Skip to content

Scan your domain with 35 DNS and email security checks at zerohook.org.

What is / Full version

TXT records

TXT RRs hold the SPF, DKIM, and DMARC strings receivers query.

Short answerAll topics in What is

String chunks

DNS TXT RDATA may contain multiple character strings. SPF and DMARC specifications concatenate them in order without inserting spaces.

Publishing unrelated TXT strings on the same owner name as SPF is allowed only if they are not second SPF version records. Two v=spf1 records still trigger permerror.

Owner names

SPF for the organizational domain is usually published at the apex. DKIM uses selector._domainkey. DMARC uses _dmarc. BIMI and MTA-STS use their own delegated names under the same zone.

Long TXT strings may be split into multiple 255-octet chunks in the wire format. Parsers reassemble them before interpreting SPF or DMARC tags.

RFC 7489 requires the DMARC policy record at _dmarc to start with v=DMARC1. A typo in the owner name or version tag produces no policy match, which receivers treat as absent DMARC.

Concatenation

When a TXT RRset contains multiple character-string chunks, SPF and DMARC parsers concatenate them in order without inserting spaces.

Publishing two separate TXT records that both begin with v=spf1 on the apex domain is a permerror under RFC 7208, even if other unrelated TXT records also exist on that name.

DKIM TXT lives at a selector under _domainkey and does not compete with apex SPF for the one-SPF rule, because the owner names differ.