Skip to main content
To send and receive email through your domain, you must publish DNS records that tell the internet where to deliver messages and how to verify your identity. This page explains the four record types that matter most (MX, SPF, DKIM, DMARC) and shows you how to add them in EnrolWeb DNS Management.

Record types at a glance

MX

Route incoming mail to the correct mail server.

SPF

Authorize which servers can send email for your domain.

DKIM

Cryptographically sign messages to prove they’re authentic.

DMARC

Tell receivers how to handle messages that fail SPF or DKIM.

Where to edit records

Open DNS Management for the domain you want to configure. DNS changes are per-domain, so edit each zone separately.

MX records

MX records tell other mail servers where to deliver messages sent to your domain. Without MX records, email cannot reach your mailbox. Priority values control preference; lower numbers are preferred.

Add an MX record

1

Open DNS Management

In your EnrolWeb dashboard, open DNS Management for the domain.
2

Add a new record

Click Add Record and choose MX as the type.
3

Enter the values

Set Host to @ (or your domain), a Priority (like 10), and the Points to value from your provider.
4

Save

Save and repeat for each MX record your provider requires.

SPF records

An SPF record is a TXT record that lists which mail servers may send email for your domain. Receivers use it to catch spoofed messages.

Add a TXT (SPF) record

1

Open DNS Management

Go to DNS Management for the domain.
2

Add a TXT record

Click Add Record and choose TXT.
3

Enter values

Set Host to @ and paste the SPF value in the Value field.
4

Save

Click Save.
Example SPF (replace with your provider’s value):
You can only have one SPF record per domain. If you need multiple services, combine their include mechanisms in a single record.

DKIM records

DKIM adds a digital signature to outgoing messages. Receivers verify the signature against a public key in your DNS. Your provider generates a public key and a selector name. Example DKIM TXT record:
Copy the exact host and value from your provider and add them as a TXT record.

DMARC records

DMARC builds on SPF and DKIM. It tells receivers what to do when a message fails both checks and can send you failure reports. Example DMARC record:
Start with p=none or p=quarantine while you monitor reports, then move to p=reject once everything is working.

Propagation and verification

DNS changes can take up to 48 hours to propagate worldwide, though many updates are visible within minutes. Verify records with:
  • dig in a terminal:
  • MXToolbox for browser-based lookups
If email still isn’t working after 48 hours, check that values were copied exactly. A single extra space in SPF or a typo in a DKIM key breaks the record.
Need help? Contact support@enrolweb.com.