Back to tutorials
Tutorial

cPanel SPF DKIM DMARC Setup Guide Tutorial (2026): Fix Deliverability for WHM Email Domains

cPanel SPF DKIM DMARC setup guide tutorial for 2026: publish correct DNS records, enable signing, and stop mail from going to spam.

By Anurag Singh
Updated on Oct 06, 2026
Category: Tutorial
Share article
cPanel SPF DKIM DMARC Setup Guide Tutorial (2026): Fix Deliverability for WHM Email Domains

Most “my email goes to spam” tickets on cPanel aren’t caused by a dead mail server. They usually come from incomplete DNS authentication.

Common issues include:

  • SPF that doesn’t match the real sending IP
  • DKIM enabled in WHM, but not published in authoritative DNS
  • DMARC that doesn’t align with the visible From domain

This cPanel SPF DKIM DMARC setup guide tutorial gives you a clean, repeatable 2026 process for WHM/cPanel servers running Exim. The goal is simple: pass the checks modern mailbox providers use.

You’ll publish records correctly, verify them from the command line, and avoid common cPanel traps. Those traps include duplicate SPF TXT records, DKIM keys published under the wrong selector, and DMARC created at the wrong hostname.

Before you start: what you need (and what to confirm first)

Five minutes of prep saves hours of “DNS propagated… right?” and retesting.

  • Root or reseller-level access to WHM on your server.
  • DNS control for the domain (either in WHM DNS functions, your registrar DNS, or a provider like Cloudflare).
  • Public sending IP for outbound mail (often your VPS main IP). Confirm with: curl -4 ifconfig.me
  • Correct server hostname (FQDN) and working rDNS/PTR. In WHM: Networking Setup → Change Hostname.

If you host client sites and email on the same server, deliverability work exposes weak spots fast. The biggest ones are hostname, PTR, and DNS ownership.

A managed VPS hosting plan from HostMyCode is a practical option if you want those fixes handled without long back-and-forth.

Step 1 — Verify your hostname, rDNS, and HELO/EHLO (deliverability basics)

Mailbox providers still care about the basics. If your server introduces itself with a hostname that doesn’t resolve cleanly, you’ll see avoidable bounces and higher spam scoring.

  1. Confirm hostname resolves:

    hostname -f
    getent hosts $(hostname -f)

    Your FQDN should resolve to your server’s primary IP.

  2. Confirm PTR/rDNS matches the hostname (or at least points to a real FQDN you control):

    dig +short -x YOUR.SERVER.IP

If you’re seeing “Bad HELO” bounces, pause here. Don’t touch SPF/DKIM/DMARC yet.

Fix server identity first.

This pairs well with: SMTP HELO/EHLO hostname fix tutorial (2026).

Step 2 — Turn on DKIM in WHM (and understand what cPanel actually publishes)

On cPanel servers, Exim typically handles DKIM signing. cPanel manages keys per domain.

  1. In WHM, go to: Email → Email Authentication.

  2. Select the domain, then Enable DKIM.

  3. Copy the suggested DKIM TXT record value shown by WHM.

The common mistake: “Enabled” in WHM means the server will sign mail. It does not guarantee the public DNS record exists.

If your authoritative DNS is elsewhere (registrar, Cloudflare, separate DNS cluster), you still must publish the DKIM TXT record there.

From the shell, you can usually find the domain’s DKIM public key in one of these locations. The exact path varies by cPanel build and configuration:

ls -la /var/cpanel/domain_keys/ 2>/dev/null
ls -la /var/cpanel/domain_keys/public/ 2>/dev/null

For normal setups, don’t edit keys manually. Make sure the DNS record matches what WHM shows.

Step 3 — Publish SPF the right way (single TXT record, no duplicates)

Most SPF problems on cPanel are self-inflicted. The usual causes are duplicate SPF TXT records or an SPF string that misses a real sender (your server IP, a relay, or a web app).

Rule: publish one SPF TXT record per hostname. For most domains, that means the root domain.

A safe starter SPF for “send mail only from this cPanel server IP” looks like:

v=spf1 ip4:YOUR.SERVER.IP -all

If you also send through a third-party provider (example: transactional SMTP), add their include exactly as they document it:

v=spf1 ip4:YOUR.SERVER.IP include:spf.provider.example -all

Checklist before you hit save:

  • Delete old SPF TXT records first (very common after migrations).
  • Don’t split policy across multiple records (for example, one with ~all and another with -all).
  • Keep the SPF string under the 255-character TXT chunking limits (many DNS UIs split it for you, but not all).

If your DNS is on Cloudflare and you want to avoid cutover mistakes, skim this first: Cloudflare DNS setup guide tutorial (2026).

Step 4 — Publish DMARC with a realistic policy (start with monitoring)

DMARC is where people get overconfident. If you jump straight to p=reject, you can block legitimate mail you forgot you send.

That includes CRMs, contact forms, ticket systems, and marketing tools.

Start in monitoring mode, read reports, then tighten gradually:

v=DMARC1; p=none; adkim=s; aspf=s; rua=mailto:dmarc-reports@yourdomain.com; ruf=mailto:dmarc-forensics@yourdomain.com; fo=1; pct=100

What these settings do:

  • p=none: monitor only (no enforcement yet).
  • adkim=s and aspf=s: strict alignment. This helps prevent spoofing, but it means your From domain must match your authenticated domains.
  • rua: aggregate reports (daily XML summaries).
  • fo=1: request forensic failures (many providers don’t send these now, but it doesn’t hurt).

Practical tip: create the mailbox(es) you list in rua/ruf before you publish the record. Otherwise, report bounces pile up.

If that mailbox lives on the same cPanel server, lock it down. DMARC report addresses attract noise.

Step 5 — Validate DNS from Linux (don’t trust only web checkers)

Web testers are fine for quick confirmation. For real troubleshooting, dig is faster.

It also shows exactly what resolvers return.

Install DNS tools if needed:

# AlmaLinux/Rocky
dnf -y install bind-utils

# Ubuntu/Debian
apt-get update && apt-get -y install dnsutils

Then query what the world sees:

# SPF (root domain)
dig +short TXT yourdomain.com

# DKIM (selector varies; WHM shows the exact name)
dig +short TXT default._domainkey.yourdomain.com

# DMARC
Dig +short TXT _dmarc.yourdomain.com

Common DNS mistakes you can spot immediately:

  • Two SPF records showing up in dig output.
  • DKIM TXT values mangled by a DNS UI (broken quotes, added spaces, or unintended line breaks).
  • DMARC published at the wrong hostname (it must be _dmarc.yourdomain.com).

Step 6 — Confirm cPanel/Exim is signing DKIM (headers don’t lie)

Publishing DKIM in DNS is required, but it’s not the finish line. Outbound mail still needs a DKIM-Signature header.

That signature must also validate.

  1. Send a test email from a cPanel mailbox on the domain to an external address you control.

  2. Open the message source and look for:

    • DKIM-Signature:
    • Authentication-Results: (often added by the receiving server)

If DKIM is missing, go back to WHM Email Authentication. Confirm the domain is actually sending through this server.

Also confirm it’s not routing through a different relay or smarthost.

Step 7 — Make sure your DNS path matches your cPanel reality (nameservers, zones, clustering)

cPanel makes it easy to edit zones locally. That convenience is also the trap.

You can “fix” a record on the server and change nothing for the outside world if the domain’s authoritative DNS is elsewhere.

Confirm the domain’s authoritative NS:

dig NS yourdomain.com +short

If you run your own nameservers, build in redundancy. That’s exactly what a DNS cluster is for.

If you’re planning that setup, see: cPanel DNS Cluster Setup Tutorial (2026).

Step 8 — Tighten DMARC safely (none → quarantine → reject)

After you’ve reviewed DMARC reports for at least a week, tighten the policy in stages. Do this only after you verify every legitimate sender aligns.

Make one change at a time. That keeps failures obvious and rollbacks simple.

  • Phase 1 (monitor): p=none
  • Phase 2 (soft enforcement): p=quarantine; pct=25 then pct=100
  • Phase 3 (hard enforcement): p=reject

Example quarantine record:

v=DMARC1; p=quarantine; adkim=s; aspf=s; rua=mailto:dmarc-reports@yourdomain.com; pct=100

Example reject record:

v=DMARC1; p=reject; adkim=s; aspf=s; rua=mailto:dmarc-reports@yourdomain.com; pct=100

Step 9 — Troubleshoot common cPanel deliverability failures (fast checks)

These are the repeat offenders on WHM servers that host lots of domains.

Problem: Two SPF TXT records (permerror)

Symptom: SPF returns “permerror” or “too many DNS lookups”.

Fix: Keep a single SPF TXT record. Delete duplicates. Then re-check:

dig +short TXT yourdomain.com

Problem: DKIM exists in DNS but fails (bad signature)

Symptom: DKIM shows “fail” at the receiver.

  • Confirm you published the right selector (WHM shows it; don’t assume default if your server uses another).
  • Check for DNS UI formatting issues (extra spaces, missing quotes, line breaks).
  • Verify system time is correct; time drift can trigger confusing validation failures. If you suspect this, see VPS Time Sync Troubleshooting Tutorial (2026).

Problem: DMARC fails even though SPF passes

Cause: DMARC requires alignment. If your visible From header uses a different domain than the one authenticating, DMARC can fail while SPF still passes.

Fix: Make your application, SMTP relay, and From address use aligned domains. If you must use a third-party sender, configure it to sign DKIM for your domain, not theirs.

Problem: Mail is deferred or stuck in queue (deliverability impact)

Even perfect SPF/DKIM/DMARC won’t help if your queue backs up. Once that happens, remote servers may throttle you.

Use the queue-focused guide if you’re seeing delays: VPS Email Queue Troubleshooting Tutorial (2026).

Step 10 — Final validation checklist (copy/paste runbook)

If you manage multiple domains, this is your “done means done” list. Work it in order.

You’ll catch the issues that waste time later.

  • Hostname is a real FQDN and resolves to the server IP.
  • rDNS/PTR exists for the sending IP and matches (or reasonably maps to) the hostname.
  • SPF is exactly one TXT record and includes all real senders.
  • DKIM enabled in WHM for each domain; DNS has the correct selector._domainkey TXT.
  • DMARC published at _dmarc; starts at p=none and moves up after reports look clean.
  • Test message headers show DKIM signature present and pass at the receiver.

Summary: keep authentication boring, consistent, and testable

You don’t win deliverability with clever records. You win with consistency.

Keep one SPF record, ensure DKIM signing matches the published key, and tighten DMARC only after you confirm every sender aligns.

If you’re building (or rebuilding) mail on a hosting VPS, start with a stable foundation. HostMyCode’s HostMyCode VPS plans are a good match for cPanel/WHM deployments where you need predictable IPs, coordinated rDNS/PTR, and enough headroom to avoid queue and reputation problems.

Running client email on cPanel means you need reliable DNS, predictable outbound IP behavior, and enough resources to keep Exim responsive under load. If you’re moving off shared hosting or consolidating multiple domains, consider managed VPS hosting or a self-managed HostMyCode VPS so you can control authentication, logging, and deliverability end-to-end.

FAQ

Should I use “~all” or “-all” in SPF on cPanel?

If you’re confident you’ve listed every legitimate sender, use -all. If you’re still inventorying senders, start with ~all briefly, then switch to -all.

Why does WHM show DKIM enabled but external tests say “no DKIM record”?

Your domain probably doesn’t use this server for authoritative DNS. Publish the DKIM TXT record at your actual DNS provider, then confirm with dig.

Can I set DMARC to reject immediately?

You can, but it’s risky. Start with p=none, confirm alignment for every sender (web apps, CRMs, ticket systems), then move to quarantine and reject.

Do I need DMARC if SPF and DKIM already pass?

Yes, if you want receivers to enforce your anti-spoofing policy. DMARC also enables reporting, which is how you find unknown senders using your domain.

What if I’m sending from WordPress plugins and forms?

Prefer SMTP authenticated sending through your cPanel mail server or a trusted relay, and keep the From domain aligned. Misaligned From addresses are a common cause of DMARC failures.