Official DNS Guide • End-to-End Encrypted Email

Proton Mail (Custom Domains) SPF Record Setup & Validator

Configure Proton Mail custom domain SPF record (include:_spf.protonmail.ch), 3 CNAME DKIM keys, and DMARC enforcement.

Quick Answer • Exact Proton Mail SPF Syntax

To authorize Proton Mail (Custom Domains) to send emails on behalf of your domain, add include:_spf.protonmail.ch to your domain's single DNS TXT SPF record before the terminating ~all mechanism. The standard record is v=spf1 include:_spf.protonmail.ch ~all.

Live Proton Mail DNS Validator

Test your domain's published SPF, DKIM, and DMARC records via global DoH edge nodes in real time.

Zero-Log Client Evaluation

Understanding Proton Mail (Custom Domains) Email Authentication

Proton Mail allows users to link custom domains with end-to-end encryption. Proton provides 3 CNAME DKIM records for zero-downtime rotation.

When Proton Mail (Custom Domains) delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Proton Mail (Custom Domains)'s IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.

Required DNS Records for Proton Mail

Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):

TypeHost / NameValue / TargetTTLPurpose
TXT@v=spf1 include:_spf.protonmail.ch ~all3600Proton Mail SPF.
MX@mail.protonmail.ch3600Primary Proton Mail MX.

Step-by-Step Setup Instructions

1

In Proton Mail > Settings > Domain names > Add domain.

2

Add the TXT verification record to verify domain ownership.

3

Add MX records: mail.protonmail.ch and mailsec.protonmail.ch.

4

Add SPF TXT record: "v=spf1 include:_spf.protonmail.ch ~all".

5

Add the 3 DKIM CNAME records (protonmail, protonmail2, protonmail3).

Common Proton Mail SPF Configuration Mistakes

× Proton Verification Token Missing

Cause: Skipping proton-verification TXT.

Fix: Add verification TXT.

Frequently Asked Questions

What is the SPF include for Proton Mail?

Use "include:_spf.protonmail.ch".

Why does Proton Mail require 3 DKIM CNAME records?

Proton Mail uses triple CNAME DKIM records (protonmail._domainkey, protonmail2._domainkey, protonmail3._domainkey) to support zero-downtime DKIM key rotation. At any point, Proton may rotate active signing to a different selector, ensuring continuous DKIM coverage without DNS update delays.

What is the Proton Mail domain verification TXT record?

Before setting up SPF, DKIM, or MX records, Proton requires a domain ownership verification TXT record (protonmail-verification=[token]). This confirms you control the domain before Proton activates mail routing.

Are emails sent through Proton Mail custom domains end-to-end encrypted?

Proton-to-Proton email is end-to-end encrypted using PGP. However, emails from your Proton custom domain to external recipients (Gmail, Outlook, etc.) use standard SMTP with TLS in transit, not E2EE. SPF/DKIM/DMARC authentication still applies to external delivery.

What MX records does Proton Mail custom domain require?

Proton requires two MX records: mail.protonmail.ch (Priority 10) and mailsec.protonmail.ch (Priority 20). Both must be set before Proton's custom domain setup will show as complete.

Does Proton Mail support DMARC reporting (rua/ruf)?

Proton Mail supports standard DMARC reporting when used with a custom domain. You can publish a DMARC record with rua= pointing to any email address you control. Proton also offers its own DMARC monitoring via SimpleLogin integration.