Learn · Email authentication
How to set up SPF, DKIM & DMARC for Zoho Mail
Setting up SPF, DKIM and DMARC for Zoho Mail is a 15-minute job, and none of it happens inside Zoho. You publish three records in your own DNS — Zoho only gives you the values. When you're done, mail sent through Zoho will be verifiably yours, and spoofers won't be able to fake your domain. (Zoho runs p=reject on its own domain — the standard is proven at their scale.)
Zoho SPF record
Add this as a TXT record at the root of your domain:
v=spf1 include:zoho.com ~all
include:zoho.com covers Zoho's mail servers, including Zoho CRM sends. The ~all says "softfail" — unlisted senders are marked suspicious but not rejected.
If your mailbox isn't on Zoho's US data centre, the include changes with it: zoho.eu, zoho.in or zoho.com.au. Each publishes its own record, and using the wrong one means your mail fails SPF. The domain you sign in at tells you which you're on.
Publish it, then wait a few minutes for DNS to spread. If your domain already has an SPF record, merge the two — never publish two (that's a permanent error). Watch the 10 DNS lookup limit while you do: include:zoho.com expands to four more includes internally, so it spends five of your ten on its own. Adding Google Workspace or Microsoft 365 alongside it takes you close to the ceiling, and going over means receivers return permerror and treat SPF as failed.
Zoho DKIM
In the Zoho Mail admin console (Domains → your domain → DKIM), Zoho generates a keypair and shows you a TXT record. Publish it at the selector it names — usually zoho._domainkey.yourdomain.com — then click Verify in Zoho.
That's the whole trick: Zoho holds the private key, DNS holds the public key, and receivers can now check that every message signed by Zoho genuinely came from your domain — even after forwarding.
Zoho DMARC record
Start in monitoring mode with reports going to a mailbox you actually read:
v=DMARC1; p=none; rua=mailto:reports@yourdomain.com
Watch the reports for a week or two. Once every sender in them is one you recognize, tighten to quarantine, then reject:
v=DMARC1; p=reject; rua=mailto:reports@yourdomain.com; sp=reject; adkim=s; aspf=s
sp=reject protects your subdomains too. The full format is covered in DMARC record examples.
What changes in your reports
Before: mail from Zoho shows SPF and DKIM passing — but aligned to zoho.com, not you, so DMARC fails. After: the same checks pass for your domain, DMARC passes, and the aggregate reports you receive list only senders you own. Anything else on the list is someone trying to use your name.
Done? Run the free DMARC checker — it reads your live DNS and confirms all three records parse and align. For the staged walk from p=none to p=reject, see DMARC policies explained.