> ## Documentation Index
> Fetch the complete documentation index at: https://help.tiretutor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Records and further reading

> Look up the exact record values for Google Workspace and Microsoft 365, plus the official setup articles.

Hand this page to whoever edits your DNS. Every value here comes from Google's or Microsoft's own instructions.

<Note>
  **Educational guidance.** Email security is not part of the TireTutor product, and TireTutor does not manage your mailboxes. These pages explain how it works so you can brief the right person.
</Note>

## The three records at a glance

| Record | Where it goes | What it holds |
| - | - | - |
| SPF | The root of your domain | One line naming your approved mail services |
| DKIM | A host name your provider gives you | A long key your provider generates |
| DMARC | `_dmarc` | Your policy, and where to send reports |

## Google Workspace values

Copy each value exactly. Replace `example.com` with your own domain.

```text SPF — TXT record at your domain root (@) theme={null}
v=spf1 include:_spf.google.com ~all
```

```text DMARC — TXT record at _dmarc theme={null}
v=DMARC1; p=none; rua=mailto:dmarc@example.com
```

**DKIM** is a TXT record at `google._domainkey`. Your administrator generates the value in the Google Workspace admin console. Choose a 2048-bit key. After the record goes live, return to the console. Start the authentication there.

## Microsoft 365 values

```text SPF — TXT record at your domain root (@) theme={null}
v=spf1 include:spf.protection.outlook.com -all
```

```text DMARC — TXT record at _dmarc theme={null}
v=DMARC1; p=none; rua=mailto:dmarc@example.com
```

**DKIM** uses two CNAME records, at `selector1._domainkey` and `selector2._domainkey`. Both values differ for every customer. Your administrator reads them from the Microsoft Defender portal.

<Note>
  Google recommends `~all` at the end of the SPF line. Microsoft recommends `-all`. Use the one your provider publishes, not a mixture.
</Note>

## Domains you own but never send from

A shop often owns spare domains: an old business name, a `.net` twin, a common
misspelling of the real one. Nobody sends mail from them, so nobody protects
them, and a forger can send as any of them.

Publish two records on each spare domain. Together they tell every receiver to
refuse all mail from it. A domain that sends nothing has no mail to break, so it
can start at `p=reject` rather than working up to it.

```text SPF — TXT record at the domain root (@) theme={null}
v=spf1 -all
```

```text DMARC — TXT record at _dmarc theme={null}
v=DMARC1; p=reject;
```

## Words you may hear

| Word | What it means for your shop |
| - | - |
| Domain | The part of your email address after the `@` |
| DNS | The address book that tells the internet where your mail and website live |
| DNS record | One entry in that address book |
| TXT record | A record that holds plain text, used by SPF and DMARC |
| CNAME record | A record that points one name at another name |
| Registrar | The company you buy and renew the domain name from |
| DNS host | The company whose system holds your DNS records |
| Selector | The host name that points at your DKIM key |
| Spoofing | Sending email that pretends to come from your address |
| Quarantine | Delivery to the spam folder instead of the inbox |

## Common mistakes

| Mistake | What happens | The fix |
| - | - | - |
| Two SPF records on one domain | Both stop working | Merge them into one record |
| More than ten `include:` entries | SPF fails with an error | Remove services you do not use |
| A space or a period inside the SPF line | The whole record fails | Copy the value exactly |
| DKIM record published, signing never started | Mail stays unsigned | Return to the provider and start it |
| Jumping straight to `p=reject` | Your own mail gets rejected | Start at `p=none` and read the reports |
| Trusting a green checkmark | A tool reports DMARC as present when it does nothing | Send a real message and read the grade |

## Free checking tools

| Tool | What it tells you |
| - | - |
| Gmail's **Show original** | Whether a real message passes all three checks |
| [Google Admin Toolbox Check MX](https://toolbox.googleapps.com/apps/checkmx/) | Your mail servers, your SPF record, and your DKIM record |
| [MXToolbox SuperTool](https://mxtoolbox.com/SuperTool.aspx) | The same records, plus DMARC, for any domain |

## Official setup articles

Give these to your IT provider. They hold the current steps for each provider.

**Google Workspace**

* [Set up SPF](https://knowledge.workspace.google.com/admin/security/set-up-spf)
* [Set up DKIM](https://knowledge.workspace.google.com/admin/security/set-up-dkim)
* [Set up DMARC](https://knowledge.workspace.google.com/admin/security/set-up-dmarc)
* [Troubleshoot DKIM issues](https://knowledge.workspace.google.com/admin/security/troubleshoot-dkim-issues) — covers reading a message's headers

**Microsoft 365**

* [Set up SPF](https://learn.microsoft.com/en-us/defender-office-365/email-authentication-spf-configure)
* [Set up DKIM](https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure)
* [Set up DMARC](https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure)

## Protecting the mailboxes too

These records stop people impersonating your domain. They do nothing about someone getting into a mailbox.

* Turn on two-step verification for every mailbox.
* Check your mail rules for forwarding you did not set up.
* Review which apps have access to your mail.
* Give each person their own login instead of one shared account.
* Close accounts the day someone leaves.
* Keep the domain renewal on a card that does not expire.

## Where to go next

<Columns cols={2}>
  <Card title="Checking your setup" icon="magnifying-glass" href="/dealers/email-security/getting-started">
    Two free checks that show which records you are missing.
  </Card>

  <Card title="Getting the records set up" icon="user-gear" href="/dealers/email-security/managing-email-security">
    Find who manages your domain, and what to ask them for.
  </Card>
</Columns>
