Skip to content

Scan your domain with 35 DNS and email security checks at zerohook.org.

For your provider

Zoho Mail

Zoho Mail's SPF help page publishes v=spf1 include:zoho.com ~all for mail sent through Zoho when the domain's MX points to Zoho.

The record

v=spf1 include:zoho.com ~all

Zoho says to add that TXT record only when Zoho handles outbound mail for the domain. If another service also sends mail for the same domain, Zoho's page says to add that service's include to the same record rather than publishing a second SPF TXT.

DKIM in Zoho

Zoho's documentation points to the admin console for DKIM keys after SPF is published. DMARC at _dmarc remains a separate TXT record under RFC 7489.

RFC 7208 returns permerror when two TXT records both start with v=spf1 on the apex. A marketing tool or Google Workspace sender must be merged into Zoho's single example record, not published as a second TXT.

One SPF record

RFC 7208 returns permerror when more than one TXT record starting with v=spf1 remains on the same name. Add other senders to that single record.

Zoho's help page describes when to publish the include and points to DKIM configuration in the admin console for outbound authentication beyond SPF.

If Google Workspace or another relay also sends for the domain, Zoho's page expects a single merged SPF TXT rather than a second record at the apex.