How do I add SPF, DKIM and DMARC records in Network Solutions?

Updated 9 October 2026 · 6 min read

Guest list Seal Rules

In Network Solutions, you add SPF, DKIM and DMARC under Advanced DNS Records, which you reach from your domain's Advanced Tools section. SPF and DMARC are TXT records, and DKIM is a TXT or CNAME record depending on your email service.

These three records work together. SPF lists the services allowed to send your email. DKIM adds a digital signature that proves an email came from your domain. DMARC tells receivers what to do when an email fails both, and sends you reports about it. Without them, Gmail, Yahoo and Outlook have no way to confirm your email is genuine, so more of it ends up in spam.

Step 1: Check that Network Solutions runs your DNS

Network Solutions says you can only use its Advanced DNS section when your domain uses its default nameservers (the servers that tell the internet where your DNS lives). Its default nameservers have names ending in worldnic.com.

If your nameservers point to another company, such as Cloudflare, Squarespace or your website host, the records belong there instead. Either add them at that company, or switch the domain back to Network Solutions' defaults. You'll find that option under your domain's Advanced Tools, where nameservers are managed. Switching nameservers moves all of your DNS, including your website, so only do it if you know every record you need is set up at Network Solutions.

Step 2: Open Advanced DNS Records

  1. Sign in to your Network Solutions account.
  2. Select Domains on the left side of the page.
  3. Choose yourbusiness.com. Depending on your screen, you may need to click a Settings or Manage button next to it.
  4. Scroll down to the Advanced Tools section.
  5. Click Manage next to Advanced DNS Records.

You'll see your current records and a + Add Record button. Network Solutions also keeps an older layout you can reach through a Classic View link. The steps below use the current layout. If your screen looks different, look for the same field names.

Step 3: Get the host name right

This is where most mistakes happen. When you add a record, the Refers to menu sets the name the record sits on. It offers three choices:

  • @ is your main domain, yourbusiness.com. Use it for SPF.
  • www is www.yourbusiness.com. You won't need it for email records.
  • Other Host lets you type a Host Name. Use it for DMARC and DKIM.

In Host Name, enter only the part in front of your domain, such as _dmarc or google._domainkey. Network Solutions' own examples use short names like mail and autodiscover, not full names. If you type the full name, you can end up with a record at _dmarc.yourbusiness.com.yourbusiness.com, and receivers won't find it.

Step 4: Add or update your SPF record

  1. In your TXT records, look for one on @ whose value starts with v=spf1.
  2. If there is one, click the pencil icon, change it, then click Edit to save. Don't add a second one. Network Solutions says only one SPF record is allowed per domain, and two break SPF completely.
  3. If there's none, click + Add Record and choose a TXT record.
  4. In Refers to, choose @.
  5. In TXT Value, enter your SPF record. For Google Workspace:
v=spf1 include:_spf.google.com ~all
  1. Leave TTL at the default and click Add.

If another service also sends email as you, add its include to the same line, before ~all, using the exact value from that service's help pages. Keep the total under 10 DNS lookups. Each include: uses at least one.

You may already have an SPF record from Network Solutions itself. Its help pages give this one for websites with a contact form hosted there:

v=spf1 include:spf.registeredsite.com include:spf.cloudus.oxcs.net ~all

If that's still in use, keep those includes and add yours to the same record, for example v=spf1 include:spf.registeredsite.com include:spf.cloudus.oxcs.net include:_spf.google.com ~all.

Step 5: Add your DKIM records

Your email service creates the DKIM key, and you publish it. Each service that sends as you needs its own. Always copy the values your service shows you, because many keys are unique to your account.

Google Workspace gives you a TXT record in the Admin console (Apps, then Google Workspace, then Gmail, then Authenticate email):

  1. Click + Add Record and choose a TXT record.
  2. In Refers to, choose Other Host, and enter google._domainkey as the Host Name.
  3. In TXT Value, paste the full value from the Admin console. It starts with v=DKIM1;.
  4. Click Add, then go back to the Admin console and click Start authentication.

A 2048-bit Google key is longer than 255 characters. If Network Solutions won't accept the value, or the saved value is shorter than what you pasted, Google's advice is to split it into quoted chunks in the same field. Our guide to setting up DKIM in Google Workspace explains how.

Mailchimp gives you two CNAME records (a CNAME points one name at another). For each, choose a CNAME record, pick Other Host, and enter the host name and the Alias to value:

TypeHost NameAlias to
CNAMEk2._domainkeydkim2.mcsv.net
CNAMEk3._domainkeydkim3.mcsv.net

Network Solutions only allows CNAME records on names in front of your domain, not on yourbusiness.com itself. DKIM names like these are fine.

Other services, such as HubSpot, Klaviyo or Shopify, show their own CNAME or TXT records. Add whatever type they show, using Other Host with only the prefix, and paste values exactly. One missing character breaks the key.

Network Solutions email. If your mailboxes are with Network Solutions, its help says Cloud Mail and Standard Email already include DKIM. For Edge Desk, ProMail and Webmail, you set DKIM up in the DKIM Manager (under Professional Email in your account) instead of typing in records.

Step 6: Add a DMARC record

First check your TXT records for one with _dmarc as the host. A domain can only have one, so edit it rather than adding another. If there's none:

  1. Click + Add Record and choose a TXT record.
  2. In Refers to, choose Other Host, and enter _dmarc as the Host Name.
  3. In TXT Value, enter:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com
  1. Click Add.

p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you actually read at yourbusiness.com. Once the reports show all your genuine email passing, change p=none to p=quarantine.

Add SPF and DKIM first. A DMARC record on its own doesn't make your email pass anything.

Step 7: Wait, then check it worked

The default TTL is 7200 seconds (2 hours), which is fine to keep. Network Solutions says Advanced DNS changes can take up to 2 hours to spread, and its SPF guide allows 24 to 48 hours.

Once they've had time, send an email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for your own domain), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.

Checked against: Network Solutions Help, How to manage DNS and advanced DNS records in Network Solutions · Network Solutions Help, How to Manage SPF Records for Email Security · Network Solutions Help, How to Set Up DKIM and DMARC · Network Solutions Help, How to manage nameservers for Network Solutions domains · Google Workspace Admin Help, Set up DKIM.

Questions people ask

Where are DNS records in Network Solutions?

Sign in, select Domains on the left, choose your domain, then scroll to Advanced Tools and click Manage next to Advanced DNS Records. That opens the list of records, with a + Add Record button.

What do I choose in the Refers to menu?

Choose @ for records on your main domain, such as SPF. For anything else, choose Other Host and type only the part in front of your domain, such as _dmarc or google._domainkey.

Why can't I see Advanced DNS Records for my domain?

Network Solutions says you can only use its Advanced DNS section when the domain uses its default nameservers. If your nameservers point to another company, add the records there, or switch back to the Network Solutions defaults.

How long do Network Solutions DNS changes take?

Network Solutions says Advanced DNS changes can take up to 2 hours to spread, and its SPF guide allows 24 to 48 hours. The default TTL is 7200 seconds, which is 2 hours.