Learn · Email authentication
Wix DMARC & SPF Record: How to Set Up Email Authentication
The Wix email story surprises most people: Wix doesn't host your business email. Your domain's SPF and DKIM records come from whoever does — Wix Professional Email is Google Workspace under the hood, and you may use Microsoft 365 or another provider instead — and Wix's own help center says exactly that: get your SPF value from your email provider. DMARC, though, is the one record you own no matter what, and it's the piece that makes everything else count.
Wix SPF record — ask your email provider
Check who sends mail for your domain, then add their SPF value as a TXT record at your domain's root:
- Wix Professional Email / Google Workspace:
v=spf1 include:_spf.google.com ~all— Wix sells business email powered by Google Workspace, so this is the same record either way. - Microsoft 365:
v=spf1 include:spf.protection.outlook.com -all - Zoho Mail:
v=spf1 include:zoho.com ~all— andzoho.eu,zoho.inorzoho.com.auif your mailbox is in that region. See our Zoho guide.
Wix's own site mail (notifications, forms, bookings) is handled by Wix's infrastructure and doesn't need an entry from you. If your domain already has an SPF record, merge the includes into one record and stay under 10 DNS lookups.
Wix DKIM
Same rule: it lives with your email provider. For Wix Professional Email, that means Google — open Google Admin (Apps → Google Workspace → Gmail → Authenticate email), generate the key, and publish the TXT record it gives you at the selector it names. Microsoft 365 and Zoho each have their own console and their own selector. Site notifications from Wix are signed by Wix's own infrastructure, so there's nothing for you to add.
Wix DMARC record
This one is yours to publish. In your Wix account, open your domain's DNS settings (Domains → your domain → Advanced Settings → DNS Records), or your external DNS host if the domain isn't registered with Wix. Add a TXT record named _dmarc:
v=DMARC1; p=none; rua=mailto:reports@yourdomain.com
Watch the aggregate reports for a week or two. Once every sender listed is one you own, enforce:
v=DMARC1; p=quarantine; rua=mailto:reports@yourdomain.com; sp=quarantine
Then reject, when you're ready:
v=DMARC1; p=reject; rua=mailto:reports@yourdomain.com; sp=reject; adkim=s; aspf=s
Wix itself runs p=quarantine on its own domain, so the walk is proven on their infrastructure too.
What changes in your reports
Before: mail from your provider passes SPF and DKIM, but aligned to the provider's domain — so DMARC fails and spoofers have an open door. After: aligned records plus your own DMARC policy, and your reports list only senders you own.
Done? Run the free DMARC checker — it reads your live DNS and confirms everything parses and aligns. For the staged walk from p=none to p=reject, see DMARC policies explained.