Email VPS
Support
Guides Contact Us
Email guides

Email DNS records: MX, SPF, DKIM and DMARC

Email DNS records

Email needs a few DNS records to work. MX tells senders where your mail is delivered, and SPF, DKIM and DMARC tell the recipient that the message is genuine. Without the last three your messages easily end up in spam.

Where to find your own values

Sign in to your account and open Email. Under your domain you will see the records you need and a copy button. If the domain uses our name servers we can add the records for you with one click. If they are with another provider, copy the values and add them there.

Always use the values from your account. The ones below are defaults, and DKIM is always specific to your domain.

MX, receiving mail

The MX record tells senders which server receives your mail. There is one record, not two, and the priority is 10.

With hosting email the value is mail.nordweb.fi and with Nordweb Email it is posti.nordweb.fi. A wrong value sends your mail to a machine that has no mailbox for you, and the sender gets an error.

SPF, who may send

SPF lists the servers allowed to send mail using your domain. Add a TXT record for the name @.

Hosting email: v=spf1 a mx include:_spf.nordweb.fi ~all

Nordweb Email: v=spf1 mx include:_spf.nordweb.fi ~all

Use the include form rather than listing IP addresses. The include is the part we can update without breaking your record if our servers ever change.

If you also send from elsewhere, such as a newsletter service or a webshop, add their include to the same record. You may only have one SPF record.

DKIM, the signature

DKIM adds a signature to outgoing mail so the recipient can verify the message was not altered on the way.

Nordweb Email signs with DKIM. The key is specific to your domain, so it cannot be printed in this guide. You will find it in the Email section of your account under the name mail._domainkey. The key is ready about a minute after the mailbox is created.

Hosting email has no DKIM. It does not sign messages, so there is no DKIM record and you should not invent one. A wrong key is worse than none, because the recipient will then reject even a genuine message. If you need DKIM, contact support and we will look at the options.

DMARC, what to do with suspicious mail

DMARC combines SPF and DKIM and tells the recipient how to act when a check fails. Add a TXT record for the name _dmarc.

Start gently and watch the reports:

v=DMARC1; p=none; rua=mailto:postmaster@your-domain.com

Replace the report address with your own. Once the reports confirm your own mail passes, you can tighten the policy to p=quarantine.

Do not start strict. If SPF or DKIM has not spread yet, a strict DMARC quietly loses your own mail.

Why these matter

  • They stop fraudsters from sending messages in your name.
  • They improve deliverability, so your mail does not land in spam.
  • Gmail and Microsoft require them ever more strictly, and without them some mail is rejected outright.

DNS changes usually show up in minutes, but sometimes they take hours to spread. Wait before changing the values again.