We write the records. You verify them green.
Most deliverability incidents start with a DNS record that's missing, mistyped or over the lookup limit, so we do not hand you a list to paste. Connect Cloudflare, Name.com, GoDaddy or Dynadot and SenderSignal publishes SPF, DKIM and return-path into your zone itself, merging your existing SPF rather than replacing it, and writing only the records it owns so nothing else in the zone is touched.
Generate, verify, publish, in that order.
Guided setup walks each record from generated to green, and never asks you to guess what a “valid” record looks like.
Records built for your stack
Correct SPF, merging your existing record and counting DNS lookups against the RFC 7208 limit of 10, plus DKIM host/selector/value, DMARC, a return-path CNAME and a tracking-domain CNAME.
Checked against live DNS
SenderSignal queries live DNS and shows exactly what's missing or wrong on each record, then re-verifies until everything is green.
One click at supported providers
Connect Cloudflare, GoDaddy, Name.com or Dynadot and SenderSignal writes the records for you: preview the change, apply it, compare what's published, and stay in sync.
It already knows your provider's records.
Generic DNS generators hand you a template and wish you luck. The 51-ESP catalog behind SenderSignal knows each provider's SPF includes and DKIM selectors, so what you publish matches what your stack actually sends with.
- 51 ESPs cataloged, Klaviyo, Mailchimp, SendGrid, Amazon SES, Google Workspace, Microsoft 365, Zoho and more
- SPF merge, not replace, your existing includes survive, with lookups counted against the RFC 7208 limit of 10
- 4 publishing providers, Cloudflare, GoDaddy, Name.com and Dynadot, with a preview → apply → compare-published → sync flow
- Powers Inbox Boost, DNS must verify before a ramp starts: publish → verify → start
Free deliverability tools, no login required.
The same record logic that powers guided setup is available as free public tools: SPF, DKIM, DMARC and BIMI checkers and generators, DNS lookups and more at sendersignal.com/tools. No account needed.
Setup is step one, monitoring keeps it true.
Deliverability monitoring
SPF, DKIM, DMARC, MTA-STS, BIMI, TLS, MX and PTR, checked continuously.
Learn more FeatureInbox Boost
Add a domain. We provision the sending server and publish your DNS.
Learn more FeatureBlacklist monitoring
45+ blacklist & reputation sources, scored 0-100 with trend history.
Learn moreNot "add a TXT record". Your exact steps.
Pick your registrar and see where the records live in that control panel, plus the mistake people make on that specific one. Then see what fixed looks like.
Websites → your domain → DNS → Records → Add recordCloudflare gotcha. Set TXT records to DNS only, never Proxied. A proxied TXT record will not resolve for mail authentication.
- SPF
@No SPF record found - DKIM
sig1._domainkeySelector not published - DMARC
_dmarcv=DMARC1; p=none
Without it, receivers cannot confirm your provider is allowed to send for you. This is the cryptographic signature. Missing it is the most common cause of silent spam filing. p=none tells receivers to do nothing. Gmail and Yahoo now expect a real policy from bulk senders.
Guided DNS setup, explained.
Which records does guided DNS generate?
How does verification work?
Which DNS providers support one-click publishing?
Will the generated records match my ESP?
What if my SPF record is already near the lookup limit?
Can I try any of this without an account?
Publish records you can prove are right.
Generate SPF, DKIM and DMARC for your exact stack, verify against live DNS, and publish in one click on supported providers.