Learn · Email authentication
Wix DMARC & SPF Record: How to Set Up Email Authentication
The Wix email story surprises most people: Wix doesn't host your business email. Your domain's SPF and DKIM records come from whoever does — Wix Professional Email is Google Workspace under the hood, and you may use Microsoft 365 or another provider instead — and Wix's own help center says exactly that: get your SPF value from your email provider. DMARC, though, is the one record you own no matter what, and it's the piece that makes everything else count.
The short version: SPF and DKIM come from your mailbox provider, not from Wix. DMARC is yours to publish, in the Wix DNS panel if your domain is registered there. Wix's own site mail — form notifications, order confirmations — is sent by Wix from Wix's address and needs nothing from you.
Which mail is actually yours to authenticate?
Untangle this first and the rest is mechanical. Three categories, only two of which need records from you:
- Your mailboxes — the address a person replies from. Hosted by Google Workspace, Microsoft 365, Zoho or similar. Their SPF include and their DKIM key are what your domain publishes.
- Marketing you send from Wix — campaigns and automations composed in the Wix dashboard, sent from Wix's infrastructure. Whether these align to your domain depends on whether Wix signs them with a DKIM key for your domain; your aggregate reports will tell you within days, and so will the
d=tag on the DKIM-Signature header of a message you send yourself. - Site notifications — form submissions, order confirmations, booking reminders, abandoned-cart mail. Wix sends these from its own sending domain, so there is nothing for you to publish. A customer receipt showing a Wix sender rather than your domain is working as designed.
If you're not sure which provider holds your mailboxes, run your domain through the free DMARC checker — the MX records it reports name them outright.
Wix SPF record — ask your email provider
Check who sends mail for your domain, then add their SPF value as a TXT record at your domain's root:
- Wix Professional Email / Google Workspace:
v=spf1 include:_spf.google.com ~all— Wix sells business email powered by Google Workspace, so this is the same record either way. - Microsoft 365:
v=spf1 include:spf.protection.outlook.com -all - Zoho Mail:
v=spf1 include:zoho.com ~all— andzoho.eu,zoho.inorzoho.com.auif your mailbox is in that region. See our Zoho guide.
Wix's own site mail (notifications, forms, bookings) is handled by Wix's infrastructure and doesn't need an entry from you. If your domain already has an SPF record, merge the includes into one record and stay under 10 DNS lookups.
Both halves of that last sentence are load-bearing. Two SPF records is a permanent error — receivers that find two stop evaluating both, so a domain with a perfectly good Google record plus a leftover record from an old host authenticates nothing. And ten lookups is a hard protocol limit, not a guideline: every include: resolves recursively, and going over returns permerror with the same result. The free SPF record checker resolves your record the way a receiver does and gives you the count.
Wix DKIM
Same rule: it lives with your email provider. For Wix Professional Email, that means Google — open Google Admin (Apps → Google Workspace → Gmail → Authenticate email), generate the key, and publish the TXT record it gives you at the selector it names. Microsoft 365 and Zoho each have their own console and their own selector. Site notifications from Wix are signed by Wix's own infrastructure, so there's nothing for you to add.
Two things people miss with Google specifically. Generating the key does not turn signing on — after publishing the record you have to go back and click Start authentication, and a key that's published but never started is the most common "DKIM is set up but nothing is signed" case there is. And choose the 2048-bit option: 1024-bit still validates, but it's weak and the major mailbox providers have signalled they intend to stop accepting it.
Confirm the key is live with the free DKIM checker. If it reports nothing, that isn't proof DKIM is missing — DNS gives no way to enumerate selectors, so a custom one is invisible to any probe. The s= tag on the DKIM-Signature header of a message you've sent is the definitive answer.
Wix DMARC record — click by click
This one is yours to publish, and it covers every sender at once: DMARC is a property of your domain, not of any individual mail service.
- Open your Wix dashboard and go to Domains.
- Click the domain you want to protect.
- Open Advanced Settings, then DNS Records.
- Find the TXT section and click Add Record.
- Set the Host name to
_dmarc— on its own. Wix appends your domain automatically; typing the full_dmarc.yourdomain.comproduces a record at_dmarc.yourdomain.com.yourdomain.comthat no receiver will ever look up. - Paste the record into the Value field and save.
If your domain is registered elsewhere and merely pointed at Wix, the nameservers may still be at that registrar — in which case the record goes there instead. The Wix DNS panel only governs domains whose DNS Wix actually hosts. Adding the record in the wrong place is a close second to the host-field mistake above as a reason a published record can't be found.
The record to publish
v=DMARC1; p=none; rua=mailto:reports@yourdomain.comWatch the aggregate reports for a week or two. Once every sender listed is one you own, enforce:
v=DMARC1; p=quarantine; rua=mailto:reports@yourdomain.com; sp=quarantineThen reject, when you're ready:
v=DMARC1; p=reject; rua=mailto:reports@yourdomain.com; sp=reject; adkim=s; aspf=sWix itself runs p=quarantine on its own domain, so the walk is proven on their infrastructure too. Every tag in those records is explained in DMARC record examples.
Wix with Google Workspace, step by step
This is the common arrangement, and it's worth having the whole sequence in one place:
- MX — point them at Google, using the hostnames the Google Admin console gives you for your account. Wix's DNS panel has a dedicated MX section.
- SPF — one TXT record at the root:
v=spf1 include:_spf.google.com ~all, merged with anything already there. - DKIM — generate in Google Admin, publish the TXT record at the host Google names (usually
google._domainkey), wait for propagation, then click Start authentication. - DMARC — the
_dmarcTXT record above. - Verify — run the DMARC checker and the DKIM checker against the live domain rather than trusting the panels.
Do them in that order. Publishing an enforcing DMARC policy before DKIM is signing is how a small business discovers, in production, that its own invoices are being rejected.
What changes in your reports
Before: mail from your provider passes SPF and DKIM, but aligned to the provider's domain — so DMARC fails and spoofers have an open door. After: aligned records plus your own DMARC policy, and your reports list only senders you own.
Aggregate reports arrive as compressed XML, usually starting a day or two after you publish. They're the only way to see which services are sending as your domain — including the ones nobody remembers signing up for. If you have one to hand, the free DMARC report analyzer turns it into a readable per-sender table in your browser, no account required.
Troubleshooting
The DMARC checker says my record isn't there
Check the host field first — _dmarc, not the full domain — and then check where you added it. If your nameservers point at a registrar rather than at Wix, the Wix panel's records are inert. Beyond that, give DNS an hour before concluding anything.
My Wix campaigns fail DMARC but my mailbox mail passes
They're different senders with different authentication. Look at the failing message's DKIM-Signature header: if d= names a Wix domain rather than yours, that mail isn't aligned to you, and it will be affected when you move to an enforcing policy. Stay at p=none until your reports show every sender you intend to keep passing.
Do I need DMARC if my Wix site barely sends email?
Yes — a domain that sends little is a domain nobody is watching, which is precisely what makes it attractive to spoof. The policy costs one DNS record, and on a domain with no legitimate senders to break, you can publish p=reject immediately rather than walking up to it.
Free checks: DMARC checker SPF checker DKIM checker Spam checker
Done? Run the free DMARC checker — it reads your live DNS and confirms everything parses and aligns. For the staged walk from p=none to p=reject, see DMARC policies explained.