Skip to content
Transactional Email100K+ customers

Postmark: SPF, DKIM & DMARC Setup Guide

Postmark is known for high deliverability, but your domain reputation is still yours to maintain. Proper DKIM authentication and DMARC setup protects your brand whether you're on shared or dedicated IPs.

1SPF Record Setup

Recommended SPF record for Postmark:

v=spf1 include:spf.mtasv.net ~all

Postmark uses DKIM for authentication by default. SPF is handled via the include:spf.mtasv.net mechanism. Postmark recommends setting up DKIM sender signature authentication in the Postmark UI, which handles alignment automatically.

Step-by-step setup:

  1. 1In Postmark, go to Sender Signatures → your domain
  2. 2Postmark will show you a DKIM TXT record to add
  3. 3Add the TXT record to your DNS at the provided selector subdomain
  4. 4Also add the SPF include to your root domain's SPF record if needed
  5. 5Verify in Postmark — the status should turn green
  6. 6Check with our SPF and DKIM checkers

2DKIM Setup

Example DKIM record location:

pm._domainkey.yourdomain.com

Postmark provides a TXT record for DKIM with the 'pm' selector by default. You can also configure a custom DKIM domain for complete alignment with your From: address domain.

Step-by-step setup:

  1. 1In Postmark, go to Sender Signatures and add your sending domain
  2. 2Copy the DKIM TXT record provided (selector: pm._domainkey.yourdomain.com)
  3. 3Add the TXT record to your DNS provider
  4. 4Click Verify in Postmark after propagation
  5. 5Optionally set up a custom return path (MAIL FROM) domain for SPF alignment
  6. 6Test with our DKIM checker

3DMARC Policy

Recommended DMARC record:

v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100

Add as a TXT record at: _dmarc.yourdomain.com

With Postmark's DKIM authentication, DMARC will pass via DKIM alignment. Add your DMARC record to _dmarc.yourdomain.com. Postmark recommends moving to p=reject once you confirm all legitimate senders are authenticated.

Common Postmark Deliverability Issues

Postmark emails going to spam even with authentication

Verify your domain isn't blacklisted — domain reputation is separate from Postmark's IP reputation. Check DMARC reports for any authentication failures. Review your email content for spam triggers.

Bounce rate too high causing Postmark to flag account

Postmark suspends accounts with bounce rates over 10%. Remove hard bounces immediately, implement email validation at signup, and use double opt-in for marketing lists.

DKIM failing with 'signature verification failed'

Ensure the TXT record is published exactly as Postmark provided — no line breaks, no modifications. Check that the selector subdomain matches (pm._domainkey.yourdomain.com).

SPF softfail (˜all) vs hardfail (-all)

Postmark recommends ~all for SPF. Using -all can cause issues if email is forwarded. Start with ~all and DMARC quarantine/reject policy to enforce rejection without breaking forwarded mail.

Is Your Postmark Domain Blacklisted?

Authentication passing is necessary — but not sufficient. Check if your sending domain or IP is on any of 60 blacklists. Free, instant, no signup.

Check Your Domain Free

Checks all 60 blacklists + SPF, DKIM, DMARC, MX in under 10 seconds

Related Free Tools

Other Email Provider Guides