Zoho Mail DNS setup: MX, SPF, DKIM and DMARC

Zoho Mail uses three MX records. The hostnames depend on the data centre your account lives in, so compare the table with what your admin console shows.

Provider names identify the service a guide is written for. Apart from Zarfio, which is our own e-mail service, they do not imply partnership or endorsement. Values that a provider generates per domain are never printed here: copy those from the provider’s panel.

Steps

  1. Add and verify the domain. Add the domain in the Zoho Mail Admin Console and publish the verification TXT record (or CNAME) that it shows.
  2. Create users and aliases. Create every address before moving MX.
  3. Publish the MX records. Remove the old MX records and add the three Zoho records with priorities 10, 20 and 50.
  4. Publish SPF. Copy the SPF value from the admin console: the include: name differs between Zoho data centres. Keep a single SPF record.
  5. Add a DKIM selector. In the admin console create a selector, publish the TXT record at <selector>._domainkey, then verify it in the console so that Zoho starts signing.
  6. Add DMARC and check. Publish a DMARC record with p=none, then run the checks on this page.

DNS records for Zoho Mail

Host "@" means the domain itself (example.com). Some DNS hosts want the field left empty, others want the full name: follow your DNS host’s convention.

PurposeTypeHostPriorityValue
Domain verificationTXT@—Generated for your domain. Copy it from the Zoho Mail Admin Console (Domains section).
Receive mail (MX)MX@10mx.zoho.com.
Receive mail (MX)MX@20mx2.zoho.com.
Receive mail (MX)MX@50mx3.zoho.com.
SPFTXT@—Generated for your domain. Copy it from the Zoho Mail Admin Console (Domains section).
DKIMTXT…._domainkey—Generated for your domain. Copy it from the Zoho Mail Admin Console (Domains section).
Domain verification
Type
TXT
Host
@
Value
Generated for your domain. Copy it from the Zoho Mail Admin Console (Domains section).
Receive mail (MX)
Type
MX
Host
@
Priority
10
Value
mx.zoho.com.
Receive mail (MX)
Type
MX
Host
@
Priority
20
Value
mx2.zoho.com.
Receive mail (MX)
Type
MX
Host
@
Priority
50
Value
mx3.zoho.com.
SPF
Type
TXT
Host
@
Value
Generated for your domain. Copy it from the Zoho Mail Admin Console (Domains section).
DKIM
Type
TXT
Host
…._domainkey
Value
Generated for your domain. Copy it from the Zoho Mail Admin Console (Domains section).
  • The hostnames in the table are those of the zoho.com (United States) data centre. Accounts in the EU, India, Australia and other regions use the same names under that region’s domain, for example mx.zoho.eu. The admin console shows the correct set.
  • The DKIM selector name is yours to choose. Enter the same name in the DKIM checker.

DMARC

DMARC is the same for every provider: one TXT record at _dmarc.example.com. Start with p=none and a reporting address, so you receive reports without affecting delivery.

Read the reports for a few weeks. When every legitimate sender passes SPF or DKIM with an aligned domain, move to p=quarantine and then p=reject. Moving to reject before DKIM is on for all senders is the usual way legitimate mail gets lost.

_dmarc.example.com.  3600  IN  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"

Optional: MTA-STS, TLS-RPT and BIMI

MTA-STS tells sending servers to require TLS when delivering to you. It needs a TXT record and a policy file served over HTTPS at mta-sts.example.com; the policy must list the MX hosts of your provider exactly.

TLS-RPT asks senders to report TLS delivery failures to an address you choose. One TXT record, no effect on delivery.

BIMI lets some mailbox providers show your logo. It requires DMARC at quarantine or reject, and most providers also require a verified mark certificate.

_mta-sts.example.com.  3600  IN  TXT  "v=STSv1; id=20260921T000000"
_smtp._tls.example.com.  3600  IN  TXT  "v=TLSRPTv1; rua=mailto:tls-reports@example.com"
default._bimi.example.com.  3600  IN  TXT  "v=BIMI1; l=https://example.com/logo.svg"

TTL advice

Before changing MX records on a domain that already receives mail, lower their TTL to 300 seconds and wait for the old TTL to run out. Resolvers then pick up the new records within minutes.

When the new setup has worked for a few days, raise the TTL again: 3600 seconds is a common value. SPF, DKIM and DMARC records change rarely and are fine at 3600.

How long do the changes take?

Your authoritative nameservers answer with the new record as soon as your DNS host has published it. A resolver that cached the old answer keeps it until the old TTL runs out; a name that did not exist before may be remembered as missing for the negative-caching time in your SOA record.

There is no moment at which a change is everywhere at once. The propagation tool shows what a fixed set of public resolvers answer at the time of the check, reported as a count such as "9 of 12 resolvers", and nothing more than that.

Providers re-check your records on their own schedule, so a verification button in the panel can stay red for a while after DNS is already correct.

Check your setup

Enter your domain and choose a check. Each one is a live lookup from our server; a lookup that fails is reported as "could not be checked", not as a missing record.

Common mistakes

  • Using the .com hostnames for an account hosted in another region. Mail is then refused because the domain is not known in that data centre.
  • Two SPF records. A domain may have only one TXT record that starts with v=spf1; a second one makes SPF fail with a permanent error. Merge the include: mechanisms into one record.
  • Leaving the old provider’s MX records next to the new ones. Mail is then delivered to either, depending on priority and chance.
  • Typing the full name into a host field that appends the domain, which produces google._domainkey.example.com.example.com. Look the record up after saving it.
  • A DKIM key cut in half. Long TXT values must be split into quoted strings of at most 255 characters; most DNS hosts do this for you, some do not.
  • More than ten DNS lookups in SPF after adding several include: mechanisms. The SPF checker counts them.
  • An MX record that points to a CNAME or to an IP address. It must point to a hostname that has A or AAAA records.

FAQ

What are the MX records for Zoho Mail?

mx.zoho.com (10), mx2.zoho.com (20) and mx3.zoho.com (50) for accounts in the US data centre. Other regions use their own domain, such as zoho.eu; the admin console shows the set for your account.

Why is the SPF value not printed here?

Because it differs by data centre and Zoho has changed the include it documents over time. The admin console shows the current value for your account.

Which DKIM selector does Zoho use?

One that you name yourself when adding the key in the admin console. There is no fixed default.