Proton Mail custom domain DNS setup: MX, SPF, DKIM and DMARC

Proton’s domain wizard walks through five records. MX and SPF are the same for every customer; the verification value and the three DKIM targets are generated for your domain.

Provider names identify the service a guide is written for. Apart from Zarfio, which is our own e-mail service, they do not imply partnership or endorsement. Values that a provider generates per domain are never printed here: copy those from the provider’s panel.

Steps

  1. Add the domain and verify it. Add the domain in Proton settings and publish the TXT record that starts with protonmail-verification=. Leave it in place after verification.
  2. Add addresses. Create the addresses on the domain, and a catch-all if you want one, before moving MX.
  3. Publish the MX records. Remove the old MX records and add mail.protonmail.ch (priority 10) and mailsec.protonmail.ch (priority 20).
  4. Publish SPF. Add one TXT record at the apex: v=spf1 include:_spf.protonmail.ch ~all.
  5. Publish the three DKIM CNAMEs. Add protonmail._domainkey, protonmail2._domainkey and protonmail3._domainkey as CNAME records with the targets the wizard shows. Three records let Proton rotate keys without you touching DNS.
  6. Add DMARC and check. Publish a DMARC record, then run the checks on this page.

DNS records for Proton Mail

Host "@" means the domain itself (example.com). Some DNS hosts want the field left empty, others want the full name: follow your DNS host’s convention.

PurposeTypeHostPriorityValue
Domain verificationTXT@—Generated for your domain. Copy it from Proton Mail settings (Domain names section).
Receive mail (MX)MX@10mail.protonmail.ch.
Receive mail (MX)MX@20mailsec.protonmail.ch.
SPFTXT@—v=spf1 include:_spf.protonmail.ch ~all
DKIMCNAMEprotonmail._domainkey—Generated for your domain. Copy it from Proton Mail settings (Domain names section).
DKIMCNAMEprotonmail2._domainkey—Generated for your domain. Copy it from Proton Mail settings (Domain names section).
DKIMCNAMEprotonmail3._domainkey—Generated for your domain. Copy it from Proton Mail settings (Domain names section).
Domain verification
Type
TXT
Host
@
Value
Generated for your domain. Copy it from Proton Mail settings (Domain names section).
Receive mail (MX)
Type
MX
Host
@
Priority
10
Value
mail.protonmail.ch.
Receive mail (MX)
Type
MX
Host
@
Priority
20
Value
mailsec.protonmail.ch.
SPF
Type
TXT
Host
@
Value
v=spf1 include:_spf.protonmail.ch ~all
DKIM
Type
CNAME
Host
protonmail._domainkey
Value
Generated for your domain. Copy it from Proton Mail settings (Domain names section).
DKIM
Type
CNAME
Host
protonmail2._domainkey
Value
Generated for your domain. Copy it from Proton Mail settings (Domain names section).
DKIM
Type
CNAME
Host
protonmail3._domainkey
Value
Generated for your domain. Copy it from Proton Mail settings (Domain names section).
  • If your DNS host proxies CNAME records through a CDN, switch the proxy off for the three DKIM records: they must resolve as plain DNS.
  • In the DKIM checker use the selector protonmail (then protonmail2 and protonmail3).

DMARC

DMARC is the same for every provider: one TXT record at _dmarc.example.com. Start with p=none and a reporting address, so you receive reports without affecting delivery.

Read the reports for a few weeks. When every legitimate sender passes SPF or DKIM with an aligned domain, move to p=quarantine and then p=reject. Moving to reject before DKIM is on for all senders is the usual way legitimate mail gets lost.

_dmarc.example.com.  3600  IN  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"

Optional: MTA-STS, TLS-RPT and BIMI

MTA-STS tells sending servers to require TLS when delivering to you. It needs a TXT record and a policy file served over HTTPS at mta-sts.example.com; the policy must list the MX hosts of your provider exactly.

TLS-RPT asks senders to report TLS delivery failures to an address you choose. One TXT record, no effect on delivery.

BIMI lets some mailbox providers show your logo. It requires DMARC at quarantine or reject, and most providers also require a verified mark certificate.

_mta-sts.example.com.  3600  IN  TXT  "v=STSv1; id=20260921T000000"
_smtp._tls.example.com.  3600  IN  TXT  "v=TLSRPTv1; rua=mailto:tls-reports@example.com"
default._bimi.example.com.  3600  IN  TXT  "v=BIMI1; l=https://example.com/logo.svg"

TTL advice

Before changing MX records on a domain that already receives mail, lower their TTL to 300 seconds and wait for the old TTL to run out. Resolvers then pick up the new records within minutes.

When the new setup has worked for a few days, raise the TTL again: 3600 seconds is a common value. SPF, DKIM and DMARC records change rarely and are fine at 3600.

How long do the changes take?

Your authoritative nameservers answer with the new record as soon as your DNS host has published it. A resolver that cached the old answer keeps it until the old TTL runs out; a name that did not exist before may be remembered as missing for the negative-caching time in your SOA record.

There is no moment at which a change is everywhere at once. The propagation tool shows what a fixed set of public resolvers answer at the time of the check, reported as a count such as "9 of 12 resolvers", and nothing more than that.

Providers re-check your records on their own schedule, so a verification button in the panel can stay red for a while after DNS is already correct.

Check your setup

Enter your domain and choose a check. Each one is a live lookup from our server; a lookup that fails is reported as "could not be checked", not as a missing record.

Common mistakes

  • Deleting the verification TXT record after the domain is verified. Proton re-checks it, and the domain can fall back to unverified.
  • Two SPF records. A domain may have only one TXT record that starts with v=spf1; a second one makes SPF fail with a permanent error. Merge the include: mechanisms into one record.
  • Leaving the old provider’s MX records next to the new ones. Mail is then delivered to either, depending on priority and chance.
  • Typing the full name into a host field that appends the domain, which produces google._domainkey.example.com.example.com. Look the record up after saving it.
  • A DKIM key cut in half. Long TXT values must be split into quoted strings of at most 255 characters; most DNS hosts do this for you, some do not.
  • More than ten DNS lookups in SPF after adding several include: mechanisms. The SPF checker counts them.
  • An MX record that points to a CNAME or to an IP address. It must point to a hostname that has A or AAAA records.

FAQ

What are the MX records for Proton Mail?

mail.protonmail.ch with priority 10 and mailsec.protonmail.ch with priority 20.

What is the SPF record for Proton Mail?

v=spf1 include:_spf.protonmail.ch ~all, as the only SPF record on the domain.

Why does Proton use three DKIM records?

They are CNAMEs to keys that Proton hosts. With three selectors Proton can rotate signing keys on its side while DNS stays unchanged.