DNS fix guides

The same instructions our checkers use in Fix It mode: provider-by-provider steps for the records that protect your email and certificates, including each dashboard's field names and quirks. Every guide notes the date its provider steps were verified.

SPF records

SPF (Sender Policy Framework) is a TXT record on your domain that lists the servers allowed to send email on its behalf. Receivers check it on every message that claims to come from your domain — no SPF record, and your legitimate mail becomes hard to tell apart from spoofed mail.

Or run the free SPF checker

DMARC records

DMARC tells receiving mail servers what to do when a message claiming to be from your domain fails SPF and DKIM checks — and sends you reports about who is sending as your domain. Without it, authentication results are advisory and you fly blind.

Or run the free DMARC checker

CAA records

CAA (Certification Authority Authorization) records name the certificate authorities allowed to issue TLS certificates for your domain. Without CAA, any CA in the world may issue for it; with CAA, issuance is scoped to the CAs you actually use.

Or run the free SSL checker

DKIM setup (by email sender)

The DKIM key comes from your sending service — these guides walk each console and the record it produces.

MX setup (by mailbox provider)

The exact MX records to receive mail at each provider, verified against their own docs.

Mail transport security

MTA-STS enforces TLS on mail delivered to your domain; TLS-RPT reports the failures.

Set up MTA-STS and TLS-RPT →

Parked & no-mail domains

Domains that never send email need three records so nobody can convincingly spoof them.

Protect a domain that doesn't send email →

Domain locks & renewals (by registrar)

Transfer lock, auto-renew, and WHOIS privacy — the settings that prevent hijacks and accidental expiry.

DNSSEC & DS records (by registrar)

A stale DS record after a DNS-provider change makes validating resolvers return SERVFAIL — the fix lives at the registrar.

Security headers (by platform)

Copy-paste configuration for HSTS and friends, with each platform's traps called out.

Blocklist delisting (by operator)

What to fix first, the official removal process, and what triggers relisting — per blocklist.

  • · SORBS shut down in June 2024 (decommissioned by Proofpoint) — any tool still reporting a SORBS listing is showing stale data.
  • · The CBL (cbl.abuseat.org) was folded into Spamhaus XBL in 2021 — treat a CBL mention as an XBL listing and use Spamhaus's checker.