Skip to content
DMARC Done

GoDaddy guide

SPF, DKIM and DMARC at GoDaddy: exact records

How to add SPF, DKIM and DMARC records in GoDaddy DNS, the values for GoDaddy email and Microsoft 365 from GoDaddy, and the default DMARC record to check.

DMARC Done team · 5 October 2026 · 5 min read

This guide covers two situations:

  1. Your domain’s DNS is at GoDaddy and your email is somewhere else, such as Microsoft 365 or Google Workspace bought directly.
  2. You also bought your email from GoDaddy: Professional Email or Microsoft 365 from GoDaddy.

It shows how to enter records in GoDaddy’s DNS panel and which values GoDaddy’s own help pages give for its email products.

Check this first: GoDaddy may have added a DMARC record already

GoDaddy announced that “Starting April 2025, all new domains purchased or transferred into GoDaddy are secured with a default DMARC record in the DNS Zone with quarantine as the initial policy.”

GoDaddy’s help center shows that default as:

v=DMARC1; p=quarantine; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net;

Two things follow from that:

  • Do not add a second DMARC record. If a _dmarc TXT record already exists, edit it. Two DMARC records cause receivers to ignore DMARC entirely.
  • Check that your real email passes before you keep p=quarantine. If your mail is sent through a service that is not yet set up for SPF or DKIM on your domain, a quarantine policy can push it into spam. The reports from that default record go to a GoDaddy address, not to you.

How GoDaddy wants records entered

The steps from GoDaddy’s help center:

  1. Sign in to your GoDaddy Domain Portfolio.
  2. Select your domain, then select DNS.
  3. Select Add New Record and choose the record type (TXT or CNAME).
  4. Fill in Name, Value and TTL, then save.

Name field: GoDaddy describes it as “The hostname or prefix of the record, without the domain name. Enter @ to put the record on your root domain.” So:

Record What you type in Name What it becomes
SPF @ yourdomain.com
DMARC _dmarc _dmarc.yourdomain.com
DKIM selector1._domainkey (example) selector1._domainkey.yourdomain.com

Do not type _dmarc.yourdomain.com in the Name field. GoDaddy adds the domain for you, and the extra copy puts the record in the wrong place.

TTL: GoDaddy’s default of 1 hour is fine.

If your email is GoDaddy Professional Email or Microsoft 365 from GoDaddy

SPF

GoDaddy’s help center says the SPF record for its email “must have the Value set as v=spf1 include:secureserver.net -all”. This applies to both Professional Email and Microsoft 365 from GoDaddy.

Type:  TXT
Name:  @
Value: v=spf1 include:secureserver.net -all

GoDaddy also says: “If your domain, DNS, and email are in the same GoDaddy account, we’ll add the SPF record for you.” Check before adding, because a domain may have only one SPF record. If you also send through another service, add its include: before -all in the same record.

GoDaddy documents a different SPF value for Microsoft 365 with its Advanced Email Security add-on. If you have that add-on, use the value from GoDaddy’s help page for it.

DKIM for Professional Email

GoDaddy says domains purchased after April 2025 automatically have DKIM added for Professional Email, and that DKIM will “eventually” be added to existing domains. For older domains, you add two CNAME records named secureserver1._domainkey and secureserver2._domainkey. Copy their values from your Email & Office Dashboard; do not guess them.

DKIM for Microsoft 365 from GoDaddy

GoDaddy’s instructions send you to the Microsoft Defender portal:

  1. Sign in with your Microsoft 365 email address and password. GoDaddy notes that “your GoDaddy username and password won’t work here.”
  2. Create the DKIM keys for your domain. Microsoft shows two CNAME records.
  3. Add both CNAMEs in GoDaddy DNS, with Names selector1._domainkey and selector2._domainkey.
  4. Back in the Defender portal, turn on signing with DKIM signatures.

DMARC

GoDaddy’s own Microsoft 365 DMARC example starts at p=quarantine. We suggest starting at p=none with reports sent to you, so you can see every sender first. If a default record already exists, edit it to:

Type:  TXT
Name:  _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1

Create the dmarc-reports@ mailbox or alias first.

If your email is somewhere else

Use the SPF and DKIM values from your email provider and enter them in GoDaddy DNS as shown above:

  • Microsoft 365 bought from Microsoft: include:spf.protection.outlook.com and two DKIM CNAMEs.
  • Google Workspace: include:_spf.google.com and a DKIM TXT record at google._domainkey.
  • Zoho Mail: the Zoho include and a DKIM TXT record for your selector.

The DMARC record is the same starter record as above.

Plain-English takeaway: In GoDaddy DNS, type only the prefix in the Name field (@, _dmarc, selector1._domainkey). Look for an existing _dmarc record before adding one, because newer GoDaddy domains get a default quarantine record.

Common mistakes at GoDaddy

  • Two DMARC records. Adding your own record next to GoDaddy’s default instead of editing it.
  • Two SPF records. GoDaddy may have added one automatically. Merge any additions into it.
  • The full domain in the Name field. It creates _dmarc.yourdomain.com.yourdomain.com.
  • Editing DNS at GoDaddy when the domain uses other name servers. If your domain points to Cloudflare or another DNS host, GoDaddy’s DNS page does not count. Edit records where the name servers point.
  • Mixing up products. Microsoft 365 from GoDaddy uses include:secureserver.net. Microsoft 365 bought directly from Microsoft uses include:spf.protection.outlook.com.

Check your setup

Run the free checker at /check?d=yourdomain.com. It shows whether your DNS is at GoDaddy, which mail provider you use, and whether you have one valid SPF record, DKIM and exactly one DMARC record.

When to move to quarantine and reject

A DMARC record at p=none only reports. Once reports show all your legitimate mail passing, move to p=quarantine and then p=reject. Our post on DMARC quarantine vs reject explains the safe order.

If you want us to read the reports and take the domain to p=reject for you, see pricing. If we do not get there within 60 days, you get a full refund.

Sources

See where your domain stands in 10 seconds

Free. No signup. We do not store the domains you check.