DKIM, SPF and DMARC
SPF, DKIM and DMARC (p=none) are published automatically for mail domains; DKIM keys rotate in three steps.
- Used by
- Client (admin and reseller on their accounts)
- Plan
- Free
- Status
- Available
- Category
- DNS and email
What it is
When you add a mail domain and this node serves its zone, the panel publishes SPF, DKIM and DMARC. Rotation is Prepare (new key and record, still signing with the old one), Confirm after DNS propagates, then Retire.
What it is for
Better deliverability from the first message and key rotation without breaking signatures in flight.
Limits
Records are only published when the node serves the zone and it belongs to the same client; otherwise the panel gives you the records to add. DMARC starts at p=none; tightening it is your decision. DKIM signs authenticated submission (587/465) with the envelope sender's domain; PHP mail() is not signed.