Rackspace Email SPF and DKIM setup
The SPF record, the DKIM switch in the Cloud Office Control Panel, the two MX records, and why DKIM only sets itself up when Rackspace is also your DNS host.
What you are setting up
Rackspace Email is a hosted mailbox service, so it is usually the source of your everyday mail: the mail your staff send from Outlook, a phone, or webmail. You authorize it with an SPF record pointing at emailsrvr.com and a DKIM key you switch on in the Cloud Office Control Panel. Rackspace signs with your own domain, so both SPF and DKIM align and DMARC passes. The part that trips people up is that Rackspace only publishes the DKIM record for you when Rackspace also hosts your DNS; everyone else copies a TXT record to their DNS host by hand.
Publish SPF and DKIM
SPF first. At your DNS host, add a TXT record at the root of the domain. Rackspace also expects the two MX records and the autodiscover CNAME if the domain is new to Rackspace, so they are listed alongside:
Type: TXT (SPF) Host: @ Value: v=spf1 include:emailsrvr.com ~all Type: MX Host: @ Value: mx1.emailsrvr.com priority 10 Value: mx2.emailsrvr.com priority 20 Type: CNAME (client autodiscovery) Host: autodiscover Value: autodiscover.emailsrvr.com
If you already have an SPF record, merge include:emailsrvr.com into it rather than adding a second one; Rackspace's own example for a second sender is v=spf1 include:emailsrvr.com include:othermailer.com ~all. Rackspace also asks that no other MX records exist beside its two. Once you are confident every sender is in the record, tighten ~all to -all.
Then DKIM. Sign in to the Cloud Office Control Panel as an administrator. In the Domains section of the home page, click Sender Authentication (DKIM), click the domain, then click Enable DKIM. If your DNS is hosted in the same control panel, Rackspace publishes the record itself and you are done. If your DNS lives anywhere else, the panel shows a DNS key (the host name) and a value; add that pair as a TXT record at your DNS host:
Type: TXT (DKIM) Host: the host name shown in the control panel (ends in ._domainkey) Value: the value shown in the control panel (starts v=DKIM1; ...)
Back in the panel, click Verify TXT Record. Rackspace says to allow up to 24 to 48 hours for DNS to propagate, though it is usually minutes. Once verified, every new outgoing message from the domain is signed with your key.
Add DMARC
Standard _dmarc TXT record, nothing Rackspace-specific. Rackspace's own guidance is SPF, then DKIM, then DMARC, and to start in monitor-only mode:
Type: TXT Host: _dmarc Value: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
Build it with our DMARC builder and progress past p=none once your reports are clean.
The Rackspace Email gotcha
DKIM is automatic only when Rackspace hosts your DNS. Many Rackspace Email customers keep DNS at their registrar or at Cloudflare, and for them Enable DKIM does nothing on its own; the key is generated, but until the TXT record it shows is published elsewhere and verified, mail keeps going out unsigned. Do not guess the host name or reuse a selector from another guide: Rackspace issues the host and value per domain, and the only correct pair is the one on the screen. The second trap is scope. include:emailsrvr.com authorizes Rackspace's own mail servers and nothing else, so a website form, an invoicing app, or a newsletter tool sending as your domain still fails SPF until it gets its own include and its own DKIM key. Their guides are in this same section.
Confirm it worked
- Verify in the control panel. Sender Authentication (DKIM) should report the TXT record as verified once it resolves.
- Send a test and read the headers. Send from a Rackspace mailbox to an outside address, open the message, and confirm the DKIM signature shows
d=yourdomain.comanddmarc=pass. Our header analyzer reads it back plainly. - Watch the reports. Rackspace should appear as an aligned, passing source in your DMARC aggregate reports, labeled as a known sender in trustyourinbox.
Connect your DNS once and we publish the Rackspace Email records above in a single click, with a five-minute window to undo. Then we keep watching this sender in your DMARC reports and tell you the moment Rackspace Email mail starts failing, so a typo in a record never quietly costs you the inbox.
Keep reading
Run a free DMARC audit
Paste your domain and see your published SPF, DKIM, and DMARC in plain English.
DKIM record checker
Confirm the DKIM TXT record Rackspace issued you resolves and is signing your mail.
Counting SPF lookups
include:emailsrvr.com costs one lookup; see how much of the budget of ten your other senders use.
Microsoft 365 SPF and DKIM setup
The other hosted mailbox many Rackspace customers migrate to or from.
Last verified 2026-08-30 against the official Rackspace Email documentation.
Was this page helpful?
Free for one domain. Set up in five minutes. We parse the reports; you read plain-English summaries.