1. Why Zoho authentication matters in 2026
Whether you send through Zoho Mail, Zoho CRM, or Zoho Campaigns, Google and Yahoo's 2024 rules apply: bulk senders must authenticate with SPF, DKIM, and DMARC or risk spam folders and outright rejection. Zoho gives you the records - but it also has one specific quirk that sends people down the wrong path, and we'll tackle that head-on.
Zoho will suggest adding an SPF include like include:transmail.net. Here's the catch: because Zoho sends using its own envelope-from domain, SPF alignment fails against your From: domain regardless of that include. So it won't make DMARC pass on its own - and a needless include eats into your 10-lookup SPF budget. The reliable path to DMARC compliance with Zoho is DKIM.
2. Where to start in Zoho
In Zoho CRM, click the Settings icon, then under Channels open Emails → Email Deliverability and select the domain you want to authenticate. (In Zoho Mail's admin console, the equivalent lives under domain settings.) Zoho displays the exact DKIM and SPF records to publish - always copy them from your own console, since selectors are unique to your domain.
3. Publish the DKIM record (your real authentication)
Zoho generates a DKIM TXT record with a selector unique to your domain. Add it at your DNS provider exactly as shown.
zmail._domainkey TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSq..."
Two common mistakes: appending your domain twice in the host field (many DNS panels auto-append, so enter just the selector like zmail._domainkey), and pasting the key with line breaks or stray spaces. The public key must be one unbroken string.
4. SPF - add it, but don't rely on it for DMARC
Publish (or merge) the Zoho SPF include Zoho specifies for your service into your single SPF record:
v=spf1 include:zoho.com ~all
SPF is still worth having for non-aligned checks and general hygiene - but understand its limit here: with Zoho's envelope-from domain, SPF won't align to your From: domain, so it won't be what makes DMARC pass. That job belongs to DKIM. Keep to one SPF record and under ten lookups.
5. Publish your DMARC policy
v=DMARC1; p=none; rua=mailto:[email protected]
Start at p=none to collect reports and confirm your Zoho DKIM is aligning. After a clean couple of weeks, tighten to p=quarantine, then p=reject. Walking the policy up prevents accidentally blocking your own mail.
6. Validate in Zoho
Back in Zoho's Email Deliverability screen, click Validate Records. Once DNS has propagated (minutes to 48 hours), your domain status flips to Authenticated. As always, that badge confirms your records resolve - not that your DMARC policy, reputation, or list are healthy.
Don't take one console's word for it. Run your domain through our CRM DNS Verifier - it checks your published records against Zoho's spec, confirms DKIM is aligning, and flags the SPF-alignment trap so you don't waste time on an include that can't pass.
Verify my Zoho DNS →7. Authenticated but still landing in spam?
Authentication done and still in spam? Check reputation and hygiene: (1) is your domain or IP blacklisted? Run a blacklist sweep. (2) is your content tripping filters? Run a spam score check. (3) is your list stale? Clean it with our List Cleaner. Authentication is the entry ticket; reputation and list quality decide placement.
8. Frequently asked questions
Should I add include:transmail.net to my SPF for Zoho?
include:transmail.net (or its zoho.com include) to your SPF - but because Zoho CRM uses its own domain in the envelope-from address, SPF alignment fails against your From: domain regardless. So the include doesn't make DMARC pass on its own, and adding includes you don't need risks the 10-lookup SPF limit. DKIM is the reliable path to DMARC alignment for Zoho.