Inbox providers such as Gmail check three DNS records on your domain (SPF, DKIM and DMARC) to tell whether an email comes from you. The Deliverability section on the Email sending page looks up those records for the domain of your From email, and tells you, record by record, what to fix.
You will learn #
- What SPF, DKIM and DMARC do
- How to run the check and read its results
- How to fix a record that’s missing or wrong
- What the check can’t see, and where to look instead
Before you begin #
- Set a From email on your own domain. You set it in step 2 of the Email sending page. The check looks at the part after the @. If you leave From email empty, Tendlio sends from your WordPress admin email, and the check looks at that address’s domain.
- Find out where you manage your domain’s DNS records, for example at your domain registrar, in Cloudflare or in your hosting panel. You add or change the records there. Tendlio can only look them up.
What the three records do #
- SPF is a TXT record that lists the services allowed to send email for your domain. A domain should have only one SPF record.
- DKIM is a key your sending service gives you to add to your DNS. It lets inbox providers check the signature the service puts on each email.
- DMARC is a TXT record on _dmarc.your-domain that tells inbox providers what to do with email that fails the other two checks. Gmail and Yahoo have required one from bulk senders since 2024.
With the three records in place, inbox providers can confirm your emails come from your domain. Without them, your emails are more likely to land in spam, and an email sent through Brevo can show as sent “via brevo.com” instead of under your own name.
Run the check #
- In your WordPress admin, open Tendlio → Settings → Email sending.
- Scroll to Deliverability: is your domain set up?, under step 4.
- Read the row for each record. Each one has a state, the advice for that state, and the record Tendlio found, if it found one.
The states are:
- Looks good: the record is there.
- Needs attention: the record is there but has a problem, or a record you should add is missing.
- Action needed: a record your emails need is missing, or your From email can’t pass the checks.
- Can’t check: Tendlio couldn’t look this record up, or can’t check it for your sending method. It says nothing about whether the record is right.
When every record looks good, the section says so above the rows.
What the check looks for, by sending method #
Brevo. Tendlio checks that your SPF record includes Brevo, and looks for Brevo’s DKIM key as the single TXT record at mail._domainkey that older Brevo setups use. If Brevo gave you two CNAME records for DKIM, the DKIM row shows Action needed even when they’re right. Brevo doesn’t need an SPF record unless you send from a dedicated IP, so you can ignore an SPF row that asks you to add Brevo, as long as Brevo shows your domain as authenticated. Set up on Brevo →, under the rows, opens the domain page in your Brevo account, where Brevo says whether your domain is authenticated and gives you the records to add.
Amazon SES and WordPress. Tendlio checks that an SPF record exists, but it can’t tell which service the record should list. The DKIM row shows Can’t check, because the DKIM key sits under a name that depends on the service that sends your email. Check DKIM where your sending service shows it:
- Amazon SES: the DKIM records are the three CNAME records from step 2 of the Amazon SES guide on the same page. The Amazon SES console shows your domain as Verified once they’re right.
- WordPress: look for a DKIM or domain authentication section in your SMTP plugin or in your email provider’s dashboard.
DMARC is checked the same way for every sending method.
Fix a record #
After you add or change a record where your DNS is managed, the change can take a few hours to show up. Then click Check again.
SPF #
- No SPF record found: add one TXT record that lists the services that send email for your domain. Each service’s documentation gives the value to add.
- More than one SPF record: mail servers treat two SPF records as an error. Merge them into one record, one v=spf1 line that lists every service you send through.
- An SPF record that doesn’t mention Brevo: Brevo doesn’t need it unless you send from a dedicated IP. If you add Brevo anyway, add include:spf.brevo.com to your existing record, not as a second record.
DKIM #
- No DKIM record found (Brevo): if Brevo’s domain page shows your domain as authenticated, your DKIM uses Brevo’s newer records, which this row can’t see. Otherwise, copy the DKIM record from Brevo’s domain setup. The row names the exact place Tendlio looked.
DMARC #
- No DMARC record: a minimal record is enough to start. Add a TXT record named _dmarc.your-store.com, with your own domain in place of your-store.com, and the value v=DMARC1; p=none. The row gives you the exact name.
- DMARC is set (policy: none): p=none only monitors. It’s a fine place to start, and you can make the policy stricter once you trust your setup.
If your From email is on a subdomain, such as shop.your-store.com, a DMARC record on your-store.com covers it, and the row says where Tendlio found it.
If your From email is on a free mailbox #
If your From email ends in gmail.com, yahoo.com, outlook.com or another free mailbox, the section shows a single row, From address, marked Action needed. You can’t add DNS records to a domain you don’t own, and large inbox providers reject bulk email that claims to come from a free mailbox, or send it to spam. Use an address on your own domain, such as hello@your-store.com, save it in step 2, and the check runs again.
When the check can’t run #
- DNS check, Can’t check: some hosts block DNS lookups from your site. That says nothing about your records. With Brevo, Brevo’s domain page shows whether each record is right. Otherwise, look at the records where your DNS is managed.
- One record shows Can’t check: Tendlio couldn’t look up that record just now. Click Check again in a moment.
- From email, Can’t check: there’s no valid address to check. Fill in From email in step 2 and save.
Tendlio keeps the results for 12 hours, and then looks the records up again the next time you open the page. The line under the rows says when it last checked. A result from a lookup that failed is kept for only 15 minutes. Check again looks the records up right away.
Why the check works this way #
It checks the domain of your From email #
Inbox providers compare the records with the domain in the address your emails come from. A record on another domain doesn’t help that address, so the check looks where the inbox providers look.
DKIM is checked only for Brevo #
Each sending service picks the name its DKIM key goes under. Tendlio looks for Brevo’s key where older Brevo setups put it, at mail._domainkey. For other services, only the service knows the name, so Tendlio would be guessing.
p=none is a safe place to start #
A DMARC policy can tell inbox providers to reject email that fails the other checks. If one of your records is still wrong, a strict policy could stop your own emails. p=none asks them to take no action, so you can get SPF and DKIM right first.
Additional resources #
- How to set up email sending and switch it to Live: the From email, and the Amazon SES guide.
- How sending works: waiting emails, the daily limit and email analytics: bounces and spam complaints.
- Emails aren’t going out
Frequently asked questions #
Why does DKIM say Can't check? #
If you send through Amazon SES or WordPress, where the DKIM key lives depends on your sending service, so check it in that service: the Amazon SES console, or your SMTP plugin or email provider. With Brevo, the lookup failed: click Check again in a moment.
Can I send from my Gmail address? #
Not for customer emails. A free mailbox can't pass SPF, DKIM and DMARC for your store, and large inbox providers reject bulk email that claims to come from one, or send it to spam. Use an address on your own domain.
I added the record, why is it still red? #
DNS changes can take a few hours to show up. Wait, then click Check again.
Does Tendlio add the records for me? #
No. The records live where your domain's DNS is managed, and you add them there. Tendlio looks them up and tells you what's missing.