> ## Documentation Index
> Fetch the complete documentation index at: https://help.enrolweb.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Email DNS Records

> Configure MX, SPF, DKIM, and DMARC records for reliable email delivery, prevent spoofing, and protect your domain reputation on any provider.

To send and receive email through your domain, you must publish DNS records that tell the internet where to deliver messages and how to verify your identity. This page explains the four record types that matter most (MX, SPF, DKIM, DMARC) and shows you how to add them in EnrolWeb DNS Management.

## Record types at a glance

<CardGroup cols={2}>
  <Card title="MX" icon="server">
    Route incoming mail to the correct mail server.
  </Card>

  <Card title="SPF" icon="shield">
    Authorize which servers can send email for your domain.
  </Card>

  <Card title="DKIM" icon="lock">
    Cryptographically sign messages to prove they're authentic.
  </Card>

  <Card title="DMARC" icon="key">
    Tell receivers how to handle messages that fail SPF or DKIM.
  </Card>
</CardGroup>

## Where to edit records

Open [DNS Management](/Domains/security-2) for the domain you want to configure. DNS changes are per-domain, so edit each zone separately.

## MX records

MX records tell other mail servers where to deliver messages sent to your domain. Without MX records, email cannot reach your mailbox. Priority values control preference; lower numbers are preferred.

### Add an MX record

<Steps>
  <Step title="Open DNS Management">
    In your EnrolWeb dashboard, open **DNS Management** for the domain.
  </Step>

  <Step title="Add a new record">
    Click **Add Record** and choose **MX** as the type.
  </Step>

  <Step title="Enter the values">
    Set **Host** to `@` (or your domain), a **Priority** (like `10`), and the **Points to** value from your provider.
  </Step>

  <Step title="Save">
    Save and repeat for each MX record your provider requires.
  </Step>
</Steps>

## SPF records

An SPF record is a TXT record that lists which mail servers may send email for your domain. Receivers use it to catch spoofed messages.

### Add a TXT (SPF) record

<Steps>
  <Step title="Open DNS Management">
    Go to **DNS Management** for the domain.
  </Step>

  <Step title="Add a TXT record">
    Click **Add Record** and choose **TXT**.
  </Step>

  <Step title="Enter values">
    Set **Host** to `@` and paste the SPF value in the **Value** field.
  </Step>

  <Step title="Save">
    Click **Save**.
  </Step>
</Steps>

Example SPF (replace with your provider's value):

```text theme={null}
v=spf1 include:_spf.example.com ~all
```

<Note>
  You can only have one SPF record per domain. If you need multiple services, combine their `include` mechanisms in a single record.
</Note>

## DKIM records

DKIM adds a digital signature to outgoing messages. Receivers verify the signature against a public key in your DNS. Your provider generates a public key and a selector name.

Example DKIM TXT record:

```text theme={null}
Host: selector1._domainkey
Value: v=DKIM1; k=rsa; p=MIGfMA0G...<public-key>...
```

Copy the exact host and value from your provider and add them as a TXT record.

## DMARC records

DMARC builds on SPF and DKIM. It tells receivers what to do when a message fails both checks and can send you failure reports.

Example DMARC record:

```text theme={null}
Host: _dmarc
Value: v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com
```

Start with `p=none` or `p=quarantine` while you monitor reports, then move to `p=reject` once everything is working.

## Propagation and verification

DNS changes can take up to 48 hours to propagate worldwide, though many updates are visible within minutes.

Verify records with:

* `dig` in a terminal:
  ```bash theme={null}
  dig MX example.com
  dig TXT example.com
  ```
* [MXToolbox](https://mxtoolbox.com) for browser-based lookups

<Tip>
  If email still isn't working after 48 hours, check that values were copied exactly. A single extra space in SPF or a typo in a DKIM key breaks the record.
</Tip>

Need help? Contact [support@enrolweb.com](mailto:support@enrolweb.com).
