SiteGround Email Authentication Guide

How to set up SPF, DKIM, DMARC, and List-Unsubscribe for SiteGround. Provider-specific DNS records, step-by-step instructions, and the mistakes to avoid.

Check your domain while following this guide

Run a free SPF, DKIM, and DMARC check to see what is passing and what still needs fixing.

No signup required. Works on any domain.

Before you start

  • You need access to the DNS settings for your domain. This is usually at your domain registrar or DNS provider (Cloudflare, Namecheap, GoDaddy, etc.).
  • You need to know which email service sends your mail (Google Workspace, Microsoft 365, etc.) so you can look up the correct SPF and DKIM values for that service.
  • DNS changes take time to propagate. After saving a record, wait at least 15-30 minutes before testing.

SPF Setup for SiteGround

SPF (Sender Policy Framework) is a DNS TXT record that lists which mail servers are allowed to send email on behalf of your domain. Receiving servers check it to decide whether to accept or flag your mail.

SiteGround manages DNS through Site Tools and also provides cPanel-based email hosting. The SPF record you need depends on which service sends your mail. The value above covers SiteGround's own email hosting. If you send through Google Workspace or another provider, use their include instead.

SPF record for SiteGround

Type: TXT    Host/Name: @    Value: v=spf1 include:spf.web-hosting.com ~all

Steps

  1. Open your DNS provider and look for an existing TXT record at host @ that starts with v=spf1.
  2. If one exists, edit it and add the new include. Never create a second SPF record. If none exists, create a new TXT record at @ with the value above.
  3. If you send through both SiteGround email and another service, merge both includes into one record: v=spf1 include:spf.web-hosting.com include:_spf.google.com ~all
  4. Use ~all (softfail) while testing. Move to -all (hardfail) only after confirming all legitimate senders are covered.
  5. Save and wait for DNS propagation.
Watch out: Go to Site Tools → Domain → DNS Zone Editor to add or edit DNS records. Use @ as the host name for root-domain records. SiteGround prepends your domain automatically, so do not enter the full domain in the Name field.

DKIM Setup for SiteGround

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing email. Receiving servers verify the signature against a public key you publish as a DNS TXT record. A valid DKIM signature proves the message was not altered in transit and that it came from an authorized sender.

Selector for SiteGround: default for SiteGround's built-in email hosting, or the selector your email provider specifies if you use an external service

Steps

  1. If using SiteGround email hosting: go to Site Tools → Email → Email Deliverability. SiteGround generates and publishes DKIM keys for your domain automatically.
  2. Click "Repair" next to DKIM if it shows as inactive. SiteGround writes the DKIM TXT record directly to your DNS zone — no manual DNS step is needed.
  3. If using an external email provider (Google Workspace, Microsoft 365, etc.): get the DKIM TXT record from that provider's admin panel, then go to Site Tools → Domain → DNS Zone Editor.
  4. Click "Add Record", select TXT, and paste the selector subdomain and key value your provider specifies. For example, host google._domainkey for Google Workspace.
Watch out: For SiteGround email, DKIM is handled through Site Tools Email Deliverability, which auto-publishes the record to DNS. If you also manually add a DKIM TXT record in the DNS Zone Editor for the same selector, it creates a conflict. Use one method only.

Verify DKIM

  • Send a test email to a Gmail address and open it. Click the three-dot menu → "Show original". Look for dkim=pass in the authentication results.
  • From the command line:
    dig TXT default._domainkey.yourdomain.com +short
  • Or use the InboxGreen DKIM checker.

DMARC Setup for SiteGround

DMARC (Domain-based Message Authentication, Reporting, and Conformance) ties SPF and DKIM together. It tells receiving servers what to do with mail that fails both checks, and sends you reports about who is sending email on behalf of your domain. DMARC also requires alignment: the domain in your visible From header must match the domain authenticated by SPF or DKIM.

Add DMARC through Site Tools → Domain → DNS Zone Editor. Create a TXT record with host _dmarc and the standard DMARC value. SiteGround prepends your domain to all records automatically, so use just _dmarc as the host, not the full _dmarc.yourdomain.com.

The three-stage approach

StageDNS valueWhen to use it
Monitor v=DMARC1; p=none; rua=mailto:[email protected]; fo=1 Start here. Collects reports without blocking any mail.
Quarantine v=DMARC1; p=quarantine; pct=25; rua=mailto:[email protected]; fo=1 After 2-4 weeks at p=none with clean reports. Sends some failing mail to spam.
Reject v=DMARC1; p=reject; pct=100; rua=mailto:[email protected]; fo=1 Full protection once SPF and DKIM alignment is verified.

Publish the DMARC record

  1. Create a TXT record at host _dmarc (not @) with the p=none value above.
  2. Replace [email protected] with a real inbox that can receive XML report emails.
  3. Wait for DNS propagation, then verify with dig TXT _dmarc.yourdomain.com +short.
  4. After 2-4 weeks, review the reports and tighten the policy when alignment looks healthy.
Why DMARC fails even when SPF and DKIM pass: DMARC cares about alignment. The domain in the visible From header must match the domain SPF or DKIM authenticated. Forwarded mail and mailing list services often break alignment.

List-Unsubscribe for SiteGround

The List-Unsubscribe header gives inbox providers like Gmail and Outlook a machine-readable way to offer a one-click unsubscribe button. When it is present and valid, Gmail shows an "Unsubscribe" link next to the sender name without the recipient needing to scroll to the bottom of the email. This reduces spam complaints and protects your sender reputation.

How to enable it

  1. In your sending platform or email template, enable the List-Unsubscribe header option. Most platforms (SendGrid, Mailgun, Brevo, Shopify Email) have a toggle or a macro for this.
  2. Use a one-click HTTPS unsubscribe URL as the primary method. Include a mailto: address as fallback.
  3. Add the List-Unsubscribe-Post header to declare one-click support (required by Gmail's February 2024 guidelines for senders above 5,000 messages/day).

Example headers

List-Unsubscribe: <https://yourdomain.com/unsubscribe/TOKEN>, <mailto:[email protected]?subject=unsubscribe>
List-Unsubscribe-Post: List-Unsubscribe=One-Click

Common mistakes

  • Using a broken or expired token in the unsubscribe URL. Inbox providers test the link periodically.
  • Only providing a mailto: link without a one-click HTTPS URL. Gmail and Outlook prefer the HTTPS method.
  • Not honoring the unsubscribe request immediately. Gmail requires that one-click unsubscribes are processed within two business days.

To verify, send a test email to a Gmail address and look at "Show original". You should see the List-Unsubscribe header in the raw message headers.

Verify All Four Records

After publishing all records, run these checks:

RecordCommandWhat to look for
SPF dig TXT yourdomain.com +short One TXT record starting with v=spf1
DKIM dig TXT default._domainkey.yourdomain.com +short A TXT record starting with v=DKIM1
DMARC dig TXT _dmarc.yourdomain.com +short A TXT record starting with v=DMARC1
All three InboxGreen Free Check Green pass on SPF, DKIM, and DMARC

Common Mistakes with SiteGround

  • Using the wrong SPF include. SiteGround email hosting uses <code>spf.web-hosting.com</code>. If you actually send through Google Workspace or another provider, use their include instead.
  • Looking for DKIM in the DNS Zone Editor when using SiteGround email hosting. SiteGround manages DKIM automatically through Site Tools → Email → Email Deliverability — no manual DNS record is needed.
  • Entering the full hostname in the DNS Zone Editor. SiteGround appends your domain automatically, so use <code>_dmarc</code> not <code>_dmarc.yourdomain.com</code>.

Free Deliverability Scan

Check SPF, DKIM, DMARC and List-Unsubscribe for your domain in seconds.

Related Tools

SPF Lookup

See your live SPF record, count DNS lookups, and spot duplicate records or syntax problems.

DKIM Checker

Look up any DKIM selector on any domain. Confirms the key exists and shows its length.

DMARC Lookup

Fetch your live DMARC record, validate syntax, and check policy and reporting configuration.

Email Header Analyzer

Paste raw email headers to see SPF, DKIM, and DMARC results in one view.

SPF Generator

Build a valid SPF record from scratch for any combination of sending services.

DMARC Generator

Build a DMARC record with the right policy, pct, and rua settings for your stage.

TXT Lookup

See all TXT records on your domain to catch duplicate SPF records or missing entries.

DKIM Generator

Generate a 2048-bit DKIM key pair if your ESP requires you to manage your own keys.

Related Reading

SPF Errors and Fixes

PermError, duplicate records, softfail vs hardfail, and alignment failures.

DKIM Errors and Fixes

Selector not found, body hash mismatch, key length, and DMARC alignment.

DMARC Errors and Fixes

Alignment failures, missing reports, and how to safely move from p=none to p=reject.

Common Questions

What DNS records do I need for SiteGround?

SiteGround provides DNS management through Site Tools and includes cPanel-based email hosting. If you use SiteGround's built-in email, publish v=spf1 include:spf.web-hosting.com ~all as a TXT record at the root domain in the DNS Zone Editor. DKIM for SiteGround email is managed through Site Tools → Email → Email Deliverability, which auto-generates and publishes the DKIM key — no manual DNS record needed. If you use Google Workspace or another email provider on SiteGround DNS, use that provider's SPF and DKIM records instead. In all cases, add DMARC as a TXT record at host _dmarc in Site Tools → Domain → DNS Zone Editor.

How long does it take for SPF, DKIM, and DMARC to start working?

Most DNS changes propagate within 15 to 60 minutes, but the full TTL can extend to 48 hours on some registrars. Always wait at least 30 minutes before testing. If a change isn't showing up after an hour, use the SPF Lookup or DKIM Checker to query live DNS rather than relying on cached results.

Can I have two SPF records?

No. RFC 7208 requires exactly one SPF TXT record at your domain root. Two records cause a PermError regardless of their content. If you send through multiple services, merge all the includes into a single record: v=spf1 include:service1.com include:service2.com ~all. Use the TXT Lookup to confirm you only have one.

What DMARC policy should I start with?

Start with p=none to collect reports without affecting delivery. After 2 to 4 weeks of reports showing all legitimate sources passing alignment, move to p=quarantine at a low percentage (pct=10), then increase gradually. Move to p=reject only when you are confident every legitimate sending source aligns correctly.

Why does DMARC fail even though SPF and DKIM both pass?

DMARC requires alignment, not just a pass. SPF alignment means the envelope sender domain (the Return-Path address) must match your From: domain. DKIM alignment means the d= tag must match your From: domain. If your ESP signs with its own domain or uses its own envelope sender, both protocols pass independently but DMARC alignment fails. Fix this by enabling custom domain authentication at your ESP.