DNS host
Add SPF, DKIM and DMARC records in Cloudflare
In the Cloudflare dashboard open DNS > Records and select Add record. SPF is a TXT record with Name @, DMARC a TXT record with Name _dmarc, and DKIM a TXT or CNAME record at <selector>._domainkey. Set DKIM CNAMEs to DNS only and keep CNAME flattening off for them, or the provider cannot see its key.
Cloudflare
What goes in Name
- SPF · Name
@- DKIM · Name
<selector>._domainkey- DMARC · Name
_dmarc
Check the records after you save them
Enter the domain: SPF, DKIM at common selectors, DMARC and MX are looked up live, so you see whether Cloudflare is serving the new records yet.
Lookups go from your browser to Cloudflare's public DNS resolver. If no selector is given, the checker tries the common ones.
Field values
What goes in each field in Cloudflare
Where: Dashboard > your domain > DNS > Recordssource (opens the vendor's page in a new tab)
- Type
- TXT
- Name
@- Content / Target
- v=spf1 include:<your provider> ~all
- Proxy status
- Not shown for TXT
- TTL
- Auto (300 seconds)
- Type
- TXT or CNAME, as your provider gives it
- Name
<selector>._domainkey- Content / Target
- The key (Content) or the CNAME target (Target)
- Proxy status
- DNS only for a CNAME
- TTL
- Auto (300 seconds)
- Type
- TXT
- Name
_dmarc- Content / Target
- v=DMARC1; p=none; rua=mailto:<address>
- Proxy status
- Not shown for TXT
- TTL
- Auto (300 seconds)
Step by step
Add a record in Cloudflare
TXT record: SPF, DMARC and DKIM keys
Open DNS Recordssource (opens the vendor's page in a new tab)
In the Cloudflare dashboard select the domain and go to DNS > Records
Add a TXT recordsource (opens the vendor's page in a new tab)
Select Add record and choose TXT as the Type
Fill in the fieldssource (opens the vendor's page in a new tab)
Name (@ for SPF, _dmarc for DMARC, <selector>._domainkey for a DKIM key), Content and TTL
Savesource (opens the vendor's page in a new tab)
Select Save. Cloudflare wraps Content in double quotes if you leave them out
CNAME record: DKIM from a provider that hosts the key
Open DNS Recordssource (opens the vendor's page in a new tab)
Select the domain and go to DNS > Records, then Add record
Choose CNAMEsource (opens the vendor's page in a new tab)
Select CNAME as the Type, enter the Name and put the full target your provider gives in Target
Set DNS onlysource (opens the vendor's page in a new tab)
Set the Proxy status to DNS only; Cloudflare may warn about or block proxying a CNAME used for DKIM
Savesource (opens the vendor's page in a new tab)
Pick the TTL and select Save
Cloudflare specifics
Before you save
- Email records should be DNS only; a proxied mail hostname breaks mail deliverysource (opens the vendor's page in a new tab)
- CNAME flattening can break a provider's DKIM CNAME; turn it off for that recordsource (opens the vendor's page in a new tab)
- Email > DMARC Management adds a DMARC record if you have none, or adds a Cloudflare rua address to the one you have. It works on apex domains onlysource (opens the vendor's page in a new tab)
- Cloudflare recommends its email security wizard (Email > DMARC Management > View records) over adding TXT records by handsource (opens the vendor's page in a new tab)
- TTL Auto is 300 seconds; your local DNS cache can take longer to show a changesource (opens the vendor's page in a new tab)
- Records here work once the domain uses the two Cloudflare nameservers; a nameserver change can take up to 24 hourssource (opens the vendor's page in a new tab)
Records by provider
The exact values each service asks for:
Troubleshooting
Common Cloudflare errors and fixes
DKIM CNAME does not resolve
Turn off CNAME flattening for that recordsource (opens the vendor's page in a new tab)
Mail hostname proxied
Set the record's proxy status to DNS onlysource (opens the vendor's page in a new tab)
TXT validation error
Use balanced double quotes around the content, or none at allsource (opens the vendor's page in a new tab)
SPF cannot be edited in DMARC Management
When the record points to an external domain, manage SPF at that DNS providersource (opens the vendor's page in a new tab)
For cold email
Mailboxes that come with the DNS records done
Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.
- SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
- $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
- 1,000+ mailboxesA volume price per mailbox, quoted on a call
Questions
Should DKIM records be proxied in Cloudflare?
No. Set DKIM CNAMEs to DNS only (grey cloud). Cloudflare may warn about or block proxying them, and a proxied or flattened CNAME hides the provider's key.
How do I add a DMARC record in Cloudflare?
Add a TXT record with Name _dmarc and Content such as v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com, or turn on Email > DMARC Management, which creates the record or adds Cloudflare's report address to it.
What is the Name for an SPF record in Cloudflare?
@, which stands for the domain itself. Keep one SPF record per domain and add every sending service's include to it.
How long do Cloudflare DNS changes take?
Records on Auto TTL refresh after 300 seconds, though local caches can hold the old value longer. Run the check above after saving.
Sources
Cloudflare documentation, checked . Menus and values change; if a step differs, Cloudflare's own page is the reference.
- Manage DNS records (developers.cloudflare.com)
- Create zone apex record (developers.cloudflare.com)
- DNS record types (developers.cloudflare.com)
- Time to Live (TTL) (developers.cloudflare.com)
- Proxy status (developers.cloudflare.com)
- Email issues troubleshooting (developers.cloudflare.com)
- Set up email records (developers.cloudflare.com)
- Security records (developers.cloudflare.com)
- Enable DMARC Management (developers.cloudflare.com)
- Full setup (developers.cloudflare.com)
Deliverability call
Talk to our deliverability team
Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.
- Review your domains, DNS records and current inbox placement
- Size the setup: domains, mailboxes per domain and daily volume per mailbox
- Plan warm-up and the move from your current provider or sequencer
- 1,000+ mailboxes: a volume price per mailbox for your setup
Free call
See open times in your time zone and book on this page.
Or open the booking pageLoading available times…
Open the booking page instead