Mail setup

SPF, DKIM and DMARC with IONOS Mail.

The records IONOS Mail needs, where to find them, and the failure specific to this provider.

SPF

Add include:_spf.perfora.net and _spf.kundenserver.de to your existing SPF record. Do not create a second record: two SPF records mean neither works, and that is the most common mistake in this whole area.

A complete record with IONOS Mail alone looks like v=spf1 include:_spf.perfora.net and _spf.kundenserver.de ~all. If you use other sending tools, their includes go in the same record.

DKIM

Found in IONOS control panel, under Email, then the domain.

IONOS requires two includes rather than one, which uses two of your ten SPF lookups before you have added anything else.

IONOS Mail publishes keys under the selector provided per mailbox package, which is what an external check looks for.

DMARC

DMARC is the same regardless of provider, because it is your instruction rather than theirs. Start at v=DMARC1; p=none; rua=mailto:you@yourdomain.com, read the reports for a few weeks, authorise everything legitimate, and only then tighten. The DMARC guide covers the order in detail, and the order is what stops you blocking your own invoices.

Worth knowing with IONOS Mail

IONOS bundles mail with hosting, so cancelling a hosting package can stop mail without any DNS change being made. Check what a cancellation covers before ending a contract.

Check it afterwards

Publishing the records is not the same as them working. Verify from outside: whether SPF passes, whether a DKIM signature is actually present, and how many lookups your SPF now performs. The free mail check answers all three in plain language.

Related

Check yours

Check whether your mail is actually passing.

Plain answers rather than policy strings. Free, no account.

Using a different mail provider?

The records differ per provider, and so do the mistakes.

SendGrid · Namecheap Private Email · Amazon SES · Microsoft 365 · Salesforce and Marketing Cloud · Klaviyo

All 20 in this set