> ## Documentation Index
> Fetch the complete documentation index at: https://help.tiretutor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting the records set up

> Find out who manages your domain, send them the exact request, and confirm the three records work.

You do not have to do this work yourself. You do have to know who does it, and what to ask them for.

<Note>
  **Educational guidance.** Email security is not part of the TireTutor product, and TireTutor does not manage your mailboxes. These pages explain how it works so you can brief the right person.
</Note>

Run the [two checks](/dealers/email-security/getting-started) first. Bring the results to this page.

## Who does which part

Two companies share the work. Neither one can finish it alone.

| The task | Who does it | Why only them |
| - | - | - |
| Turn on DKIM signing | Your email provider's administrator | The key is made inside your email account |
| Publish all three records | Whoever can edit your DNS | The records live in DNS, not in your mailbox |
| Confirm the result | You | Run Check 1 again and read the grade |

## Step 1 — Find out who can edit your DNS

Most shops do not know this. Work down the list until you get a name.

<Warning>
  Do not create a new domain or a new DNS account to get around missing access. Two DNS setups for one domain break your mail.
</Warning>

<Steps>
  <Step title="Ask whoever renews the domain name each year">
    That person holds the registrar login, or knows who does.
  </Step>

  <Step title="Ask your IT provider, if you use one">
    Ask specifically about DNS records. Do not ask about your website.
  </Step>

  <Step title="Ask the company that set up your email">
    They often kept the access after the original setup.
  </Step>

  <Step title="Contact your email provider's support">
    Google and Microsoft support can read your domain and name your DNS host.
  </Step>
</Steps>

<Check>
  You have a person or a company, and a way to contact them.
</Check>

## Step 2 — Send the request

Copy the message below. Replace `example.com` with your domain. Send it to whoever edits your DNS.

Pick the SPF line that matches your email provider.

```text Request to your DNS host theme={null}
Subject: Please add three email security records for example.com

Hello,

Please add the following DNS records for example.com.

1. SPF — a TXT record at the root of the domain.

   For Google Workspace:
   v=spf1 include:_spf.google.com ~all

   For Microsoft 365:
   v=spf1 include:spf.protection.outlook.com -all

   If a TXT record starting with v=spf1 exists, edit that one.
   Please do not add a second SPF record.

2. DKIM — a TXT record. Our email administrator generates the
   host name and the value. I can pass them to you separately.

3. DMARC — a TXT record at _dmarc:
   v=DMARC1; p=none; rua=mailto:dmarc@example.com

Please confirm when the records are live. Please also tell me who
to contact for DNS changes in future.

Thank you,
[your name and shop name]
```

<Note>
  The DMARC line needs a real mailbox at your domain to receive the reports. Create `dmarc@example.com`, or name a mailbox someone monitors.
</Note>

## Step 3 — Ask your email provider to turn on DKIM

DKIM is the one record your DNS host cannot produce. Your email provider generates it.

If you administer your own Google Workspace or Microsoft 365 account, follow your provider's article in the [reference](/dealers/email-security/reference#official-setup-articles). Otherwise send this message.

```text Request to your email provider or IT support theme={null}
Subject: Please turn on DKIM signing for example.com

Hello,

We use [Google Workspace / Microsoft 365] for email at example.com.

Please:

1. Turn on DKIM signing for example.com.
2. Send me the exact DNS records we must publish, with the host
   name and the value for each.
3. Tell me the final step that starts the signing, once the
   records are live.

We can pass the records to whoever edits our DNS.

Thank you,
[your name and shop name]
```

<Warning>
  Publishing the DKIM record is not the last step. Someone must go back into the email provider and start the signing. Many setups stop one click early and stay broken.
</Warning>

## Step 4 — Confirm the work

A DNS change usually spreads within an hour, sometimes longer. Then run [Check 1](/dealers/email-security/getting-started#check-1-read-the-grade-on-a-message-you-send) again.

<Check>
  SPF, DKIM, and DMARC all say PASS on a message you just sent.
</Check>

Trust that grade, not a confirmation email. The grade comes from a mail system that actually received your message.

## Step 5 — Tighten DMARC later

Your DMARC record starts at `p=none`. That setting reports fakes but blocks nothing. It is the safe place to start.

<Warning>
  Never jump straight to `p=reject`. Skip the reporting weeks and you block your own invoices from a tool you forgot about.
</Warning>

<Steps>
  <Step title="Read your DMARC reports for two to four weeks">
    They name every system sending mail as your shop. The reports arrive as machine-readable files, not as plain summaries. Ask your IT provider to read them for you.
  </Step>

  <Step title="Add any of your own tools that appear">
    Booking tools, review platforms, and newsletters each need an SPF entry.
  </Step>

  <Step title="Ask your DNS host to change p=none to p=quarantine">
    Fakes go to spam instead of the inbox.
  </Step>
</Steps>

## If TireTutor built your website

Your DNS records may sit with TireTutor rather than with you. The [website editor](/dealers/website/overview) does not include DNS records, so you cannot add these three yourself. It manages your site's own address, not your email.

Send the exact record to support instead: the type, the host name, and the value. Take those from the [reference](/dealers/email-security/reference). Support publishes the record in your DNS for you.

<Note>
  Support publishes a record you supply. Support does not set up email authentication for you, and does not troubleshoot mail delivery.
</Note>

## Still need help?

Contact support through the [contact form](https://tiretutor.com/contact), or call [855-400-4521](tel:+18554004521).

## Where to get help elsewhere

TireTutor support does not configure these records, and cannot troubleshoot them for you. Take the request above to your own IT provider, or open a case with your email provider. Google and Microsoft both support this for their own customers.

## Where to go next

<Columns cols={2}>
  <Card title="Records and further reading" icon="book" href="/dealers/email-security/reference">
    Exact record values, plain-word definitions, and the official articles.
  </Card>

  <Card title="Overview" icon="shield-check" href="/dealers/email-security/overview">
    What these records protect, and what goes wrong without them.
  </Card>
</Columns>

<Columns cols={2}>
  <Card title="Your website" icon="globe" href="/dealers/website/overview">
    What the website editor covers, and who on your team can use it.
  </Card>

  <Card title="Managing site settings" icon="sliders" href="/dealers/website/managing-site-settings">
    Change your logo, colours, tracking details, and form recipients.
  </Card>
</Columns>
