Skip to main content
CRM Setup · 12 min read

SPF, DKIM and DMARC for Zoho in 2026.

The exact DNS records Zoho needs, where to publish them, and the SPF-alignment trap that wastes time. The short version: with Zoho, DKIM is what makes DMARC pass, not the SPF include Zoho suggests.

Updated May 2026·By EmailSheriff

1. Why Zoho authentication matters in 2026

Whether you send through Zoho Mail, Zoho CRM, or Zoho Campaigns, Google and Yahoo's 2024 rules apply: bulk senders must authenticate with SPF, DKIM, and DMARC or risk spam folders and outright rejection. Zoho gives you the records - but it also has one specific quirk that sends people down the wrong path, and we'll tackle that head-on.

The Zoho-specific trap

Zoho will suggest adding an SPF include like include:transmail.net. Here's the catch: because Zoho sends using its own envelope-from domain, SPF alignment fails against your From: domain regardless of that include. So it won't make DMARC pass on its own - and a needless include eats into your 10-lookup SPF budget. The reliable path to DMARC compliance with Zoho is DKIM.

DKIM
The protocol that carries Zoho DMARC alignment
10
Maximum DNS lookups allowed in a single SPF record
1
SPF records allowed per domain (merge, never duplicate)
48 hr
Worst-case DNS propagation after you publish a record

2. Where to start in Zoho

In Zoho CRM, click the Settings icon, then under Channels open Emails → Email Deliverability and select the domain you want to authenticate. (In Zoho Mail's admin console, the equivalent lives under domain settings.) Zoho displays the exact DKIM and SPF records to publish - always copy them from your own console, since selectors are unique to your domain.

3. Publish the DKIM record (your real authentication)

Zoho generates a DKIM TXT record with a selector unique to your domain. Add it at your DNS provider exactly as shown.

DNS · Zoho DKIM TXT (example - use your own selector & key)
zmail._domainkey TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSq..."

Two common mistakes: appending your domain twice in the host field (many DNS panels auto-append, so enter just the selector like zmail._domainkey), and pasting the key with line breaks or stray spaces. The public key must be one unbroken string.

4. SPF - add it, but don't rely on it for DMARC

Publish (or merge) the Zoho SPF include Zoho specifies for your service into your single SPF record:

DNS · merged SPF TXT record at root
v=spf1 include:zoho.com ~all

SPF is still worth having for non-aligned checks and general hygiene - but understand its limit here: with Zoho's envelope-from domain, SPF won't align to your From: domain, so it won't be what makes DMARC pass. That job belongs to DKIM. Keep to one SPF record and under ten lookups.

5. Publish your DMARC policy

DNS · TXT record at _dmarc.yourdomain.com
v=DMARC1; p=none; rua=mailto:[email protected]

Start at p=none to collect reports and confirm your Zoho DKIM is aligning. After a clean couple of weeks, tighten to p=quarantine, then p=reject. Walking the policy up prevents accidentally blocking your own mail.

6. Validate in Zoho

Back in Zoho's Email Deliverability screen, click Validate Records. Once DNS has propagated (minutes to 48 hours), your domain status flips to Authenticated. As always, that badge confirms your records resolve - not that your DMARC policy, reputation, or list are healthy.

Confirm it independently

Don't take one console's word for it. Run your domain through our CRM DNS Verifier - it checks your published records against Zoho's spec, confirms DKIM is aligning, and flags the SPF-alignment trap so you don't waste time on an include that can't pass.

7. Authenticated but still landing in spam?

Authentication done and still in spam? Check reputation and hygiene: (1) is your domain or IP blacklisted? Run a blacklist sweep. (2) is your content tripping filters? Run a spam score check. (3) is your list stale? Clean it with our List Cleaner. Authentication is the entry ticket; reputation and list quality decide placement.

8. Frequently asked questions

Should I add include:transmail.net to my SPF for Zoho?
Be careful here. Zoho often suggests adding include:transmail.net (or its zoho.com include) to your SPF - but because Zoho CRM uses its own domain in the envelope-from address, SPF alignment fails against your From: domain regardless. So the include doesn't make DMARC pass on its own, and adding includes you don't need risks the 10-lookup SPF limit. DKIM is the reliable path to DMARC alignment for Zoho.
What records does Zoho need for authentication?
Zoho provides a DKIM TXT record (with a selector unique to your domain) you publish in DNS, and instructs you to add an SPF include for the Zoho service you use (e.g. zoho.com or transmail.net for Zoho's transactional sending). You then publish your own DMARC TXT record at _dmarc. After publishing, return to Zoho and click Validate so it activates DKIM signing.
Where do I set up authentication in Zoho CRM?
In Zoho CRM, click the Settings icon, then under the Channels category open Emails → Email Deliverability, and select the domain you want to authenticate. Zoho shows you the DKIM and SPF records to publish in your DNS, then you click Validate Records. Once validated, your domain status shows Authenticated.
Why does Zoho show authenticated but emails still go to spam?
Zoho's authenticated status confirms your DKIM record resolves and validates - it doesn't guarantee inbox placement. The usual culprits are a missing or p=none DMARC policy, SPF misalignment (expected with Zoho - rely on DKIM), a blacklisted domain, spammy content, or a stale list. Confirm DKIM alignment independently and check reputation and list health.

Keep your sending healthy

CRM DNS Verifier
Forensic verification for Salesforce, Zoho, HubSpot, Mailchimp - finds the exact misconfigurations that break authentication.
Full Audit
All 6 deliverability checks on a domain in 30 seconds, graded A-F. Catches SPF lookup overflow and DKIM alignment issues.
DNS Checker
SPF · DKIM · DMARC · MX with plain-English explanations. Includes a 10-lookup counter for SPF.