Namecheap guide
SPF, DKIM and DMARC at Namecheap: exact records
How to add SPF, DKIM and DMARC records in Namecheap Advanced DNS, the values for Namecheap Private Email, and the Host field rules that trip people up.
DMARC Done team · 5 October 2026 · 4 min read
This guide covers domains managed in Namecheap’s Advanced DNS panel, whether your email is Namecheap Private Email or another provider such as Microsoft 365 or Google Workspace.
One condition first: Advanced DNS only controls your domain if the domain uses Namecheap’s own name servers (BasicDNS or PremiumDNS). If you pointed the domain to custom name servers, such as Cloudflare, add the records there instead.
How Namecheap wants records entered
The path from Namecheap’s knowledge base:
- Sign in and open Domain List.
- Click Manage next to your domain.
- Open the Advanced DNS tab.
- Click Add new record and choose TXT Record (or CNAME Record for CNAME-based DKIM).
- Fill in Host and Value, then save with the check mark.
Host field: Namecheap’s rule is that “The domain name itself should not be included in the Host field”. Use @ for the domain itself:
| Record | Type | What you type in Host | What it becomes |
|---|---|---|---|
| SPF | TXT | @ |
yourdomain.com |
| DMARC | TXT | _dmarc |
_dmarc.yourdomain.com |
| DKIM (Private Email) | TXT | privateemail._domainkey (example) |
privateemail._domainkey.yourdomain.com |
Namecheap says changes “Normally” take about 30 minutes to show up.
If you use Namecheap Private Email
SPF
Namecheap’s Private Email setup article gives this record:
Type: TXT
Host: @
Value: v=spf1 include:spf.privateemail.com ~all
For domains on BasicDNS, choosing Private Email in the domain’s Mail Settings sets up the mail records automatically. Check the Advanced DNS list before adding anything by hand, because a domain may have only one SPF record.
DKIM
Namecheap’s DKIM article for Private Email describes these steps:
- Create at least one mailbox first. Namecheap notes that “The DKIM can only be generated after a mailbox has been created.”
- In your Namecheap account, open your Private Email subscription with Manage and find the DKIM section.
- Click Generate. Namecheap says it can take about 60 minutes.
- Copy the host and value shown and make sure they appear as a TXT record in Advanced DNS.
The host name shown is typically privateemail._domainkey. Namecheap says older subscriptions use default._domainkey. Copy whatever your dashboard shows.
Namecheap’s article contains two notes that disagree on whether BasicDNS adds the DKIM record automatically. Do not rely on it: after generating the key, check Advanced DNS and add the TXT record yourself if it is not there.
DMARC
Namecheap’s Private Email article suggests a starter DMARC record with p=none and reports sent to postmaster@. Our starter record does the same with a dedicated reporting address and failure reporting options:
Type: TXT
Host: _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1
Create the dmarc-reports@ mailbox or alias first, or use postmaster@ if that already exists.
If your email is somewhere else
Use your provider’s values and enter them in Advanced DNS as shown above:
- Microsoft 365:
v=spf1 include:spf.protection.outlook.com -all, plus two DKIM CNAMEs (Hostselector1._domainkeyandselector2._domainkey) copied from the Microsoft Defender portal. - Google Workspace:
v=spf1 include:_spf.google.com ~all, plus a DKIM TXT record with Hostgoogle._domainkey. - Zoho Mail: the Zoho include from your Admin Console, plus a DKIM TXT record for your selector.
Add the same DMARC starter record.
If you moved from Private Email to another provider, remove the spf.privateemail.com include and the old Private Email DKIM record once nothing sends through Private Email any more.
Plain-English takeaway: In Namecheap Advanced DNS, type only the prefix in Host (
@,_dmarc,privateemail._domainkey), never your domain name. With Private Email, generate DKIM in the Private Email dashboard and confirm the TXT record actually appears.
Common mistakes at Namecheap
- The domain in the Host field.
_dmarc.yourdomain.comin Host becomes_dmarc.yourdomain.com.yourdomain.com. - Editing Advanced DNS on a domain that uses custom name servers. Those records are not used. Edit them where the name servers point.
- Two SPF records. Automatic Private Email setup plus a hand-added record. Merge into one.
- DKIM generated but not published. Check that the TXT record exists in Advanced DNS.
- Namecheap’s own DMARC example copied as-is. Namecheap’s general TXT article uses an example with
p=rejectandpct=100. That is an end state, not a starting point.
Check your setup
Run the free checker at /check?d=yourdomain.com. It shows whether your DNS is at Namecheap, which mail provider you use, and whether SPF, DKIM and DMARC are in place.
When to move to quarantine and reject
p=none only reports. It does not stop anyone from sending email as your domain. When reports show all your legitimate mail passing, move to p=quarantine and then to p=reject. Our post on DMARC quarantine vs reject explains the safe order.
If you would rather we do it, see pricing. If the domain is not at p=reject within 60 days, you get a full refund.
Sources
- Namecheap Knowledgebase, How do I add TXT/SPF/DKIM/DMARC records for my domain?: https://www.namecheap.com/support/knowledgebase/article.aspx/317/2237/how-do-i-add-txtspfdkimdmarc-records-for-my-domain/
- Namecheap Knowledgebase, How to set up Namecheap Private Email DNS records for domains on Namecheap Basic/Premium nameservers: https://www.namecheap.com/support/knowledgebase/article.aspx/1338/2176/how-to-set-up-namecheap-private-email-dns-records-for-domains-on-namecheap-basicpremium-nameservers/
- Namecheap Knowledgebase, How to set up a DKIM record for Private Email: https://www.namecheap.com/support/knowledgebase/article.aspx/10383/2176/how-to-set-up-a-dkim-record-for-private-email/