Email DNS records: MX, SPF, DKIM and DMARC
Email fails quietly. A mailbox can be set up perfectly and still have its messages land in spam, because the receiving server checks the domain's records before it decides whether to trust anything. These are the email DNS records that decide that, what each one is for, and which of them UHost publishes for you.
The four records
What each one actually does.
MX — where mail is delivered
Names the server that accepts mail for the domain. Without it, nobody can send you anything: there is no address to deliver to. This is the only one of the four that affects mail coming in.
SPF — who may send as you
A list of the servers allowed to send mail for the domain. A receiving server checks the sending address against it. Publish one record, not several: two SPF records are treated as none.
DKIM — a signature on every message
Your server signs outgoing mail with a private key, and publishes the matching public key in DNS so the receiver can check the message arrived unaltered and really came from you.
DMARC — what to do when a check fails
Tells receiving servers what you want done with mail that fails SPF and DKIM, and where to send reports. Without it, each receiver guesses differently.
What UHost does
Which records you have to touch.
When UHost is the authoritative DNS for the domain, it publishes the MX, SPF and DMARC records itself when you turn on mail for that domain, and signs outgoing mail with DKIM. There is nothing to copy out and paste in.
When your DNS is somewhere else — at your registrar, or another provider — UHost shows you the exact email DNS records to add there, and you add them by hand. The panel shows them under the domain's mail settings, so you are copying values rather than composing them.
- Add every one of them, not just MX. Mail arrives with MX alone, but what you send will be treated as suspect.
- Wait for the old values to expire before judging the result, because receivers cache what they last saw.
- Send a test message to an address on a large mail provider and look at whether it arrives in the inbox or the spam folder.
Mailboxes
Setting up the mailbox itself.
Mailboxes live under Mail, with a size limit each and forwarding if you want it. Mail is read over IMAP on port 993 and sent over SMTP on port 465, both over TLS, and there is Roundcube webmail in the browser for anyone who would rather not set up a client at all.
UHost answers the automatic configuration that Thunderbird and Outlook look for, so in most mail clients the address and password are enough and the ports fill themselves in. An account can only send as its own address, and sending is rate limited, which is what stops one compromised password turning your domain into a spam source.
Mail is stored outside the website's own account, so a compromised website does not give somebody your mail.
Messages are not carried across. UHost lists every address it finds in an account backup so you can create those mailboxes here, because the passwords on the old server cannot come with them and a mailbox nobody can open is worse than none. See migrating your websites.
Your servers, without the per-account bill.
UHost launches 13 October 2026: the whole panel free for up to three websites, and Pro for unlimited websites on a server.