In Namecheap, go to Domain List, click Manage next to your domain, open the Advanced DNS tab and use Add New Record in the Host Records section. SPF and DMARC are TXT records, and DKIM is a TXT or CNAME record depending on the service that sends your email.
These three records work together. SPF lists the services allowed to send email for yourbusiness.com. DKIM is a digital signature that proves an email really came from your domain. DMARC tells receivers what to do when an email fails both checks, and sends you reports about it. Gmail and Yahoo expect all three from anyone sending in bulk, and without them more of your email lands in spam.
Step 1: Check your domain uses Namecheap DNS
Host Records on the Advanced DNS tab only take effect if your domain uses Namecheap's own DNS. Look at the Nameservers section on your domain's Manage page:
| Nameservers setting | Where you add the records |
|---|---|
| Namecheap BasicDNS, Namecheap PremiumDNS (or FreeDNS) | Advanced DNS → Host Records, as described below |
| Namecheap Web Hosting DNS (dns1.namecheaphosting.com, dns2.namecheaphosting.com) | The Zone Editor in your hosting cPanel |
| Custom DNS | At the company those name servers belong to, such as Cloudflare or your web host |
Name servers are the servers that tell the rest of the internet where your DNS records live. If they point somewhere else, records you add in Namecheap are ignored, so add them where the name servers point instead.
Step 2: Get the Host field right
Namecheap adds your domain to the end of whatever you type in the Host field. Its own guide says the domain name should not be included.
- For the main domain, yourbusiness.com, enter
@. - For DMARC, enter
_dmarc. - For Google Workspace DKIM, enter
google._domainkey.
If you type the full name, you end up with a record at _dmarc.yourbusiness.com.yourbusiness.com, and receivers won't find it.
Step 3: Understand the Mail Settings section
Below Host Records, the Advanced DNS tab has a Mail Settings section with a drop-down. It controls where your email is delivered (your MX records), and some options add records for you:
- Custom MX is the one to choose for Google Workspace and most other email services. You enter their MX records yourself. For Google Workspace, Namecheap's guide gives one MX record with Host
@, Valuesmtp.google.comand Priority1. Custom MX doesn't add SPF, DKIM or DMARC. - Private Email sets up Namecheap's own mailboxes. It adds the MX records and an SPF record,
v=spf1 include:spf.privateemail.com ~all, which then appears in Host Records and can be edited. - Email Forwarding forwards your addresses to another inbox. It adds MX records and an SPF record that Namecheap says can't be deleted while forwarding is on. Namecheap also says free forwarding can't be used with Private Email or another email service at the same time.
Whichever option you pick, check Host Records afterward for any TXT record starting with v=spf1 that Namecheap added, before you add your own.
Step 4: Add or update your SPF record
- On the Advanced DNS tab, look in Host Records for a TXT record with Host
@whose value starts withv=spf1. - If there is one, edit it. Don't add a second. A domain can only have one SPF record, and two break SPF completely.
- If there's none, click Add New Record, choose TXT Record, and enter
@in Host. - In Value, enter your SPF record. For Google Workspace:
v=spf1 include:_spf.google.com ~all
- Leave TTL on Automatic and click Save All Changes.
If another service also sends email as you, add its include to the same line, before ~all. Use the exact value from that service's help pages, and keep the total under 10 DNS lookups. Each include: uses at least one.
If you've moved from Namecheap Private Email to Google Workspace, the record Namecheap added still says include:spf.privateemail.com. Change that to include:_spf.google.com rather than adding a second record. Keep both includes only if Private Email still sends some of your email.
Step 5: Add your DKIM records
The service that sends your email creates the DKIM key. You publish it in your DNS. Each service that sends as you needs its own.
Google Workspace gives you a TXT record in the Admin console under Apps, Google Workspace, Gmail, Authenticate email:
- Click Add New Record and choose TXT Record.
- In Host, enter
google._domainkey. - In Value, paste the full value from the Admin console. It starts with
v=DKIM1; k=rsa; p=. - Click Save All Changes, then go back to the Admin console and click Start authentication.
Namecheap's Value field takes up to 2,500 characters, so a 2048-bit key fits in one piece. You don't need to split it.
Mailchimp and many other services give you CNAME records instead. A CNAME record points one name at another, so the service can look after the key for you. Mailchimp's two look like this:
| Type | Host | Value |
|---|---|---|
| CNAME Record | k2._domainkey | dkim2.mcsv.net |
| CNAME Record | k3._domainkey | dkim3.mcsv.net |
Copy the exact names and values your own service shows, because they differ between services and sometimes between accounts. Enter only the part before your domain in Host. Paste values exactly; one missing character breaks the key.
Step 6: Add a DMARC record
- Click Add New Record and choose TXT Record.
- In Host, enter
_dmarc. - In Value, enter:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com
- Click Save All Changes.
p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you read. Once the reports show all your genuine email passing, change p=none to p=quarantine.
Add SPF and DKIM first. A DMARC record on its own doesn't make your email pass anything. If a DMARC record already exists at _dmarc, edit it rather than adding a second one.
Step 7: Check it worked
Namecheap says new host records normally take about 30 minutes to work, which matches its default TTL (how long other servers may keep showing the old value). Once they've had time, send one email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for yourbusiness.com itself), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.
Checked against: Namecheap Knowledgebase, How do I add TXT/SPF/DKIM/DMARC records for my domain? · Namecheap Knowledgebase, How do I set up host records for a domain? · Namecheap Knowledgebase, How to create a CNAME record for your domain · Namecheap Knowledgebase, How can I set up MX records required for mail service? · Namecheap Knowledgebase, How to activate Google Workspace for Mail · Namecheap Knowledgebase, How to set up Namecheap Private Email DNS records for domains on Namecheap Basic/Premium nameservers · Namecheap Knowledgebase, How to set up Free Email Forwarding · Namecheap Knowledgebase, How to change DNS for a domain · Namecheap Knowledgebase, Namecheap DNS limits · Google Workspace Admin Help, Set up DKIM.