- Will this stop people spoofing my domain straight away?
- Not on its own. The records only take effect once you publish them at your DNS host, and DMARC only protects you when its policy is set to quarantine or reject. On the default none setting it monitors and reports but blocks nothing. It also cannot stop lookalike domains, only forgery of your exact domain.
- What is the difference between -all and ~all on my SPF record?
- Hard fail (-all) tells receivers to reject any mail from a server not on your list. Soft fail (~all) tells them to accept it but mark it suspicious. Start with soft fail while you confirm every legitimate sender is listed, then move to hard fail once you are sure, so you do not block your own mail.
- Why can't the tool generate my DKIM key?
- Because the key is created by your email provider and half of it, the private key, never leaves their systems. We would be handing you an invalid record. Generate the DKIM key in Microsoft 365, Google Workspace or your sending platform, then publish the value they give you at the selector they specify.
- Where do I put these records?
- All three are DNS TXT records at your domain host. SPF goes on your root domain, DMARC goes on the host _dmarc.yourdomain.co.uk, and DKIM goes on a selector host like selector._domainkey.yourdomain.co.uk. The tool labels each one with its exact host name so you know which box to paste it into.
- I already have an SPF record. Can I have a second one?
- No. A domain must have exactly one SPF record. If you publish a second, most receivers treat both as invalid and your authentication breaks. You need to merge the new senders into your existing record instead. This tool cannot see your current record, so check before you publish.