Our email service

Zarfio DNS setup: MX, SPF, DKIM and DMARC

Zarfio is our own email service. The panel prepares the MX, SPF, DKIM and DMARC records for your domain; this guide covers the order of the steps and how to check each one.

Zarfio is operated by the same team as OrbitProbe. Links to Zarfio are promotional.

Steps

  1. Open an account and add the domain. Create a Zarfio account and add the domain you own. The panel lists the records that domain needs.
  2. Verify the domain. Publish the verification record the panel shows at your DNS host, then confirm it in the panel.
  3. Create the mailboxes. Create every address you use today before moving MX. Existing mailboxes at Google Workspace or Yandex 360 can be migrated.
  4. Lower the MX TTL and switch MX. On a domain that already receives mail, lower the MX TTL first. Then replace the old MX records with the ones from the panel.
  5. Publish SPF, DKIM and DMARC. Copy the SPF and DKIM values from the panel exactly as shown. If another service also sends for the domain, keep one SPF record and add that service’s include: to it.
  6. Check with OrbitProbe. Run the MX, SPF, DKIM and DMARC checks on this page until each one reads the values from the panel.

DNS records for Zarfio

Host "@" means the domain itself (example.com). Some DNS hosts want the field left empty, others want the full name: follow your DNS host’s convention.

PurposeTypeHostPriorityValue
Domain verificationTXT@—Generated for your domain. Copy it from the Zarfio panel, in the settings of your domain.
Receive mail (MX)MX@10mx1.zarfio.com.
SPFTXT@—v=spf1 mx -all
DKIMTXTdkim._domainkey—Generated for your domain. Copy it from the Zarfio panel, in the settings of your domain.
Domain verification
Type
TXT
Host
@
Value
Generated for your domain. Copy it from the Zarfio panel, in the settings of your domain.
Receive mail (MX)
Type
MX
Host
@
Priority
10
Value
mx1.zarfio.com.
SPF
Type
TXT
Host
@
Value
v=spf1 mx -all
DKIM
Type
TXT
Host
dkim._domainkey
Value
Generated for your domain. Copy it from the Zarfio panel, in the settings of your domain.
  • The MX and SPF values are the same for every domain. The verification code (zarfio-verify=…) and the DKIM key are generated for your domain: copy them from the panel, under Domains, your domain, DNS records. Somebody else’s DKIM value will not work.
  • The DKIM selector is always dkim, so the record name is dkim._domainkey. Enter dkim as the selector in the DKIM checker. The SPF record v=spf1 mx -all authorises the hosts in your MX record; if another service also sends for the domain, add its include: to the same record.

DMARC

DMARC is the same for every provider: one TXT record at _dmarc.example.com. Start with p=none and a reporting address, so you receive reports without affecting delivery.

Read the reports for a few weeks. When every legitimate sender passes SPF or DKIM with an aligned domain, move to p=quarantine and then p=reject. Moving to reject before DKIM is on for all senders is the usual way legitimate mail gets lost.

_dmarc.example.com.  3600  IN  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"

Optional: MTA-STS, TLS-RPT and BIMI

MTA-STS tells sending servers to require TLS when delivering to you. It needs a TXT record and a policy file served over HTTPS at mta-sts.example.com; the policy must list the MX hosts of your provider exactly.

TLS-RPT asks senders to report TLS delivery failures to an address you choose. One TXT record, no effect on delivery.

BIMI lets some mailbox providers show your logo. It requires DMARC at quarantine or reject, and most providers also require a verified mark certificate.

_mta-sts.example.com.  3600  IN  TXT  "v=STSv1; id=20260921T000000"
_smtp._tls.example.com.  3600  IN  TXT  "v=TLSRPTv1; rua=mailto:tls-reports@example.com"
default._bimi.example.com.  3600  IN  TXT  "v=BIMI1; l=https://example.com/logo.svg"

Mail clients: autodiscover and autoconfig

Zarfio mailboxes work with webmail and with standard IMAP, SMTP and ActiveSync clients. For manual setup use the server names shown in the Zarfio panel.

TTL advice

Before changing MX records on a domain that already receives mail, lower their TTL to 300 seconds and wait for the old TTL to run out. Resolvers then pick up the new records within minutes.

When the new setup has worked for a few days, raise the TTL again: 3600 seconds is a common value. SPF, DKIM and DMARC records change rarely and are fine at 3600.

How long do the changes take?

Your authoritative nameservers answer with the new record as soon as your DNS host has published it. A resolver that cached the old answer keeps it until the old TTL runs out; a name that did not exist before may be remembered as missing for the negative-caching time in your SOA record.

There is no moment at which a change is everywhere at once. The propagation tool shows what a fixed set of public resolvers answer at the time of the check, reported as a count such as "9 of 12 resolvers", and nothing more than that.

Providers re-check your records on their own schedule, so a verification button in the panel can stay red for a while after DNS is already correct.

Check your setup

Enter your domain and choose a check. Each one is a live lookup from our server; a lookup that fails is reported as "could not be checked", not as a missing record.

Common mistakes

  • Switching MX before the mailboxes exist, so mail for addresses that were not created yet is rejected.
  • Two SPF records. A domain may have only one TXT record that starts with v=spf1; a second one makes SPF fail with a permanent error. Merge the include: mechanisms into one record.
  • Leaving the old provider’s MX records next to the new ones. Mail is then delivered to either, depending on priority and chance.
  • Typing the full name into a host field that appends the domain, which produces google._domainkey.example.com.example.com. Look the record up after saving it.
  • A DKIM key cut in half. Long TXT values must be split into quoted strings of at most 255 characters; most DNS hosts do this for you, some do not.
  • More than ten DNS lookups in SPF after adding several include: mechanisms. The SPF checker counts them.
  • An MX record that points to a CNAME or to an IP address. It must point to a hostname that has A or AAAA records.

FAQ

Why are the Zarfio record values not printed here?

Because DKIM keys and verification values are generated per domain, and the panel is the authoritative place for the rest. A guide that prints values can go stale; the panel cannot.

Is Zarfio part of OrbitProbe?

It is a separate product run by the same team, which is why it is marked as our email service. The lookup tools on OrbitProbe work the same for every mail provider.

Can I keep my current DNS host?

Yes. Zarfio only needs records added where your DNS is hosted today; the nameservers do not change.

Will mail be lost during the switch?

Not if the mailboxes exist before MX changes. Sending servers retry for days when a delivery attempt fails temporarily, and with a lowered TTL the switch takes effect for most resolvers within minutes.