DMARC
DMARC is the same for every provider: one TXT record at _dmarc.example.com. Start with p=none and a reporting address, so you receive reports without affecting delivery.
Read the reports for a few weeks. When every legitimate sender passes SPF or DKIM with an aligned domain, move to p=quarantine and then p=reject. Moving to reject before DKIM is on for all senders is the usual way legitimate mail gets lost.
_dmarc.example.com. 3600 IN TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
Optional: MTA-STS, TLS-RPT and BIMI
MTA-STS tells sending servers to require TLS when delivering to you. It needs a TXT record and a policy file served over HTTPS at mta-sts.example.com; the policy must list the MX hosts of your provider exactly.
TLS-RPT asks senders to report TLS delivery failures to an address you choose. One TXT record, no effect on delivery.
BIMI lets some mailbox providers show your logo. It requires DMARC at quarantine or reject, and most providers also require a verified mark certificate.
_mta-sts.example.com. 3600 IN TXT "v=STSv1; id=20260921T000000"
_smtp._tls.example.com. 3600 IN TXT "v=TLSRPTv1; rua=mailto:tls-reports@example.com"
default._bimi.example.com. 3600 IN TXT "v=BIMI1; l=https://example.com/logo.svg"
Mail clients: autodiscover and autoconfig
Zarfio mailboxes work with webmail and with standard IMAP, SMTP and ActiveSync clients. For manual setup use the server names shown in the Zarfio panel.
TTL advice
Before changing MX records on a domain that already receives mail, lower their TTL to 300 seconds and wait for the old TTL to run out. Resolvers then pick up the new records within minutes.
When the new setup has worked for a few days, raise the TTL again: 3600 seconds is a common value. SPF, DKIM and DMARC records change rarely and are fine at 3600.
How long do the changes take?
Your authoritative nameservers answer with the new record as soon as your DNS host has published it. A resolver that cached the old answer keeps it until the old TTL runs out; a name that did not exist before may be remembered as missing for the negative-caching time in your SOA record.
There is no moment at which a change is everywhere at once. The propagation tool shows what a fixed set of public resolvers answer at the time of the check, reported as a count such as "9 of 12 resolvers", and nothing more than that.
Providers re-check your records on their own schedule, so a verification button in the panel can stay red for a while after DNS is already correct.