Set up SPF, DKIM and DMARC for Zoho Mail
The exact SPF, DKIM and DMARC records Zoho Mail needs, where to add them and how to check they pass and align, so Zoho Mail mail reaches the inbox.
Updated September 30, 2026
Zoho Mail needs include:zohomail.com in your SPF record (or your data center’s version, such as zohomail.eu or zohomail.in), a DKIM TXT record at a selector you choose in the Admin Console (for example zoho._domainkey), and a DMARC record at _dmarc. After adding the DKIM record you must verify the selector and enable it, or Zoho doesn’t sign your mail.
Records at a glance
| Host | Type | Value |
|---|---|---|
@ | TXT | v=spf1 include:zohomail.com ~allFor accounts in Zoho’s US data center (zoho.com). Other regions use their own domain, shown in your Admin Console. |
<selector>._domainkey | TXT | v=DKIM1; k=rsa; p=<public key from Zoho>You pick the selector name (e.g. zoho). Copy the value from Domains > Email Configuration > DKIM. |
_dmarc | TXT | v=DMARC1; p=none; rua=mailto:<your report address> |
Zoho also has you add MX records and a domain verification record when you set up the domain. Those don’t affect DMARC and aren’t covered here.
Set up SPF for Zoho Mail
Zoho’s SPF include lists the servers that send mail for your data center, so use the one that matches where your account is hosted:
- US (
zoho.com):include:zohomail.com - Other data centers use their regional domain, for example
include:zohomail.eu(Europe),include:zohomail.in(India) orinclude:zohomail.com.au(Australia). The SPF section of the Admin Console shows the exact value for your account.
A domain can have only one SPF record. If you already have one, add Zoho’s include to it instead of creating a second record:
v=spf1 include:zohomail.com include:sendgrid.net ~allIf you send through several Zoho services, Zoho suggests include:one.zoho.com instead, which covers them in one entry. Zoho recommends -all if Zoho is your only sender and ~all if others send for your domain too. With DMARC Dojo’s hosted SPF, you add Zoho as a sender in the dashboard instead, and it keeps you under the 10-lookup limit.
Set up DKIM in the Zoho Mail Admin Console
- Sign in to the Zoho Mail Admin Console, go to Domains in the left menu and choose your domain.
- On the Email Configuration tab, select DKIM and add a selector.
- Type a selector name, such as
zoho, and choose a key size: 1024 or 2048 bits. Prefer 2048 if your DNS host accepts long TXT values. - Copy the TXT record Zoho generates. At your DNS host, create a TXT record at
<selector>._domainkeywith that value. Zoho uses TXT, not CNAME, so you publish the key yourself. - Back in the Admin Console, click Verify next to the selector. When it verifies, Zoho offers to enable DKIM. Make the selector the default and enable it for the domain.
Make it pass DMARC (alignment)
- SPF aligns for normal mailbox sending: Zoho Mail uses your address as the envelope sender, so an SPF pass is for your domain.
- DKIM aligns once your selector is enabled, because Zoho signs with
d=your domain.
With both in place, Zoho mail keeps passing DMARC even when forwarding breaks SPF. Other Zoho products that send email for you, such as Zoho Campaigns or ZeptoMail, have their own domain authentication settings; Zoho Mail’s DKIM key doesn’t cover them. More in DMARC alignment explained.
Add DMARC
v=DMARC1; p=none; rua=mailto:<your report address>Publish it at _dmarc and watch the reports for a few weeks. DMARC Dojo recognizes Zoho in DMARC reports, so Zoho traffic shows up as its own source, separate from anything else sending as your domain. Once everything passes, step up to quarantine and reject (how to move from p=none to p=reject).
Check your Zoho Mail DKIM
Enter your domain to check SPF, DKIM and DMARC. We try common selectors; if you chose a custom name, look it up with the DKIM checker.
Troubleshooting
- Selector won’t verify. Your DNS host may have added the domain twice (
zoho._domainkey.example.com.example.com). Enter onlyzoho._domainkeyat hosts that append the domain, as GoDaddy does. - 2048-bit key rejected or truncated. Some hosts limit TXT strings to 255 characters. Split the value into two quoted strings, or use a 1024-bit key.
- SPF fails for some messages. The include is for the wrong data center, for example
zohomail.comon an account hosted in Europe. - Two SPF records. Adding Zoho as a separate
v=spf1record makes SPF fail for everyone. Merge them into one. - DKIM verified but mail unsigned. The selector isn’t set as default or DKIM isn’t enabled for the domain.
Frequently asked questions
Should I use zohomail.com or zoho.com in my SPF record?
Use include:zohomail.com for Zoho’s US data center, as Zoho’s current documentation shows, or your region’s zohomail domain. Copy the exact value from your Admin Console rather than a guide.
What is the Zoho Mail DKIM selector?
There isn’t a fixed one. You choose the name when you add DKIM in the Admin Console, and Zoho uses it in the DKIM-Signature header. A short name like zoho is common.
Can I have more than one DKIM selector in Zoho Mail?
Yes. You can add several and switch the default, which is how you rotate keys: publish the new selector, verify it, make it default, then remove the old record later.
Do I need separate records for a subdomain on Zoho Mail?
Yes, if the subdomain sends mail. Add it as its own domain in Zoho and publish SPF and DKIM for it. DMARC is inherited from the parent unless you publish a _dmarc record for the subdomain.