Skip to content
DMARC Done

Cloudflare guide

SPF, DKIM and DMARC on Cloudflare DNS: exact records

How to add SPF, DKIM and DMARC records in Cloudflare DNS, why DKIM CNAMEs must be DNS only, and how Email Routing and DMARC Management fit in.

DMARC Done team · 5 October 2026 · 4 min read

Cloudflare is a DNS host, not a mailbox provider. If your domain uses Cloudflare name servers, your email records live in Cloudflare, even though your email runs on Microsoft 365, Google Workspace, Zoho or another provider. This guide shows how to enter the records in Cloudflare and the Cloudflare-specific details to watch.

How Cloudflare wants records entered

  1. Log in to the Cloudflare dashboard and select your domain.
  2. Go to the DNS Records page.
  3. Select Add record.
  4. Choose the Type, fill in Name and Content, then save.

Name field: Cloudflare’s documentation describes the Name as “A subdomain or the zone apex (@)”. Cloudflare adds your domain to what you type. So:

Record Type What you type in Name What it becomes
SPF TXT @ yourdomain.com
DMARC TXT _dmarc _dmarc.yourdomain.com
DKIM (Google, Zoho) TXT google._domainkey (example) google._domainkey.yourdomain.com
DKIM (Microsoft 365) CNAME selector1._domainkey selector1._domainkey.yourdomain.com

Type the short form shown above. After saving, the record list shows the full name, so you can confirm it landed in the right place.

Proxy status: the Cloudflare-specific trap

Cloudflare can “proxy” some records through its network. Its documentation is clear about which ones: “Only … A, AAAA, and CNAME records can be proxied. Other record types (such as MX or TXT) are always DNS-only.”

That makes SPF, DMARC and TXT-based DKIM safe by default. The one to watch is DKIM delivered as a CNAME, which is how Microsoft 365 and some sending services do it. Cloudflare says a query to a proxied record “will be answered with Cloudflare anycast IP addresses” rather than the real target, and it recommends keeping email records DNS-only. Cloudflare already blocks proxying for some records used for DKIM, but check anyway: when you add a DKIM CNAME, make sure Proxy status shows DNS only (the grey cloud).

The records to add

Use the values from your mail provider’s guide:

  • Microsoft 365: SPF v=spf1 include:spf.protection.outlook.com -all, plus two DKIM CNAMEs copied from the Microsoft Defender portal.
  • Google Workspace: SPF v=spf1 include:_spf.google.com ~all, plus a DKIM TXT record at google._domainkey.
  • Zoho Mail: the Zoho SPF include from your Admin Console, plus a DKIM TXT record for your selector.

Then the DMARC starter record:

Type:    TXT
Name:    _dmarc
Content: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1
TTL:     Auto

Create the dmarc-reports@ mailbox or alias with your mail provider first.

If you use Cloudflare Email Routing

Email Routing forwards mail sent to your domain to another inbox, such as a personal Gmail address. When you turn it on, Cloudflare adds three MX records, a DKIM record at cf2024-1._domainkey and this SPF record:

v=spf1 include:_spf.mx.cloudflare.net ~all

Cloudflare’s documentation states that “Email Routing does not support sending or replying from your Cloudflare domain.” If you reply from the destination inbox, the reply comes from that address, not from your domain.

If you use Email Routing for incoming mail and a separate provider to send, you still need exactly one SPF record. Merge them, for example:

v=spf1 include:_spf.mx.cloudflare.net include:_spf.google.com ~all

Cloudflare also offers a separate Email Sending product. If you use it, follow Cloudflare’s own setup records for it.

Cloudflare DMARC Management

Cloudflare has a built-in feature called DMARC Management, which it says “helps you track every source that is sending emails from your domain and review DMARC reports”. Its documentation says it is “Available on all plans”.

To turn it on, go to Email > DMARC Management and select Enable DMARC Management. If your domain has no DMARC record, Cloudflare offers to add one. If it already has one, Cloudflare adds its own reporting address to your rua tag.

Cloudflare also recommends its Email security wizard (under DMARC Management, View records) for creating SPF, DKIM and DMARC records instead of writing them by hand.

Both are reasonable options. Just make sure you end up with exactly one DMARC record. A rua tag can hold several addresses separated by commas, so Cloudflare’s address and your own can sit in the same record.

Plain-English takeaway: In Cloudflare, type _dmarc and @ in the Name field, keep DKIM CNAMEs on DNS only (grey cloud), and if you use Email Routing, merge its SPF include into a single SPF record.

Common mistakes on Cloudflare

  • A proxied DKIM CNAME. If a DKIM CNAME shows the orange cloud, switch it to DNS only so receivers can follow it to your key.
  • Editing DNS at the registrar instead of Cloudflare. Once a domain uses Cloudflare name servers, records at your registrar no longer count.
  • Two SPF records. Email Routing adds one. If you add your provider’s record next to it instead of merging, SPF fails with a permanent error.
  • Two DMARC records. Adding a record manually after DMARC Management or the wizard already created one.
  • Deleting Email Routing records you still need. If you stop using Email Routing, remove its MX and SPF parts. If you still use it, leave them.

Check your setup

Run the free checker at /check?d=yourdomain.com. It detects Cloudflare from your name servers, identifies your mail provider and shows whether SPF, DKIM and DMARC are correct.

When to move to quarantine and reject

p=none collects reports but does not stop anyone from sending email as your domain. When reports show all your legitimate mail passing, move to p=quarantine and then p=reject. Our post on DMARC quarantine vs reject explains the safe order.

If you want us to read the reports and take the domain to p=reject for you, see pricing. If we do not get there within 60 days, you get a full refund.

Sources

See where your domain stands in 10 seconds

Free. No signup. We do not store the domains you check.