Skip to content

Set up SPF and DMARC for support email

Understand the SPF and DMARC checks on the email setup page, what the advice means and how to fix two SPF records or a missing DMARC record.

Last updated 2 min read

On this page

When you verify your domain for sending, Hushdesk also checks SPF and DMARC. They are not what decides verification, but they help your replies reach the inbox. The setup page shows a plain-English tip for each one that needs attention.

Before you start

  • Who can do this: owners and admins in Hushdesk, plus whoever manages your domain's DNS.
  • Plan: all plans.
  • What you need: your domain set up for sending. See Send replies from your own domain.
  • Time: ten minutes.

Step by step

  1. Open your address under Settings > Email and press Check DNS now in step 4.
  2. Read the tips under the records. Each one names the exact record to add or change.
  3. For SPF, add or edit one TXT record on your domain:
    • No SPF yet: add v=spf1 include:spf.mtasv.net ~all.
    • SPF exists: add include:spf.mtasv.net before the final ~all or -all.
    • Two SPF records: merge them into one.
  4. For DMARC, add a TXT record at _dmarc.yourstore.com with v=DMARC1; p=none; rua=mailto:dmarc@yourstore.com.
  5. Wait a few minutes and press Check DNS now again.

What happens next

When SPF is right, the check says SPF is set up. For DMARC, a record with p=none is reported as monitoring mode, with the advice to consider p=quarantine once SPF and DKIM pass consistently. A stricter policy is reported as enforced.

The advice you may see

Advice (shortened) What to do
"Add a TXT record on … with value v=spf1 include:spf.mtasv.net ~all" Add a new SPF record
"Your SPF record exists but does not include spf.mtasv.net" Add the include to your existing record
"You have 2 SPF records; receivers treat that as a failure" Merge into one record
"Optional but recommended: add a TXT record at _dmarc…" Add a DMARC record in monitoring mode
"DMARC is published in monitoring mode (p=none)" Fine for now; tighten later

Tips

  • Never create a second SPF record. Always edit the one you have.
  • Start DMARC with p=none and read the reports for a couple of weeks before tightening it.
  • DNS changes usually show within minutes but can take up to 48 hours.

Troubleshooting

"DNS lookup failed (…). Try again in a minute."

The lookup did not get an answer. Wait and check again.

"No TXT records found on …"

Your domain has no TXT records at all. Add the SPF record shown.

Frequently asked questions

Do I need an SPF record to send from my domain with Hushdesk?

It is recommended. Hushdesk verifies your domain with DKIM and Return-Path, which is what decides whether replies come from your address. SPF is checked too, and the page tells you exactly what to add, such as include:spf.mtasv.net, so receivers trust mail sent through our email provider.

What does it mean if I have two SPF records?

Receivers treat two SPF records on one domain as a failure, so neither works. Merge them into a single TXT record that starts with v=spf1, lists every service you send with, including include:spf.mtasv.net, and ends with ~all or -all. The page advises this when it finds two.

Do I need a DMARC record?

It is optional but recommended. A DMARC record at _dmarc on your domain tells receivers what to do with mail that fails checks and sends you reports. Start with v=DMARC1; p=none and a reporting address, then move to p=quarantine once SPF and DKIM pass consistently.

Will adding Hushdesk to SPF break my other email?

Not if you add it to your existing record. Add include:spf.mtasv.net before the final ~all or -all in the SPF record you already have, rather than creating a second record. Your other mail services keep working because their includes stay in the same record.

Why does the DNS check say lookup failed?

The DNS lookup itself did not get an answer, which is usually a temporary network or DNS server problem rather than a mistake in your records. Wait a minute and press Check DNS now again. If it keeps failing, check that the domain name is spelled correctly.

Was this helpful?

Still stuck?

Chat with the Hushdesk team. A person answers on every plan.