:
-
Host Value: @
-
TXT Value: v=spf1 include:_spfprod.ngpvan.com ~all
-
If you use multiple sending platforms, combine all senders into a single SPF record. You can only have one SPF record per domain. Here are two common examples:
G Suite (Google Workspace) + Targeted Email:
v=spf1 include:_spf.google.com include:_spfprod.ngpvan.com ~all
Microsoft Office 365 + Targeted Email:
v=spf1 include:spf.protection.outlook.com include:_spfprod.ngpvan.com ~all
Important: Stay under the 10-lookup limit. You can validate your full SPF record using the Kitterman SPF Validator. Enter your domain and confirm you see include:_spfprod.ngpvan.com in the result with a passing validation.
Step 5: Configure your DKIM record
DKIM requires a key tied to your specific Targeted Email account. Retrieve it directly from the platform rather than using a generic value.
-
In Targeted Email, go to Settings → Deliverability and enter your domain. This displays the correct DKIM record values for your account.
-
Log in to your DNS host.
-
Create a new TXT record using these values:
-
Host Value: ngpweb3._domainkey.yourorganizationsdomain.org (replace with your domain)
-
TXT Value: The full DKIM value from your Targeted Email settings page
-
GoDaddy note: Some domain providers automatically append your domain to the end of the host field, which breaks the record. If DKIM fails validation, try shortening the host value to just ngpweb3._domainkey.
To validate your DKIM record after publishing, use MXToolbox's DKIM lookup — enter your domain and use ngpweb3 as the selector value.
Step 6: Configure your DMARC record
DMARC gives mailbox providers instructions for what to do when a message fails SPF or DKIM, and generates reports on who is sending mail using your domain.
-
In your DNS host, create a new TXT record with:
-
Host Value: _dmarc.yourdomain.org (replace with your actual domain — use your apex domain, not a subdomain)
-
TXT Value: v=DMARC1; p=none; rua=mailto:youremail@yourdomain.org
-
Recommended approach:
-
Start at p=none (monitoring only). This tells providers to take no action on failing mail, but sends you reports so you can see what's happening. Gmail only requires p=none for compliance.
-
Once you've confirmed SPF and DKIM are aligned and working, you can move toward p=quarantine or p=reject over time.
The rua= parameter is optional but useful. It directs mailbox providers to email you reports about how your domain is being used. Because these reports can be high volume, consider using a DMARC monitoring service (like Dmarcian or Valimail) and using the email address they provide instead of your own.
To verify DMARC alignment after setup: Send a test email through Targeted Email to a Gmail account. Open the email in Gmail, click the three-dot menu in the upper right, and select Show Original. A table will appear showing SPF, DKIM, and DMARC results, all three should show Pass.
Step 7: Register your domain in Targeted Email
After your DNS records are in place, you must register your domain within Targeted Email before you can send. DNS changes can take up to 48 hours to propagate, so wait before completing this step if you just made updates.
-
Go to Targeted Email → Settings → Deliverability.
-
Enter your domain name and select Check Domain.
-
This runs a check on your SPF and DKIM records. When both show green checkmarks, select Register Domain.
-
Registration typically completes within 5 minutes. Click Check Domain again to confirm. Green checkmarks across the board mean your domain is registered and ready to send.
If you haven't completed this step, you'll see a warning on the Review step any time you try to create or send an email.
What else do you need help with?
-
Navigate back to the Email Deliverability Index.
How do I set up SPF for EveryAction Targeted Email? | How do I configure DKIM in Targeted Email? | How do I add a DMARC record for EveryAction emails? | Why can't I use a Gmail or Yahoo address to send from Targeted Email? | How do I register my domain in Targeted Email? | Why is my DKIM record failing validation in GoDaddy? | How do I find out who my DNS host is?
