1

Open the domain's DNS zone in Cloudflare

Log into the Cloudflare dashboard, select the domain, then go to DNS → Records.

2

Add the MX record (hosted mailboxes only)

For sending-only domains, skip this step and keep your existing MX records.

Click Add record and fill in:

Type
MX
Name
@ (root domain)
Mail server
the MX value shown on the domain's page (Cloudflare shows no proxy option for MX, which is correct)
Priority
10
TTL
Auto
3

Add the SPF record

Type
TXT
Name
@
Content
the SPF value shown on the domain's page
4

Add the DKIM record

Type
TXT
Name
the DKIM host shown on the domain's page, e.g. mail._domainkey — type it exactly as shown, not the full domain
Content
the full DKIM value (it's long)
Paste the whole DKIM value as one string. Cloudflare automatically splits long TXT content into properly-chunked segments — you don't need to break it up yourself.
5

Add the DMARC record

Type
TXT
Name
_dmarc
Content
the DMARC value shown on the domain's page

Already have an SPF record? Don't add a second one

Look for an existing TXT record on @ that starts with v=spf1 (e.g. from Google Workspace or your web host). A domain may have only one. With two, receivers treat SPF as broken and your email goes to spam. Instead, edit the existing record and add mx after v=spf1:

Before
v=spf1 include:_spf.google.com ~all
After
v=spf1 mx include:_spf.google.com ~all

The example above is for hosted mailboxes. For sending only, use the a:... mechanism shown on your domain page instead of mx, and place it before the final all term. Same for DMARC: if _dmarc already has a record, keep yours.

6

Wait, then verify

Cloudflare is usually fast to propagate (often just a few minutes), but give it 5–10 minutes. Then go back to the domain's page and click Check DNS. If a record isn't found, the page tells you exactly what it sees and what to change.

Back to domains