Official DNS Guide • Business Email Suite

Zoho Mail & Zoho Workplace SPF Record Setup & Validator

Configure Zoho Mail SPF record (include:zoho.com) and generate Zoho DKIM selector keys (zmail._domainkey).

Quick Answer • Exact Zoho Mail SPF Syntax

To authorize Zoho Mail & Zoho Workplace to send emails on behalf of your domain, add include:zoho.com to your domain's single DNS TXT SPF record before the terminating ~all mechanism. The standard record is v=spf1 include:zoho.com ~all.

Live Zoho Mail DNS Validator

Test your domain's published SPF, DKIM, and DMARC records via global DoH edge nodes in real time.

Zero-Log Client Evaluation

Understanding Zoho Mail & Zoho Workplace Email Authentication

Zoho Mail uses "include:zoho.com" and a 2048-bit DKIM selector key configured in Zoho Mail Admin Console.

When Zoho Mail & Zoho Workplace delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Zoho Mail & Zoho Workplace's IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.

Required DNS Records for Zoho Mail

Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):

TypeHost / NameValue / TargetTTLPurpose
TXT@v=spf1 include:zoho.com ~all3600Zoho Mail SPF.

Step-by-Step Setup Instructions

1

Log in to Zoho Mail Admin Console > Domains > SPF.

2

Add "include:zoho.com" to your root SPF record.

3

Add a DKIM selector (e.g. "zmail") and copy the TXT key.

4

Publish TXT at zmail._domainkey and verify.

Common Zoho Mail SPF Configuration Mistakes

× Selector Not Activated

Cause: DNS published but not verified in Zoho Admin.

Fix: Click verify icon in Zoho.

Frequently Asked Questions

What is the SPF include for Zoho in Europe?

For EU accounts, use "include:zoho.eu".

What are the different Zoho SPF includes for different regions?

Zoho uses region-specific SPF records: include:zoho.com for US accounts, include:zoho.eu for European accounts, and include:zoho.in for Indian accounts. Using the wrong regional include will cause SPF failures for emails routed through Zoho's regional servers.

What DKIM selectors does Zoho Mail provide?

Zoho generates TXT-based DKIM keys (not CNAME). The default selector names are "zmail" or "zoho", published at zmail._domainkey.yourdomain.com. These are 2048-bit RSA TXT records configured directly in Zoho Mail Admin Console under Email Configuration > DKIM.

How do I set up DMARC for Zoho Mail?

Publish a DMARC TXT record at _dmarc.yourdomain.com: "v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com". This instructs receiving servers to reject all unauthenticated messages from your domain and send aggregate XML reports to your monitoring address.

Does Zoho Mail support custom DKIM selectors?

Yes. In Zoho Mail Admin Console, you can add multiple DKIM selectors to support phased key rotation or migration. Zoho allows up to 5 active selectors per domain.

Why might Zoho DKIM show as Not Activated after publishing the DNS record?

Zoho must explicitly activate DKIM after you publish the TXT record. Go to Zoho Mail Admin Console > Domain > Email Configuration > DKIM Configuration and click the verification/activate icon. DNS propagation can take up to 48 hours, so wait before re-verifying.