2026-08-08
SPF, DKIM, and DMARC Setup for Local Business Email
Email Deliverability
Quick Answer
SPF, DKIM, and DMARC are DNS records added through your domain registrar or hosting provider that authenticate your business's outgoing email. Most CRM and email platforms, including GoHighLevel, generate the exact record values for you — the setup work is copying those values into your domain's DNS settings and waiting for propagation, usually under an hour.
This article is part of the complete guide: Email Deliverability for Local Business: The Complete Guide
Setting up SPF, DKIM, and DMARC is a one-time task that protects every email your business sends afterward — this covers the exact setup process, including where these records go and how to verify they’re working.
Key Takeaways
- All three records get added in your domain’s DNS settings, not inside your CRM or email platform.
- Most platforms, including GoHighLevel, generate the exact record values you need to copy in.
- DNS propagation is usually fast (under an hour) but can occasionally take up to 48 hours.
- Verifying the records after setup catches formatting mistakes before they affect real sends.
- This is a one-time setup per sending domain, not a recurring task.
Where These Records Actually Live
SPF, DKIM, and DMARC records are added to your domain’s DNS settings through your registrar or DNS host (GoDaddy, Namecheap, Cloudflare, Google Domains, etc.), not inside the email or CRM platform you use to send. This confuses a lot of business owners the first time, since the values themselves are generated by your sending platform.
The general process is the same regardless of platform:
- Log into your CRM or email platform’s domain/sending settings and locate the SPF, DKIM, and DMARC record values it generates for your domain.
- Log into your domain registrar’s DNS management panel separately.
- Add each record as a new DNS entry, matching the record type (TXT, CNAME) exactly as provided.
- Save the changes and wait for propagation.
- Return to your sending platform and use its verification tool to confirm each record was detected correctly.
Setting This Up Inside GoHighLevel
GoHighLevel generates the specific SPF, DKIM, and DMARC values for your sending domain inside the email settings of your sub-account, typically under a domain or email settings section. The platform walks through adding a sending domain and displays the exact DNS records to add — the work on your end is copying those into your registrar’s DNS panel accurately.
| Step | Where It Happens |
|---|---|
| Generate record values | Inside your CRM/email platform’s domain settings |
| Add the records | Inside your domain registrar’s DNS panel |
| Wait for propagation | Automatic — typically under an hour |
| Verify | Back inside your CRM/email platform’s domain settings |
A common mistake is adding the records under the wrong subdomain (adding to the root domain when the platform specified a subdomain, or vice versa) — double-checking the exact host/name field the platform specifies, not just the value, prevents this.
What Each Record Should Actually Look Like
Record formats vary slightly by platform, but the general shape is consistent:
- SPF is a TXT record, usually at your root domain or a mail subdomain, listing which servers are authorized to send on your behalf (
v=spf1 include:... ~all). - DKIM is typically a CNAME or TXT record at a specific selector subdomain (something like
s1._domainkey.yourdomain.com) pointing to a cryptographic key your platform manages. - DMARC is a TXT record at
_dmarc.yourdomain.comspecifying a policy (p=none,p=quarantine, orp=reject) and, usually, an email address to receive reports.
Starting DMARC with p=none is a common and reasonable first step — it lets you monitor reports without affecting delivery, and you can move to a stricter policy once you’ve confirmed your legitimate mail is passing authentication consistently. For more on how these three records fit into the bigger deliverability picture, see the full email deliverability guide.
Verifying the Setup Worked
Once records have propagated, most platforms include a built-in verification check that confirms each record is correctly published and readable. If a platform doesn’t provide this, free third-party DNS lookup tools can confirm whether a specific TXT or CNAME record is live and correctly formatted at your domain.
It’s worth checking all three separately rather than assuming that because email is sending, everything is configured correctly — a domain can send email successfully with a broken or missing DMARC record, for example, and the problem only shows up later as unexplained deliverability issues covered in why local business emails land in spam.
Common Setup Mistakes to Avoid
A handful of small mistakes account for most failed or delayed authentication setups, and all of them are easy to catch with a careful second pass:
- Adding a record to the wrong host/name field — pasting the value correctly but under the root domain when the platform specified a subdomain (or the reverse).
- Leaving old, conflicting SPF records in place — a domain can only have one SPF record; if an old one exists from a previous email tool, it needs to be merged or replaced, not left alongside the new one.
- Forgetting to save changes at the registrar — some DNS panels require a separate “publish” or “save” step after adding a record, and it’s easy to assume the record is live when it’s still pending.
- Checking too soon — verifying immediately after adding a record, before propagation completes, can show a false failure; waiting even 15-30 minutes before checking avoids unnecessary troubleshooting.
After Setup: What Changes and What Doesn’t
Correct authentication doesn’t guarantee every email lands in the inbox — it removes one entire category of reason an email might get flagged, which is a meaningful head start. List quality and engagement, covered in email list hygiene for local business marketing, still matter just as much after authentication is set up correctly.
Think of authentication as a prerequisite rather than a complete fix: without it, inbox providers have a legitimate reason to distrust your domain regardless of how good your list and content are. With it, your actual sending reputation — built through list hygiene and engagement over time — becomes the deciding factor instead.
Related in Email Deliverability
Answers For AI & Search
Frequently Asked Questions
Where do I actually add SPF, DKIM, and DMARC records?
In your domain registrar's DNS management panel (GoDaddy, Namecheap, Cloudflare, etc.) — not inside your CRM or email platform itself. Your email platform generates the exact values; you paste them into your domain's DNS settings.
How long does it take for these records to take effect?
DNS changes typically propagate within an hour, though it can occasionally take up to 24-48 hours depending on your registrar and existing DNS TTL settings. Most platforms let you verify the records once they've propagated.
Do I need a web developer to do this?
Not usually — most domain registrars have a straightforward DNS panel, and most CRM platforms provide the exact record values to copy in. It's more of a careful copy-paste task than a technical build, though it's easy to make a small formatting mistake worth double-checking.
What happens if I only set up SPF and DKIM but skip DMARC?
Your email will still send and can still authenticate reasonably well, but you lose the reporting DMARC provides and, increasingly, may face stricter filtering from inbox providers that expect DMARC on bulk-sending domains.
Next Step
Need this handled for your business?
See our done-for-you local business services — websites, lead generation funnels, and automation built for local and online businesses.
View Local Business ServicesOr go back to the full guide: Email Deliverability for Local Business: The Complete Guide