Skip to content

Proton Mail SPF, DKIM and DMARC check

Enter the domain you send from with Proton Mail. We check the SPF include, the Proton Mail DKIM key, your DMARC policy and MX records, and tell you what is missing.

What Proton Mail expects

SPF

Add include:_spf.protonmail.ch to your single SPF record, for example: v=spf1 include:_spf.protonmail.ch ~all

Costs 2 of your 10 SPF lookups (checked October 2026).

Build a combined SPF record if you send from more than one service.

DKIM

Selectors we look for: protonmailprotonmail2protonmail3

Proton gives you three CNAME records (protonmail, protonmail2 and protonmail3._domainkey) under Settings > Domain names > your domain > DKIM. Publish all three.

DMARC

DMARC is set on your domain, not in Proton Mail. If you have none, start with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com and tighten it once reports look clean. Generate one.

MX

mail.protonmail.ch (10) and mailsec.protonmail.ch (20).

Values come from Proton Mail’s public setup documentation and can change. The Proton settings always shows the exact records for your account. Use those if they differ from this page.

Keep it working after setup

The usual failures come later: a second SPF record added for a new tool, a DKIM CNAME lost in a DNS move, a DMARC record deleted with an old zone. SenderBeacon checks twice a day and emails you in plain English. From $9/month, 14-day free trial, no card.

Start free trial

Questions

How long until Proton Mail DNS changes show up?

Usually minutes, sometimes up to an hour, depending on the TTL on your records and your DNS host. Re-run the check after publishing.

Why does the check say DKIM is missing when Proton Mail says it is verified?

Most often the record went on the wrong host (for example _domainkey.yourdomain.com.yourdomain.com, because the DNS host appended the domain twice), or you are checking a different domain or subdomain than the one you send from.

Other provider checks