How do I add SPF, DKIM and DMARC records in Bluehost?

Updated 9 October 2026 · 5 min read

Guest list Seal Rules

In the Bluehost Portal, click Domains in the left-hand menu, choose your domain, open the DNS tab and use Add record in the Manage Advanced DNS Records section. SPF and DMARC are TXT records, and DKIM is a TXT or CNAME record depending on the service that sends your email.

These three records work together. SPF lists the services allowed to send email for yourbusiness.com. DKIM is a digital signature that proves an email really came from your domain. DMARC tells receivers what to do when an email fails both checks, and sends you reports about it. Gmail and Yahoo expect all three from anyone sending in bulk, and without them more of your email lands in spam.

Step 1: Check your domain uses Bluehost name servers

Name servers are the servers that tell the rest of the internet where your DNS records live. In the Bluehost Portal, click Domains, choose your domain and open the Nameservers tab.

  • ns1.bluehost.com and ns2.bluehost.com: add the records in Bluehost, as described below.
  • Anything else, such as Cloudflare or the company you bought the domain from: add the records there. Records you add at Bluehost won't be used.

Step 2: Open the DNS tab

  1. Log in to the Bluehost Portal.
  2. Click Domains in the left-hand menu and choose yourbusiness.com if you have more than one domain.
  3. Open the DNS tab and scroll to Manage Advanced DNS Records.

To add a record, click + Add record on the right and choose Single record. To change one, click the three-dot menu beside it and choose Edit.

The same records also appear in cPanel's Zone Editor (under Hosting, then cPanel, then Domains), and Bluehost's own guides use both screens. Pick one and stick with it.

Step 3: Get the host right

The Bluehost Portal asks which host a record Refers to:

  • For the main domain, yourbusiness.com, choose @.
  • For anything else, choose Other Host and type the name in the Host Name box: _dmarc for DMARC, or google._domainkey for Google Workspace DKIM.

Type only the part before your domain. After saving, check the record list. The name should read _dmarc.yourbusiness.com or just _dmarc, not _dmarc.yourbusiness.com.yourbusiness.com. If the domain appears twice, edit the record and remove the extra part. Older Bluehost screens may call this field Host Record.

Step 4: Edit Bluehost's SPF record

Bluehost adds an SPF record to every domain automatically, so there's almost certainly one already. For shared and cloud hosting it looks like this:

v=spf1 a mx include:websitewelcome.com ~all
  1. Find the TXT record on @ that starts with v=spf1.
  2. Edit it rather than adding another. A domain can only have one SPF record, and two break SPF completely.
  3. Add Google Workspace's include before ~all. If your website or Bluehost mailboxes also send email for you, keep the Bluehost parts:
v=spf1 a mx include:websitewelcome.com include:_spf.google.com ~all

If nothing at Bluehost sends email as you, the record can simply be:

v=spf1 include:_spf.google.com ~all
  1. Save the change.

If there's no SPF record, click + Add record, choose Single record, set the type to TXT, choose @ for Refers to, paste the record into TXT Value and click Add. For any other service that sends as you, add the include from that service's help pages to the same record. Keep the total under 10 DNS lookups. Each a, mx and include: uses at least one.

Step 5: Add your DKIM records

The service that sends your email creates the DKIM key. You publish it in your DNS. Each service that sends as you needs its own.

Google Workspace gives you a TXT record in the Admin console under Apps, Google Workspace, Gmail, Authenticate email:

  1. Click + Add record and choose Single record.
  2. Set the type to TXT and Refers to to Other Host.
  3. In Host Name, enter google._domainkey.
  4. In TXT Value, paste the full value from the Admin console. It starts with v=DKIM1; k=rsa; p=.
  5. Click Add, then go back to the Admin console and click Start authentication.

A 2048-bit key is long. After saving, open the record and check the whole value is there. If it was cut short, see our guide to setting up DKIM in Google Workspace for how to split it.

Mailchimp and many other services give you CNAME records instead. A CNAME record points one name at another, so the service can look after the key for you. Choose CNAME as the type, enter the name as the host, and put the target in the field labeled Points To. Mailchimp's two look like this:

TypeHostPoints To
CNAMEk2._domainkeydkim2.mcsv.net
CNAMEk3._domainkeydkim3.mcsv.net

Copy the exact names and values your own service shows, because they differ between services and sometimes between accounts. Paste values exactly; one missing character breaks the key.

Bluehost mailboxes have their own DKIM key. In cPanel, open Email Deliverability, click Manage next to your domain and copy the Name and Value under the suggested DKIM record. Bluehost's guide says to add it in the DNS tab as a TXT record with Other Host, and not to click Install the Suggested Record.

Step 6: Add a DMARC record

  1. Click + Add record and choose Single record.
  2. Set the type to TXT, Refers to to Other Host, and enter _dmarc in Host Name.
  3. In TXT Value, enter:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com
  1. Click Add.

p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you read. Once the reports show all your genuine email passing, change p=none to p=quarantine.

If a TXT record on _dmarc already exists, edit it rather than adding a second. Add SPF and DKIM first, too. A DMARC record on its own doesn't make your email pass anything.

Step 7: Check it worked

Bluehost says a record change usually works within minutes but can take up to 8 hours, depending on the TTL (how long other servers may keep showing the old value). Once it's had time, send one email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for yourbusiness.com itself), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.

Checked against: Bluehost Help, Guide to the DNS Tab in the Bluehost Portal · Bluehost Help, How to Set Up SPF Records · Bluehost Help, How to Add a DKIM Record · Bluehost Help, Bluehost DNS Records for Email Services · Bluehost Help, How to Manage DNS Records in cPanel · Bluehost Help, How to Navigate the Nameservers Tab in Bluehost Portal · Google Workspace Admin Help, Set up DKIM.

Questions people ask

Bluehost already has an SPF record with websitewelcome.com in it. What do I do with it?

Bluehost adds that record to every domain. Edit it and add your email service's include, so the domain keeps only one SPF record. Keep the Bluehost part if your website or cPanel email sends email for you.

Should I use the Bluehost Portal or cPanel's Zone Editor?

Bluehost's own guides use both, and both only matter while your domain uses Bluehost's name servers. The Bluehost Portal's DNS tab is the simpler screen. Pick one and make all your changes there, so you can see what you've done.

How long do Bluehost DNS changes take?

Bluehost says a single record change usually works within a few minutes but can take up to 8 hours. A change of name servers can take 24 to 48 hours.

Do I need to do anything for Bluehost's own email?

If you send email from mailboxes hosted at Bluehost, cPanel's Email Deliverability tool shows the DKIM record Bluehost suggests for your domain. Bluehost's guide says to add it in the DNS tab rather than with the Install the Suggested Record button.