Canny Pigeons

Learn · Email authentication

Wix DMARC & SPF Record: How to Set Up Email Authentication

The Wix email story surprises most people: Wix doesn't host your business email. Your domain's SPF and DKIM records come from whoever does — Wix Professional Email is Google Workspace under the hood, and you may use Microsoft 365 or another provider instead — and Wix's own help center says exactly that: get your SPF value from your email provider. DMARC, though, is the one record you own no matter what, and it's the piece that makes everything else count.

The short version: SPF and DKIM come from your mailbox provider, not from Wix. DMARC is yours to publish, in the Wix DNS panel if your domain is registered there. Wix's own site mail — form notifications, order confirmations — is sent by Wix from Wix's address and needs nothing from you.

Which mail is actually yours to authenticate?

Untangle this first and the rest is mechanical. Three categories, only two of which need records from you:

If you're not sure which provider holds your mailboxes, run your domain through the free DMARC checker — the MX records it reports name them outright.

Wix SPF record — ask your email provider

Check who sends mail for your domain, then add their SPF value as a TXT record at your domain's root:

Wix's own site mail (notifications, forms, bookings) is handled by Wix's infrastructure and doesn't need an entry from you. If your domain already has an SPF record, merge the includes into one record and stay under 10 DNS lookups.

Both halves of that last sentence are load-bearing. Two SPF records is a permanent error — receivers that find two stop evaluating both, so a domain with a perfectly good Google record plus a leftover record from an old host authenticates nothing. And ten lookups is a hard protocol limit, not a guideline: every include: resolves recursively, and going over returns permerror with the same result. The free SPF record checker resolves your record the way a receiver does and gives you the count.

Wix DKIM

Same rule: it lives with your email provider. For Wix Professional Email, that means Google — open Google Admin (Apps → Google Workspace → Gmail → Authenticate email), generate the key, and publish the TXT record it gives you at the selector it names. Microsoft 365 and Zoho each have their own console and their own selector. Site notifications from Wix are signed by Wix's own infrastructure, so there's nothing for you to add.

Two things people miss with Google specifically. Generating the key does not turn signing on — after publishing the record you have to go back and click Start authentication, and a key that's published but never started is the most common "DKIM is set up but nothing is signed" case there is. And choose the 2048-bit option: 1024-bit still validates, but it's weak and the major mailbox providers have signalled they intend to stop accepting it.

Confirm the key is live with the free DKIM checker. If it reports nothing, that isn't proof DKIM is missing — DNS gives no way to enumerate selectors, so a custom one is invisible to any probe. The s= tag on the DKIM-Signature header of a message you've sent is the definitive answer.

Wix DMARC record — click by click

This one is yours to publish, and it covers every sender at once: DMARC is a property of your domain, not of any individual mail service.

  1. Open your Wix dashboard and go to Domains.
  2. Click the domain you want to protect.
  3. Open Advanced Settings, then DNS Records.
  4. Find the TXT section and click Add Record.
  5. Set the Host name to _dmarc — on its own. Wix appends your domain automatically; typing the full _dmarc.yourdomain.com produces a record at _dmarc.yourdomain.com.yourdomain.com that no receiver will ever look up.
  6. Paste the record into the Value field and save.

If your domain is registered elsewhere and merely pointed at Wix, the nameservers may still be at that registrar — in which case the record goes there instead. The Wix DNS panel only governs domains whose DNS Wix actually hosts. Adding the record in the wrong place is a close second to the host-field mistake above as a reason a published record can't be found.

The record to publish

v=DMARC1; p=none; rua=mailto:reports@yourdomain.com

Watch the aggregate reports for a week or two. Once every sender listed is one you own, enforce:

v=DMARC1; p=quarantine; rua=mailto:reports@yourdomain.com; sp=quarantine

Then reject, when you're ready:

v=DMARC1; p=reject; rua=mailto:reports@yourdomain.com; sp=reject; adkim=s; aspf=s

Wix itself runs p=quarantine on its own domain, so the walk is proven on their infrastructure too. Every tag in those records is explained in DMARC record examples.

Wix with Google Workspace, step by step

This is the common arrangement, and it's worth having the whole sequence in one place:

  1. MX — point them at Google, using the hostnames the Google Admin console gives you for your account. Wix's DNS panel has a dedicated MX section.
  2. SPF — one TXT record at the root: v=spf1 include:_spf.google.com ~all, merged with anything already there.
  3. DKIM — generate in Google Admin, publish the TXT record at the host Google names (usually google._domainkey), wait for propagation, then click Start authentication.
  4. DMARC — the _dmarc TXT record above.
  5. Verify — run the DMARC checker and the DKIM checker against the live domain rather than trusting the panels.

Do them in that order. Publishing an enforcing DMARC policy before DKIM is signing is how a small business discovers, in production, that its own invoices are being rejected.

What changes in your reports

Before: mail from your provider passes SPF and DKIM, but aligned to the provider's domain — so DMARC fails and spoofers have an open door. After: aligned records plus your own DMARC policy, and your reports list only senders you own.

Aggregate reports arrive as compressed XML, usually starting a day or two after you publish. They're the only way to see which services are sending as your domain — including the ones nobody remembers signing up for. If you have one to hand, the free DMARC report analyzer turns it into a readable per-sender table in your browser, no account required.

Troubleshooting

The DMARC checker says my record isn't there

Check the host field first — _dmarc, not the full domain — and then check where you added it. If your nameservers point at a registrar rather than at Wix, the Wix panel's records are inert. Beyond that, give DNS an hour before concluding anything.

My Wix campaigns fail DMARC but my mailbox mail passes

They're different senders with different authentication. Look at the failing message's DKIM-Signature header: if d= names a Wix domain rather than yours, that mail isn't aligned to you, and it will be affected when you move to an enforcing policy. Stay at p=none until your reports show every sender you intend to keep passing.

Do I need DMARC if my Wix site barely sends email?

Yes — a domain that sends little is a domain nobody is watching, which is precisely what makes it attractive to spoof. The policy costs one DNS record, and on a domain with no legitimate senders to break, you can publish p=reject immediately rather than walking up to it.

Free checks: DMARC checker SPF checker DKIM checker Spam checker

Done? Run the free DMARC checker — it reads your live DNS and confirms everything parses and aligns. For the staged walk from p=none to p=reject, see DMARC policies explained.

See every sender using your domain

Point one DNS record at Canny Pigeons and get a clear dashboard of your DMARC reports — free for one domain, hosted DMARC included.

Start free