Set up SPF, DKIM and DMARC for Postmark

The exact SPF, DKIM and DMARC records Postmark needs, where to add them and how to check they pass and align, so Postmark mail reaches the inbox.

Updated September 30, 2026

Postmark needs two records: a DKIM TXT record at a selector Postmark generates (a timestamp followed by pm, such as 20131031155228pm._domainkey) and a custom Return-Path CNAME, usually pm-bounces, pointing to pm.mtasv.net. You don’t need to add Postmark to your SPF record. Add a DMARC record at _dmarc and Postmark mail passes DMARC on both DKIM and SPF.

Records at a glance

HostTypeValue
<timestamp>pm._domainkeyTXT
k=rsa; p=<public key from Postmark>
Copy the hostname and value from Sender Signatures > DNS Settings. The number is unique to your domain.
pm-bouncesCNAME
pm.mtasv.net
The custom Return-Path. You can pick another name, but it must be a subdomain of the domain you send from.
_dmarcTXT
v=DMARC1; p=none; rua=mailto:<your report address>

Set up SPF for Postmark

You don’t need to change your SPF record. Receivers check SPF against the Return-Path (envelope sender) domain, not the From address, and every Postmark message uses a Return-Path on a domain whose SPF already lists Postmark’s servers. So SPF passes by default.

An old include:spf.mtasv.net in your root SPF record does nothing for Postmark mail, because your root domain isn’t the Return-Path. Postmark says you can safely remove it, which also frees one of your ten SPF lookups. If you do keep other senders in the record, the record stays as it was:

Root SPF record: Postmark isn’t in it, and doesn’t need to be
v=spf1 include:_spf.google.com -all

What makes SPF count for DMARC is the custom Return-Path in the next sections, not an include. If you use DMARC Dojo’s hosted SPF, there’s nothing to add for Postmark; senders that do need an include are added in the dashboard instead of in DNS.

Set up DKIM in Postmark

  1. In Postmark, open Sender Signatures, find your domain (add it first if it isn’t there) and click DNS Settings.
  2. In the DKIM section, copy the Hostname and Value. The hostname looks like 20131031155228pm._domainkey: a timestamp from when the key was created, then pm.
  3. At your DNS host, create a TXT record with that hostname and value. Postmark’s DKIM is a TXT record with the public key, not a CNAME.
  4. Back in Postmark, click Verify. Postmark also checks on its own and marks DKIM verified within 48 hours. Once DKIM is verified, the whole domain is verified for sending, so any address on it can send.

Postmark signs with 1024-bit keys. When a key is rotated, Postmark shows a new pending hostname with a newer timestamp; add it as a second TXT record and leave the old one until Postmark switches over. To confirm signing, send a message to an outside mailbox and look for DKIM-Signature with d= your domain and dkim=pass in Authentication-Results.

Make it pass DMARC (alignment)

  • DKIM aligns once the DKIM record is verified, because Postmark signs with d= your domain. That alone is enough to pass DMARC.
  • SPF doesn’t align by default. Without a custom Return-Path, the envelope sender is on a Postmark domain (pm.mtasv.net). SPF passes, but for Postmark’s domain, so it doesn’t count for yours.

The fix is the custom Return-Path. In the same DNS Settings page, go to the Return-Path section, keep the default pm-bounces or enter your own subdomain, and add the CNAME to pm.mtasv.net. With pm-bounces.example.com as the Return-Path and example.com in the From address, the domains align under DMARC’s default relaxed mode. Having both DKIM and SPF aligned is worth it: if a forwarder breaks one, the other still carries DMARC. More in DMARC alignment explained.

Add DMARC

Starter DMARC record
v=DMARC1; p=none; rua=mailto:<your report address>

Start at p=none and read the aggregate reports. DMARC Dojo recognizes Postmark in DMARC reports, so its traffic appears as its own source with DKIM and SPF alignment results. Once Postmark and your other senders pass, move to quarantine and then reject (how to get there safely).

Check your Postmark records

Enter your domain to see your DKIM, SPF and DMARC results, a score out of 100 and the fixes to make.

Troubleshooting

  • DKIM won’t verify. The usual cause is a doubled name such as 20131031155228pm._domainkey.example.com.example.com. At hosts that append your domain, enter only the part before it. Look the record up with dig TXT to see where it really landed.
  • Return-Path won’t verify on Cloudflare. Postmark recommends turning off the proxy (orange cloud) on the pm-bounces CNAME so the record is DNS only.
  • SPF fails alignment in reports. The custom Return-Path isn’t set up or verified, so mail still uses Postmark’s default Return-Path. Adding Postmark to your root SPF record won’t fix this.
  • The key value was mangled. Some DNS editors add quotes or line breaks. Copy the value again from Postmark, and check the result against the dashboard.

Frequently asked questions

Do I need include:spf.mtasv.net in my SPF record?

No. That include only covers your root domain, which Postmark doesn’t use as the Return-Path. SPF passes on Postmark’s own Return-Path by default, and a custom Return-Path CNAME is what makes it align with your domain.

Can I use a different name than pm-bounces?

Yes. Any subdomain of your sending domain works, as long as it’s a CNAME to pm.mtasv.net and isn’t already used for something else, such as a website or MX record.

Why is my Postmark DKIM selector a long number?

Postmark names each key after the time it was created, followed by pm. That keeps every key unique, so a new key can be published alongside the old one during rotation.

Can I send from a subdomain with Postmark?

Yes. Add the subdomain as its own domain in Postmark and publish its DKIM and Return-Path records under that subdomain. It inherits the parent’s DMARC policy unless it has its own _dmarc record.

Do transactional and broadcast streams need separate records?

No. DKIM and the Return-Path are set per domain in Postmark, so the same records cover every message stream sending from that domain.