STRATO guide
SPF, DKIM and DMARC at STRATO: exact records
How SPF, DKIM and DMARC work at STRATO: the built-in rules for STRATO mail, how to switch them off, and how to add your own records.
DMARC Done team · 5 October 2026 · 4 min read
STRATO handles email authentication differently from most DNS hosts. Instead of asking you to type SPF and DMARC records, it offers built-in rules you choose from a list, and it signs STRATO mail with DKIM automatically. This guide explains those rules, when to keep them, and how to switch to your own records.
Where the settings live
The path from STRATO’s FAQ (the customer area is in German):
- Log in and go to Domains > Domainverwaltung.
- Click the gear icon next to your domain.
- Open the DNS tab.
- Choose TXT- und CNAME-Records verwalten (manage TXT and CNAME records).
This page holds the SPF and DMARC rules and lets you add your own TXT and CNAME records.
Prefix field: STRATO asks for a “Präfix” (prefix) and adds your domain to it automatically. So for DMARC you type _dmarc, and for a DKIM record you type something like selector1._domainkey. We could not confirm from STRATO’s documentation how the form wants a record on the domain itself to be written. After saving, check the record list or run our checker to confirm a root record sits at yourdomain.com.
If you use STRATO email
SPF
STRATO offers these SPF choices:
- Standard STRATO Mailserver: authorizes STRATO’s mail servers.
- Fail: STRATO describes this as the recommended setting when you use another mail server.
- Softfail: like Fail, but treated less strictly.
- Keine STRATO SPF-Regel: no STRATO SPF rule, so you can add your own.
If STRATO is the only service that sends mail as your domain, the Standard STRATO Mailserver rule covers it. STRATO’s FAQ on mail landing in spam tells you to create an SPF record such as this one.
If your DNS is at another host but you send through STRATO, STRATO’s FAQ gives this record:
Type: TXT
Host: @ (your domain)
Value: v=spf1 redirect=_spf.strato.com
A redirect hands the whole decision to STRATO’s own SPF record, which (when we checked on 2026-10-05) lists STRATO’s sending addresses and ends in -all.
DKIM
STRATO states that for customers who send only through its mail servers (via smtp.strato.de), it has signed all outgoing mail with DKIM “for years”. There is no switch to flip.
If your DNS is at another host, STRATO’s FAQ lists two CNAME records:
Host: strato-dkim-0002._domainkey Points to: strato-dkim-0002._domainkey.rzone.de.
Host: strato-dkim-0003._domainkey Points to: strato-dkim-0003._domainkey.rzone.de.
DMARC
STRATO says “DMARC ist bei STRATO bereits aktiviert” (DMARC is already active at STRATO) through a standard STRATO DMARC rule. STRATO’s documentation does not say what record that rule publishes, so run the checker to see what is live for your domain.
To control DMARC yourself, which you need if you want reports sent to you:
- Set the DMARC option to Keine STRATO-DMARC-Regel (no STRATO DMARC rule).
- Add your own TXT record:
Type: TXT
Präfix: _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1
STRATO’s FAQ example uses p=quarantine; pct=100. We suggest starting at p=none with a reporting address, so you can see every sender before enforcing.
STRATO notes one catch: you can only switch back to the standard STRATO DMARC rule if no TXT record with the prefix _dmarc exists.
If your email is somewhere else
If you use Microsoft 365, Google Workspace or Zoho Mail with a domain whose DNS is at STRATO:
- Set the SPF option to Keine STRATO SPF-Regel.
- Add a TXT record on the domain itself with your provider’s SPF value, for example
v=spf1 include:spf.protection.outlook.com -allfor Microsoft 365 orv=spf1 include:_spf.google.com ~allfor Google Workspace. - Add the DKIM records your provider gives you (CNAMEs for Microsoft 365, a TXT record for Google and Zoho).
- Set DMARC to Keine STRATO-DMARC-Regel and add the
_dmarcrecord above.
If you send through both STRATO and another provider, your one SPF record must list both. In standard SPF syntax that is, for example:
v=spf1 include:_spf.strato.com include:_spf.google.com ~all
Plain-English takeaway: At STRATO, SPF and DMARC are switches first and records second. Keep STRATO’s rules if STRATO is your only mail sender and you do not need reports. To get reports or use another provider, switch the rule to “Keine STRATO … Regel” and add your own record with the prefix
_dmarc.
Common mistakes at STRATO
- Adding a custom SPF record while a STRATO SPF rule is still on. That can leave two SPF records. Pick the “no STRATO rule” option first.
- Adding a
_dmarcrecord next to the standard rule. Switch the DMARC rule off first, so only your record is published. - Keeping “Standard STRATO Mailserver” after moving email to Microsoft 365 or Google. Your new provider’s servers are then not authorized.
- Typing the full domain into the prefix. STRATO adds the domain itself.
- Expecting reports from the standard rule. If you want aggregate reports in your own mailbox, you need your own DMARC record.
Check your setup
Run the free checker at /check?d=yourdomain.com. It detects STRATO from your name servers and shows the SPF, DKIM and DMARC records actually published, including whatever the STRATO rules produce.
When to move to quarantine and reject
p=none collects reports but does not stop anyone from sending email as your domain. Once the reports show all your legitimate mail passing, move to p=quarantine and then p=reject. Our post on DMARC quarantine vs reject explains the order.
If you want us to handle it, see pricing. If your domain is not at p=reject within 60 days, you get a full refund.
Sources
- STRATO FAQ, Wie kann ich bei STRATO meine DNS-Einträge verwalten?: https://www.strato.de/faq/domains/wie-kann-ich-bei-strato-meine-dns-eintraege-verwalten/
- STRATO FAQ, DMARC bei STRATO aktivieren: https://www.strato.de/faq/hosting/dmarc-bei-strato-aktivieren/
- STRATO FAQ, Wie kann ich für meine Domain die DKIM-Einstellungen ändern?: https://www.strato.de/faq/mail/wie-kann-ich-fuer-meine-domain-die-dkim-einstellungen-aendern/
- STRATO FAQ, Gesendete E-Mails landen im Spam-Ordner des Empfängers: https://www.strato.de/faq/mail/gesendete-e-mails-landen-im-spam-ordner-des-empfaengers/
- DNS lookup of
_spf.strato.com(TXT), via Google Public DNS: https://dns.google/resolve?name=_spf.strato.com&type=TXT