Find and set up SPF and DKIM records in Knox
Find your domain's SPF and DKIM records in Knox, add them at your DNS provider and check that your email authentication is connected.
Get the right details ready
Have access to Knox and the provider managing your domain's DNS. Keep a copy of existing DNS records and identify any other services that send email for the domain. Your mailbox password is not needed for this task.
Security first. Never include account passwords, card details or authentication codes in a support ticket.
Make the change in Knox
Work through each step in order. Keep this guide open in another tab if that is easier.
- 1
Open DNS setup in Knox
Sign in at knox.oxnames.com, open My services and select your email-hosting service. Choose the DNS setup tab to open Connect your domain. You do not need to log in to cPanel or Webuzo to copy these records.
- If your service has multiple domains, select the domain you want to connect.
- SPF appears under Authorise your mail server. DKIM appears under Verify your outgoing email.
- Use Copy name and Copy value for each record. Keep Knox open while you update DNS.
- 2
Find the provider that manages your DNS
Add the records at the provider hosting your active DNS zone. This may be your domain registrar, IONOS, Cloudflare or another provider. Registering a domain with one company does not always mean that company manages its DNS.
- You can keep your existing nameservers and website hosting.
- Open the domain's DNS records page and keep a copy of the current records before editing.
- If you are unsure which provider is authoritative, ask support before making changes.
- 3
Add or update the SPF TXT record
SPF identifies which servers may send email for your domain. In your DNS provider, look for a TXT record whose value begins v=spf1. Use the SPF name, value and TTL shown in Knox for the selected domain.
- If no SPF record exists, add a TXT record using the displayed details. The root host is commonly shown as @; some providers expect a blank host instead.
- If an SPF record already exists, update that single record to include oXnames alongside any other services that still send for the domain. Do not add a second v=spf1 record at the same name.
- Do not overwrite a record used by Microsoft 365, a website or another legitimate sender without merging its requirements. Ask support to help if needed.
- Other TXT records, such as domain verification records, can remain. Only the SPF policy must be a single record.
- 4
Publish the DKIM public key
DKIM lets receiving servers verify a signature added to your outgoing email. Knox displays the public key for your selected domain. Create a TXT record using its exact Host / name, Value / content and TTL.
- The host is commonly default._domainkey, but always use the name shown for your domain.
- Copy the entire value, including the long p= key. Do not shorten it or reuse a sample key from another guide.
- Some DNS providers automatically append your domain to the host. Use the Full name in Knox to check the result and avoid adding the domain twice.
- Publish only the public TXT value shown in Knox. You do not need a private key, mailbox password or Knox password in DNS.
- If Knox says the key is still being prepared, refresh shortly. Contact support if it does not appear.
- 5
Repeat for any additional email domains
Each domain needs its own DNS records in the correct DNS zone, even when several domains share one email-hosting service. Switch domains in Knox and copy that domain's records.
- DKIM keys can differ between domains. Always copy the key displayed for the selected domain.
- SPF settings may look similar, but check each domain's existing senders before updating it.
- A domain must be added to your email service before Knox can show its setup records.
- 6
Check the published records in Knox
Save the DNS changes, return to DNS setup in Knox, choose the same domain and click Check DNS now or Check DNS again. The checks query public DNS, rather than just confirming that a suggested record exists on the mail server.
- Connected: the check recognises the expected configuration.
- Missing: the record is not visible in public DNS yet.
- Needs attention: compare the host and value with Knox; check for old or duplicate records.
- Unable to verify: the lookup could not complete, or the policy needs further checking. This does not automatically mean the record is wrong.
- DNS caching can delay updates. Allow time for the old records to expire and check again; use the last-checked time to see when the result was obtained.
- 7
Understand MX and DMARC alongside SPF and DKIM
SPF and DKIM help authenticate outgoing mail. They do not direct incoming messages to your mailbox. DNS setup also shows MX records for receiving email and a DMARC record for your authentication policy.
- Change MX records only when you are ready to move incoming email to oXnames, using the assigned destination shown in Knox.
- The suggested DMARC policy starts in monitoring mode, p=none. Do not replace an existing stricter policy without reviewing it.
- SPF and DKIM being connected does not guarantee inbox placement; message content, recipient engagement and sender reputation also affect delivery.
- 8
Get help if the checks do not connect
Open a support ticket through Knox and tell us the domain, your DNS provider, which check needs attention and when you saved the change. Include the public record name and value or a screenshot of that DNS entry.
- For SPF, include the current SPF record and tell us about other services that send email for the domain.
- For DKIM, check that the whole public key was saved and that the host name does not contain the domain twice.
- Do not send your mailbox password, DNS-provider password or a private signing key.
Check that it worked
SPF and DKIM show Connected in Knox after the correct records become visible in public DNS. MX and DMARC have their own separate checks.
Try this before contacting support
Check the selected domain, the record type, the host name and the complete value. Keep only one SPF record at the same name. If DNS is still cached or a lookup fails, wait and recheck; contact Knox support if the problem persists.
Open a support ticket →