Skip to main content
Protect your domain reputation today
SimpleDMARC

How to Set Up DMARC for Zoho Mail | SimpleDMARC

Step-by-step DMARC setup for Zoho Mail — domain verification, generate a monitor-mode record, configure SPF and DKIM through the Zoho Control Panel, verify, then enforce.

SimpleDMARC Team

Last updated August 12, 2026

Why Zoho Mail Setup Starts Before DMARC

Zoho Mail requires your domain to be verified as owned before most authentication features fully activate — DKIM signing in particular depends on this. If you haven't verified your domain in the Zoho Mail Control Panel yet, do that first under Domains. It's a separate step from DMARC itself, but everything else here assumes it's done.

Once that's out of the way, DMARC setup is straightforward: generate a record, publish it, configure SPF and DKIM, watch reports, then enforce.

Step 1Generating Your DMARC Record

DNS / record
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; ruf=mailto:dmarc-reports@yourdomain.com; fo=1; adkim=r; aspf=r; pct=100

p=none keeps you in monitor mode — nothing gets blocked while you confirm every legitimate sender is passing. rua/ruf are your report addresses, and relaxed alignment (adkim=r, aspf=r) is the right starting point while you're still mapping out what sends mail as your domain.

Step 2Configure SPF for Zoho Mail

DNS / record
v=spf1 include:zoho.com ~all

Add further includes for any other service sending mail as your domain — a CRM, a marketing platform, anything beyond Zoho itself.

Step 3Enable DKIM in the Zoho Mail Control Panel

Go to Email Authentication under Domains, then DKIM. Generate a key — Zoho lets you pick a selector name or assigns one automatically. Publish the resulting TXT record in your DNS, typically at a host like [selector]._domainkey.

Step 4Wait for Enforcement (Monitor First)

Give it one to two weeks before touching your policy. Watch reports for anything failing that shouldn't be, and confirm what percentage of mail already passes. Then move to p=quarantine, and eventually p=reject, by updating the same TXT record.

Step 5Verify Your Setup

  • Check the record with a DMARC Checker — watch specifically for a duplicate DMARC record, common if the domain was configured by a previous provider before migrating to Zoho
  • Confirm SPF with the SPF Checker
  • Send a real test message and check the authentication results on the receiving end.

Frequently asked questions

Do I need to verify my domain before setting up DMARC on Zoho?
Yes. Domain ownership verification in the Zoho Mail Control Panel should happen first — DKIM in particular depends on it.
What if my Zoho account is on a regional data center outside the US?
Check your SPF include value in the Control Panel's DNS setup page. Regional accounts sometimes use a different include domain than `zoho.com`.
I generated a DKIM key but it's not signing my mail. Why?
Publishing the DNS record isn't enough on Zoho — go back into the Control Panel and confirm the DKIM status shows as active, not just generated.
I'm migrating to Zoho from another provider. What should I check?
Look for a leftover DMARC or SPF record from your old provider before adding new ones. Duplicate records at the same host break validation.
Can DMARC pass on SPF alone, without DKIM configured?
Yes, DMARC only needs one of SPF or DKIM to align. But DKIM survives email forwarding better than SPF does, so setting up both is worth the extra step.

Protect your domain with SimpleDMARC

Monitor DMARC reports, catch spoofing early, and move from p=none to enforcement with confidence.

How to Set Up DMARC for Zoho Mail | SimpleDMARC