Skip to content
DMARC Done

Zoho Mail guide

SPF, DKIM and DMARC for Zoho Mail: exact records

The SPF, DKIM and DMARC records for a domain on Zoho Mail, how to create and enable the DKIM key in the Admin Console, and the common mistakes.

DMARC Done team · 5 October 2026 · 4 min read

This guide is for businesses that use Zoho Mail with their own domain. It lists the three records you need, with the values from Zoho’s own help pages, and the order to add them in.

Zoho creates the DKIM key in its Admin Console. You publish all three records at your DNS host, the company where your domain’s DNS records live.

The records at a glance

Record Type Host Value
SPF TXT @ v=spf1 include:zohomail.com ~all (see note on regions)
DKIM TXT zoho._domainkey (or your selector) generated in the Zoho Admin Console
DMARC TXT _dmarc v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1

SPF: one TXT record at the root

SPF (Sender Policy Framework) lists the servers allowed to send mail for your domain. Zoho’s SPF help page gives this value for Zoho Mail:

Type:  TXT
Host:  @
Value: v=spf1 include:zohomail.com ~all

Zoho’s page shows both endings. Its setup steps use ~all (soft fail). Its list of valid records shows -all (hard fail), which is the stricter choice when Zoho is the only service that sends mail as you. Either works with DMARC. If you are not sure whether other services send as your domain, start with ~all.

Two details from Zoho’s page:

  • If you send from several Zoho services, Zoho lists include:one.zoho.com as an alternative.
  • Regions: Zoho runs separate data centers (for example zoho.com, zoho.eu, zoho.in and zoho.com.au). We could not confirm the include value for every region from Zoho’s documentation. Copy the exact SPF value your own Admin Console shows rather than the example above.

If other services send as your domain, add their include: values before the all term. A domain can have only one SPF record.

DKIM: create a selector, publish, verify, enable

DKIM (DomainKeys Identified Mail) signs each message with a key tied to your domain. Zoho does not create one until you ask.

Step 1: Create the key

  1. Sign in to the Zoho Mail Admin Console.
  2. Go to Domains and select your domain.
  3. In the Email Configuration tab, select DKIM.
  4. Add a selector. A selector is just a name for the key, for example zoho.
  5. Choose the key length: 1024 or 2048 bits. Choose 2048 if your DNS host accepts long TXT values.

Zoho then shows a TXT record name and value.

Step 2: Publish it at your DNS host

Type:  TXT
Host:  zoho._domainkey
Value: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3... (copy the full value from Zoho)

If you picked a different selector, the host is yourselector._domainkey.

Step 3: Verify and enable

Back in the Admin Console, click Verify next to the selector. Zoho then asks whether to enable DKIM now or later. Enable it. Zoho notes that DNS changes can take 12 to 24 hours to be visible, so if verification fails at first, wait and try again.

DMARC: one TXT record at _dmarc

DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do with mail that fails SPF and DKIM, and where to send reports. Start in monitoring mode:

Type:  TXT
Host:  _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1

Create the dmarc-reports@ mailbox or alias in Zoho first. Reports arrive daily as XML attachments.

Zoho’s DMARC help page also recommends rolling the policy out “in a phased manner”: none first, then quarantine, then reject.

Plain-English takeaway: For Zoho Mail, publish one SPF record with the Zoho include your Admin Console shows, create a DKIM selector in the Admin Console and publish its TXT record, click Verify and enable it, then add DMARC at _dmarc with p=none.

Where to add the records

  1. Sign in at your DNS host and open the DNS settings for your domain.
  2. Add each record with the type, host and value above.
  3. Save. For DKIM, go back to the Zoho Admin Console to verify and enable.

Panels differ in how they want the host name typed. Some want _dmarc and add your domain automatically. Our guides for GoDaddy, Cloudflare, IONOS, Strato and Namecheap show the convention for each.

Common mistakes

  • Using another region’s include. An include for the wrong Zoho data center will not cover your mail servers. Copy the value from your Admin Console.
  • Publishing DKIM but not enabling it. Verification and enabling are separate steps in Zoho. Until DKIM is enabled, your mail is not signed.
  • The host name doubled. If your DNS panel adds the domain automatically, typing zoho._domainkey.yourdomain.com creates zoho._domainkey.yourdomain.com.yourdomain.com. Type only zoho._domainkey.
  • Two SPF records. If you moved to Zoho from another host, remove or merge the old SPF record.
  • Other senders forgotten. Zoho Campaigns, a CRM or your website form may send mail as your domain too. Each needs SPF or DKIM with your domain before DMARC is enforced.

Check your setup

Run the free checker at /check?d=yourdomain.com. It detects your mail provider from your MX records, checks SPF and DMARC, looks for DKIM under common selector names, and shows what is missing. If you chose an unusual selector name, the checker may not find it. Receivers will, because every signed message names its selector.

When to move to quarantine and reject

p=none collects reports but does not stop anyone from sending email as your domain. Once reports show your legitimate mail passing, move to p=quarantine, then to p=reject. Our post on DMARC quarantine vs reject explains the safe order and how long to wait at each step.

If you would rather hand it over, we take the domain to p=reject for you and refund you in full if we do not get there within 60 days. See pricing.

Sources

See where your domain stands in 10 seconds

Free. No signup. We do not store the domains you check.