Warning: session_start(): open(/var/cpanel/php/sessions/ea-php83/sess_606809d4fa313628096486c90d6e7fa8, O_RDWR) failed: Disk quota exceeded (122) in /home/ofgnmrmy/rankests.com/index.php on line 2

Warning: session_start(): Failed to read session data: files (path: /var/cpanel/php/sessions/ea-php83) in /home/ofgnmrmy/rankests.com/index.php on line 2
SPF/DKIM/DMARC Generator | Rankests

SPF/DKIM/DMARC Generator

Search Engine Optimization

SPF/DKIM/DMARC Generator

Free · No sign-up · No API key needed

Build the DNS records that stop spoofing & the spam folder

Generate SPF, DKIM and DMARC records for your domain, then verify they're actually live — all four steps in one tool.

Which services send mail for this domain?

Allow this domain's own MX mail serversadds "mx"
Allow this domain's own web/mail server (A record)adds "a"
Each line becomes its own include: mechanism.
CIDR ranges like 203.0.113.0/24 are fine too.

Your SPF Record

TXT record for @ (root domain)
A domain can only have one SPF record. If one already exists, merge these mechanisms into it instead of publishing a second v=spf1 TXT record — two SPF records will cause mail servers to fail SPF checks (permerror).
The private key is generated locally by your browser's own encryption engine (Web Crypto API) and is never sent to this or any server.
Generating your RSA key pair…
Save your private key now. It only exists in this browser tab — refreshing or leaving this page loses it forever, and it cannot be recovered or re-downloaded from here later. Store it on your mail server (e.g. in OpenDKIM's key directory) and keep it secret.

Private Key (keep on your mail server only)

selector.private.pem

DNS TXT Record to Publish

selector._domainkey

OpenDKIM Config Snippet (if you self-host mail)

KeyTable / SigningTable / TrustedHosts
Paste whatever your mail server, hosting panel, or "openssl rsa -pubout" command gave you — headers and line breaks are stripped automatically.
selector._domainkey
Don't have OpenSSL/OpenDKIM and would rather not self-host signing? Google Workspace, Microsoft 365 and most transactional-email providers (SendGrid, Mailgun, Amazon SES, etc.) generate and rotate their own DKIM keys for you — check their admin panel for a ready-made CNAME or TXT record instead.
Comma-separate multiple addresses. Daily summary reports land here.

Advanced alignment options

Your DMARC Record

_dmarc
Recommended rollout: publish with p=none first and watch the aggregate reports for a couple of weeks, move to p=quarantine once legitimate mail is passing, then p=reject once you're confident nothing legitimate is being blocked.
📡
Looking up DNS records…

Results


About SPF/DKIM/DMARC Generator

SPF/DKIM/DMARC Generator builds all three email-authentication DNS records your domain needs, in one place. The SPF Record Generator lets you pick your mail providers (Google Workspace, Microsoft 365, Zoho, Amazon SES, SendGrid, Mailgun, Mailchimp/Mandrill, HubSpot) or add your own includes and IP addresses, and assembles a correctly formatted v=spf1 record while warning you about the 10-lookup limit. The DKIM Key & Record Generator creates a real RSA key pair using your browser's own encryption engine - the private key is generated locally and never uploaded anywhere - and formats the matching DNS TXT record, or you can paste in a public key you already have. The DMARC Record Generator walks you through policy, alignment and reporting options to produce a valid v=DMARC1 record. Once you've published your records, the built-in Verify tab runs live DNS lookups to confirm SPF, DMARC and DKIM are actually visible on the internet. No AI and no third-party API key is required for any of this - record building runs entirely in your browser and verification uses plain DNS lookups.



Update cookies preferences