In IONOS, open Domains & SSL, click the gear icon under Actions next to your domain, choose DNS, and use Add record to create each one. SPF and DMARC are TXT records, and DKIM is a TXT or CNAME record depending on the service that sends your email.
These three records work together. SPF lists the services allowed to send email for yourbusiness.com. DKIM is a digital signature that proves an email really came from your domain. DMARC tells receivers what to do when an email fails both checks, and sends you reports about it. Gmail and Yahoo expect all three from anyone sending in bulk, and without them more of your email lands in spam.
IONOS used to be called 1&1. If you bought your domain from 1&1, it's in your IONOS account and these steps apply.
Step 1: Check your domain uses IONOS name servers
Name servers are the servers that tell the rest of the internet where your DNS records live. IONOS lets you use other name servers for a domain, and when you do, it says records you add at IONOS aren't visible on the internet.
To check, click the gear icon next to your domain and choose Name Server. If it shows the IONOS name servers, carry on below. If it lists other name servers, such as Cloudflare's or your web designer's, add the records at that provider instead.
Step 2: Open the DNS settings
- Log in to your IONOS account.
- Open Domains & SSL. It's a tile on the start page. If your screen looks different, look for Domains in the main menu.
- Find yourbusiness.com, click the gear icon under Actions, and choose DNS.
You'll see a list of the records your domain already has, with Add record above it. To change a record, use its edit option rather than adding a new one.
Step 3: Get the host name right
IONOS adds your domain to the end of whatever you type in the Host name field. Its DMARC guide shows _dmarc becoming _dmarc.yourbusiness.com automatically.
- For the main domain, yourbusiness.com, enter
@. - For DMARC, enter
_dmarc. - For Google Workspace DKIM, enter
google._domainkey.
If you type the full name, you end up with a record at _dmarc.yourbusiness.com.yourbusiness.com, and receivers won't find it.
Step 4: Add or update your SPF record
IONOS turns on its own SPF record by default for domains on its name servers, so there's very likely one already. It's a TXT record on @ that starts with v=spf1 and includes an IONOS address such as _spf-us.ionos.com.
- In the record list, find the TXT record that starts with
v=spf1. - Edit it rather than adding another. A domain can only have one SPF record, and two break SPF completely.
- Add Google Workspace's include before
~all. If you also use IONOS email, keep the IONOS include, so the record looks like:
v=spf1 include:_spf-us.ionos.com include:_spf.google.com ~all
Keep the IONOS part exactly as it appears in your own record. If you don't send any email through IONOS at all, the record can simply be:
v=spf1 include:_spf.google.com ~all
- Click Save.
If there's no SPF record, click Add record, choose TXT, enter @ in Host name and the record in Value, then save. IONOS also offers a one-click IONOS SPF (TXT) option under Add record, which is only for email sent through IONOS. IONOS says that if an SPF record already exists for another service, it adds the IONOS mail servers to it.
For any other service that sends as you, add the include from that service's help pages to the same record. Keep the total under 10 DNS lookups. Each include: uses at least one.
Step 5: Add your DKIM records
The service that sends your email creates the DKIM key. You publish it in your DNS. Each service that sends as you needs its own.
You may already see CNAME records such as s1-ionos._domainkey. Those are IONOS's own DKIM records for IONOS email. Leave them alone; they don't clash with keys from other services.
Google Workspace gives you a TXT record in the Admin console under Apps, Google Workspace, Gmail, Authenticate email:
- Click Add record and choose TXT.
- In Host name, enter
google._domainkey. - In Value, paste the full value from the Admin console. It starts with
v=DKIM1; k=rsa; p=. - Click Save, then go back to the Admin console and click Start authentication.
A 2048-bit key is long. After saving, open the record and check the whole value is there. If it was cut short, see our guide to setting up DKIM in Google Workspace for how to split it.
Mailchimp and many other services give you CNAME records instead. A CNAME record points one name at another, so the service can look after the key for you. In IONOS, choose CNAME, put the name in Host name and the target in Points to. Mailchimp's two look like this:
| Type | Host name | Points to |
|---|---|---|
| CNAME | k2._domainkey | dkim2.mcsv.net |
| CNAME | k3._domainkey | dkim3.mcsv.net |
Copy the exact names and values your own service shows, because they differ between services and sometimes between accounts. Enter the target without http:// or https://, and paste values exactly; one missing character breaks the key.
Step 6: Add a DMARC record
- Click Add record and choose TXT.
- In Host name, enter
_dmarc. - In Value, enter:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com
- Click Save.
p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you read. Once the reports show all your genuine email passing, change p=none to p=quarantine.
If a TXT record on _dmarc already exists, edit it rather than adding a second. Add SPF and DKIM first, too. A DMARC record on its own doesn't make your email pass anything.
Step 7: Check it worked
IONOS says changes take effect on its own servers immediately and can take up to an hour to show everywhere, because other servers keep the old value for a while (the TTL). Once they've had time, send one email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for yourbusiness.com itself), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.
Checked against: IONOS Help, Managing TXT Records · IONOS Help, Configuring a DMARC Record for a Domain · IONOS Help, Using IONOS SPF to Improve Email Delivery · IONOS Help, Email Authentication with DKIM · IONOS Help, Microsoft 365, Creating a DKIM Entry for a Domain in the Microsoft 365 Defender Portal · IONOS Help, Configuring a CNAME Record for a Subdomain · IONOS Help, Using Your Own Name Servers for a Domain · Google Workspace Admin Help, Set up DKIM.