Yandex 360 mail DNS setup: MX, SPF, DKIM and DMARC

Yandex 360 for Business needs one MX record, an SPF record and a DKIM key that the organisation’s admin panel generates for your domain.

Provider names identify the service a guide is written for. Apart from Zarfio, which is our own e-mail service, they do not imply partnership or endorsement. Values that a provider generates per domain are never printed here: copy those from the provider’s panel.

Steps

  1. Add and confirm the domain. Add the domain in the admin panel and confirm it with the TXT record the panel shows (other methods are offered too).
  2. Create the mailboxes. Create every address before moving MX.
  3. Publish the MX record. Remove the old MX records and add one record with priority 10 that points to mx.yandex.net.
  4. Publish SPF. Add one TXT record at the apex: v=spf1 redirect=_spf.yandex.net. If other services send for the domain, use include:_spf.yandex.net together with their includes and end the record with ~all, because redirect cannot be combined with all.
  5. Publish DKIM. Copy the public key from the admin panel into a TXT record at mail._domainkey.
  6. Add DMARC and check. Publish a DMARC record with p=none, then run the checks on this page.

DNS records for Yandex 360

Host "@" means the domain itself (example.com). Some DNS hosts want the field left empty, others want the full name: follow your DNS host’s convention.

PurposeTypeHostPriorityValue
Domain verificationTXT@—Generated for your domain. Copy it from the Yandex 360 for Business admin panel (in the settings of your domain).
Receive mail (MX)MX@10mx.yandex.net.
SPFTXT@—v=spf1 redirect=_spf.yandex.net
DKIMTXTmail._domainkey—Generated for your domain. Copy it from the Yandex 360 for Business admin panel (in the settings of your domain).
Domain verification
Type
TXT
Host
@
Value
Generated for your domain. Copy it from the Yandex 360 for Business admin panel (in the settings of your domain).
Receive mail (MX)
Type
MX
Host
@
Priority
10
Value
mx.yandex.net.
SPF
Type
TXT
Host
@
Value
v=spf1 redirect=_spf.yandex.net
DKIM
Type
TXT
Host
mail._domainkey
Value
Generated for your domain. Copy it from the Yandex 360 for Business admin panel (in the settings of your domain).
  • The DKIM selector is "mail". Enter it in the DKIM checker.
  • If your domain is delegated to Yandex’s own DNS hosting, the panel can create these records for you.

DMARC

DMARC is the same for every provider: one TXT record at _dmarc.example.com. Start with p=none and a reporting address, so you receive reports without affecting delivery.

Read the reports for a few weeks. When every legitimate sender passes SPF or DKIM with an aligned domain, move to p=quarantine and then p=reject. Moving to reject before DKIM is on for all senders is the usual way legitimate mail gets lost.

_dmarc.example.com.  3600  IN  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"

Optional: MTA-STS, TLS-RPT and BIMI

MTA-STS tells sending servers to require TLS when delivering to you. It needs a TXT record and a policy file served over HTTPS at mta-sts.example.com; the policy must list the MX hosts of your provider exactly.

TLS-RPT asks senders to report TLS delivery failures to an address you choose. One TXT record, no effect on delivery.

BIMI lets some mailbox providers show your logo. It requires DMARC at quarantine or reject, and most providers also require a verified mark certificate.

_mta-sts.example.com.  3600  IN  TXT  "v=STSv1; id=20260921T000000"
_smtp._tls.example.com.  3600  IN  TXT  "v=TLSRPTv1; rua=mailto:tls-reports@example.com"
default._bimi.example.com.  3600  IN  TXT  "v=BIMI1; l=https://example.com/logo.svg"

TTL advice

Before changing MX records on a domain that already receives mail, lower their TTL to 300 seconds and wait for the old TTL to run out. Resolvers then pick up the new records within minutes.

When the new setup has worked for a few days, raise the TTL again: 3600 seconds is a common value. SPF, DKIM and DMARC records change rarely and are fine at 3600.

How long do the changes take?

Your authoritative nameservers answer with the new record as soon as your DNS host has published it. A resolver that cached the old answer keeps it until the old TTL runs out; a name that did not exist before may be remembered as missing for the negative-caching time in your SOA record.

There is no moment at which a change is everywhere at once. The propagation tool shows what a fixed set of public resolvers answer at the time of the check, reported as a count such as "9 of 12 resolvers", and nothing more than that.

Providers re-check your records on their own schedule, so a verification button in the panel can stay red for a while after DNS is already correct.

Check your setup

Enter your domain and choose a check. Each one is a live lookup from our server; a lookup that fails is reported as "could not be checked", not as a missing record.

Common mistakes

  • Adding other senders after redirect=. Everything after a redirect is ignored unless the record is rewritten with include:.
  • Two SPF records. A domain may have only one TXT record that starts with v=spf1; a second one makes SPF fail with a permanent error. Merge the include: mechanisms into one record.
  • Leaving the old provider’s MX records next to the new ones. Mail is then delivered to either, depending on priority and chance.
  • Typing the full name into a host field that appends the domain, which produces google._domainkey.example.com.example.com. Look the record up after saving it.
  • A DKIM key cut in half. Long TXT values must be split into quoted strings of at most 255 characters; most DNS hosts do this for you, some do not.
  • More than ten DNS lookups in SPF after adding several include: mechanisms. The SPF checker counts them.
  • An MX record that points to a CNAME or to an IP address. It must point to a hostname that has A or AAAA records.

FAQ

What is the MX record for Yandex 360?

mx.yandex.net with priority 10. It is the only MX record.

What is the SPF record for Yandex 360?

v=spf1 redirect=_spf.yandex.net when Yandex is the only sender. With other senders, write v=spf1 include:_spf.yandex.net include:… ~all instead.

Which DKIM selector does Yandex use?

mail, so the record lives at mail._domainkey. The key itself is generated per domain and shown in the admin panel.