In Porkbun, you add SPF, DKIM and DMARC in your domain's DNS records, which you open with the DNS button under the domain name on the Domain Management page. SPF and DMARC are TXT records, and DKIM is a TXT or CNAME record depending on your email service.
These three records work together. SPF lists the services allowed to send your email. DKIM adds a digital signature that proves an email came from your domain. DMARC tells receivers what to do when an email fails both, and sends you reports about it. Without them, Gmail, Yahoo and Outlook have no way to confirm your email is genuine, so more of it ends up in spam.
Step 1: Check that Porkbun runs your DNS
Records you add at Porkbun only count if your domain uses Porkbun's nameservers (the servers that tell the internet where your DNS lives). Porkbun's are:
- curitiba.ns.porkbun.com
- fortaleza.ns.porkbun.com
- maceio.ns.porkbun.com
- salvador.ns.porkbun.com
To check, go to Domain Management, click Details next to your domain and look at Nameservers. If they point somewhere else, such as Cloudflare, Shopify or your website host, add the records there instead. Records in Porkbun's editor aren't used while the domain points elsewhere.
Step 2: Open the DNS editor
- Log in to Porkbun. You land on Domain Management.
- Find yourbusiness.com and click the DNS button under the domain name. You can also click Details, then the edit icon next to DNS Records.
- You'll see your domain's current DNS records, with the option to add new ones.
Each record has a Type, a Host, an Answer (the value), a TTL and an optional Notes field. Notes are only for you and don't change anything.
Step 3: Get the Host field right
This is where most mistakes happen. Porkbun's Host field takes only the part in front of your domain. Porkbun adds yourbusiness.com for you.
- For the main domain, yourbusiness.com, leave Host blank. Porkbun says to leave it empty rather than typing @.
- For DMARC, enter
_dmarc. - For Google Workspace DKIM, enter
google._domainkey.
If you type the full name, you can end up with a record at _dmarc.yourbusiness.com.yourbusiness.com, and receivers won't find it.
Step 4: Add or update your SPF record
- In your current records, look for a TXT record with a blank Host whose answer starts with
v=spf1. - If there is one, click the pencil icon to edit it, change it, and save. Don't add a second one. A domain can only have one SPF record, and two break SPF completely.
- If there's none, click Add Record, choose TXT as the Type, leave Host blank, and enter your SPF record in Answer. For Google Workspace:
v=spf1 include:_spf.google.com ~all
- Click Add.
If another service also sends email as you, add its include to the same line, before ~all, using the exact value from that service's help pages. Keep the total under 10 DNS lookups. Each include: uses at least one.
Watch out for Porkbun email forwarding records
Porkbun's email forwarding uses two MX records (fwd1.porkbun.com and fwd2.porkbun.com) and its own SPF record:
v=spf1 include:_spf.porkbun.com ~all
If you see these and you now use Google Workspace or another email service for your mailboxes, they clash. Porkbun says a domain's MX records can only point to one mail provider, so you can't forward some addresses through Porkbun and deliver others to Google. Delete the fwd1 and fwd2 MX records when you switch, and edit that SPF record so it allows your new service instead. If you keep Porkbun forwarding and another service also sends email as you, merge them into one record: keep include:_spf.porkbun.com and add that service's include before ~all.
About Quick Setup
Porkbun's DNS editor has a Quick Setup option (some of its guides call it Quick DNS Config) that adds records for common services, including Google Workspace and Microsoft 365. It asks you to confirm before changing your DNS. Porkbun's guide says the Google Workspace option adds an MX record and an SPF record, but not DKIM or DMARC. Its guides don't say whether it removes records you already have, so look through your record list afterwards. You should see one SPF record, and MX records for one email service only.
Step 5: Add your DKIM records
Your email service creates the DKIM key, and you publish it. Each service that sends as you needs its own. Always copy the values your service shows you, because many keys are unique to your account.
Google Workspace gives you a TXT record in the Admin console (Apps, then Google Workspace, then Gmail, then Authenticate email):
- Click Add Record and choose TXT as the Type.
- In Host, enter
google._domainkey. - In Answer, paste the full value from the Admin console. It starts with
v=DKIM1;. - Click Add, then go back to the Admin console and click Start authentication.
A 2048-bit Google key is longer than 255 characters. If the saved answer looks shorter than what you pasted, Google's advice is to split it into quoted chunks in the same field. Our guide to setting up DKIM in Google Workspace explains how.
Mailchimp gives you two CNAME records (a CNAME points one name at another):
| Type | Host | Answer |
|---|---|---|
| CNAME | k2._domainkey | dkim2.mcsv.net |
| CNAME | k3._domainkey | dkim3.mcsv.net |
Other services, such as HubSpot, Klaviyo or Shopify, show their own CNAME or TXT records. Add whatever type they show, with only the prefix in Host, and paste values exactly. One missing character breaks the key.
Step 6: Add a DMARC record
First check your record list for an existing TXT record with _dmarc as the Host. A domain can only have one, so edit it rather than adding another. If there's none:
- Click Add Record and choose TXT as the Type.
- In Host, enter
_dmarc. - In Answer, enter:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com
- Click Add.
p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you actually read. Once the reports show all your genuine email passing, change p=none to p=quarantine.
Porkbun's own Google Workspace guide shows a DMARC record that starts at p=quarantine. We suggest starting at p=none, because a strict policy before SPF and DKIM pass can send your own email to spam.
Add SPF and DKIM first. A DMARC record on its own doesn't make your email pass anything.
Step 7: Wait, then check it worked
Leave TTL at Porkbun's default. Porkbun's minimum TTL is 600 seconds (10 minutes), so changes to an existing record take about 10 minutes to show everywhere. New records usually work within seconds, though your email service may take longer to check them.
Once they've had time, send an email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for your own domain), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.
Checked against: Porkbun Knowledge Base, How to Add DNS Records on Porkbun · Porkbun Knowledge Base, How to Edit DNS Records · Porkbun Knowledge Base, How to Connect a Domain to Google Workspace Email · Porkbun Knowledge Base, How to configure your domain for Microsoft 365 email · Porkbun Knowledge Base, How to use Porkbun email when your DNS is hosted elsewhere · Porkbun Knowledge Base, How to Set Up Email Forwarding Service · Porkbun Knowledge Base, How Long Will It Take for Changes to DNS to Show Up? · Porkbun Knowledge Base, How to switch to Porkbun's Nameservers · Google Workspace Admin Help, Set up DKIM.