Skip to content
DMARC Done

IONOS guide

SPF, DKIM and DMARC at IONOS: exact records

How to add SPF, DKIM and DMARC records in IONOS DNS, what IONOS sets up for its own mail automatically, and the DMARC record you add yourself.

DMARC Done team · 5 October 2026 · 4 min read

This guide covers domains whose DNS is at IONOS, whether you also use IONOS email or send through Microsoft 365, Google Workspace or another provider. IONOS does a lot automatically for its own mail. DMARC is the part you add yourself.

How IONOS wants records entered

The path from IONOS’s help center:

  1. Log in to IONOS and click the Domains & SSL tile.
  2. Click the gear icon under Actions next to your domain.
  3. Click DNS.
  4. Click Add record and choose the record type.
  5. Fill in Host name and Value, then click Save.

Host name field: for DMARC, IONOS says to “enter the subdomain name _dmarc”. For the root domain, IONOS uses @. IONOS adds your domain to what you type:

Record Type What you type in Host name What it becomes
SPF TXT @ yourdomain.com
DMARC TXT _dmarc _dmarc.yourdomain.com
DKIM (example) CNAME or TXT selector1._domainkey selector1._domainkey.yourdomain.com

If you use IONOS email

SPF is on by default

IONOS states: “IONOS SPF is enabled by default for all IONOS-hosted domains.” The values it uses are:

US accounts:     v=spf1 include:_spf-us.ionos.com ~all
UK/EU accounts:  v=spf1 include:_spf-eu.ionos.com ~all

If your domain already has an SPF record, IONOS says it is “automatically supplemented with the information of the IONOS mail servers.” If the record is missing, you can add it with Add record and the IONOS SPF (TXT) option. IONOS says propagation can take up to 48 hours.

If your DNS is somewhere else but you send through IONOS mail, add the value for your region as a TXT record at that DNS host.

DKIM is on by default

For DKIM, IONOS says: “If you use the IONOS name servers for your domains, which is the default setting, you do not need to do anything else.”

If you deleted the DKIM records by accident, or your DNS is hosted elsewhere, IONOS documents three CNAME records:

Host: s1-ionos._domainkey     Points to: s1.dkim.ionos.com
Host: s2-ionos._domainkey     Points to: s2.dkim.ionos.com
Host: s42582890._domainkey    Points to: s42582890.dkim.ionos.com

Copy these from IONOS’s DKIM help page or your own account rather than from this guide, in case they change.

If you use Microsoft 365 from IONOS

IONOS says: “These steps are not necessary if you purchased Microsoft 365 from IONOS. We do the domain configuration for you automatically in the background.” Check with the free checker that SPF and DKIM are in place, then add DMARC as below.

If your email is somewhere else

Use the SPF and DKIM values from your provider and enter them in IONOS DNS as shown above:

  • Microsoft 365 bought from Microsoft: IONOS’s help center tells you to copy the SPF value from the Microsoft 365 admin center. Microsoft’s standard value is v=spf1 include:spf.protection.outlook.com -all. DKIM is two CNAMEs from the Microsoft Defender portal.
  • Google Workspace: v=spf1 include:_spf.google.com ~all and a DKIM TXT record at google._domainkey.
  • Zoho Mail: the Zoho include from your Admin Console and a DKIM TXT record for your selector.

If your domain uses IONOS name servers but not IONOS mail, look at the SPF record carefully. Because IONOS SPF is on by default, you may find an IONOS include you do not need. Remove it only if nothing sends mail through IONOS, for example a contact form on IONOS web hosting.

DMARC: the record you add yourself

We found no DMARC switch or assistant in IONOS’s documentation. You add DMARC as a normal TXT record:

Type:       TXT
Host name:  _dmarc
Value:      v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1

IONOS’s own help page describes p=none as having “no influence on email delivery” and being “particularly suitable for testing.” Its examples send reports to postmaster@. Any mailbox works, as long as it exists.

Plain-English takeaway: With IONOS email and IONOS DNS, SPF and DKIM are usually already done. Add one TXT record with Host name _dmarc and the starter value, then check that every other service that sends as you is covered.

Common mistakes at IONOS

  • Typing the full name in Host name. IONOS adds the domain itself. _dmarc.yourdomain.com becomes _dmarc.yourdomain.com.yourdomain.com.
  • Two SPF records. IONOS supplements an existing SPF record, but a second record added by hand still breaks SPF. Keep one.
  • The wrong IONOS region. US accounts use _spf-us.ionos.com, UK and EU accounts use _spf-eu.ionos.com.
  • Deleting the IONOS DKIM CNAMEs while tidying up. Mail from IONOS stops being signed. Add them back from IONOS’s help page.
  • Forgetting other senders. A newsletter tool or online shop that sends as your domain needs its own SPF or DKIM setup before DMARC is enforced.

Check your setup

Run the free checker at /check?d=yourdomain.com. It detects IONOS from your name servers, shows your mail provider, and checks SPF, DKIM and DMARC.

When to move to quarantine and reject

p=none collects reports but does not stop anyone from sending email as your domain. When reports show your legitimate mail passing, move to p=quarantine and then to p=reject. Our post on DMARC quarantine vs reject explains how.

If you would rather we do it, see pricing: one fee per domain, and a full refund if the domain is not at p=reject within 60 days.

Sources

See where your domain stands in 10 seconds

Free. No signup. We do not store the domains you check.