Wix SPF and DKIM setup
The CNAME records Wix asks for when you authenticate a custom domain for email marketing and automations, when Wix publishes them for you, and why the fifth CNAME can collide with your own DMARC record.
What you are setting up
Wix Email Marketing (and the “send an email” step in Wix Automations) sends campaigns on your behalf. Until you authenticate your custom domain, Wix sends them under one of its own authenticated domains, such as wixemails.com, and your recipients see a Wix signature. Authenticating hands the signature to your domain. Wix does not give you a TXT record to paste; it gives you a short list of CNAME records that delegate DKIM (and, since the fifth record was added, DMARC) to Wix. Whether you have to publish them yourself depends on where your domain's DNS lives.
Publish SPF and DKIM
In your site's dashboard, go to Email Marketing and, under Sender Details, click Manage Senders. Enter a sender name and a reply-to address on your custom domain, save, and confirm the address with the code Wix emails you. The domain status then reads “Not authenticated”; click Authenticate this domain to open the list of CNAME records. They look like this (the exact values are generated for your domain, so copy them from Wix):
Type: CNAME (DKIM) Host: s1._domainkey Value: (the target Wix shows you) Type: CNAME Host: sg Value: (the target Wix shows you) ... plus the remaining CNAMEs Wix lists, up to five in total
Wix's own example names the hosts s1._domainkey.yourdomain.com and sg.yourdomain.com. Most DNS hosts append your domain automatically, so enter only s1._domainkey and sg in the host field; if a host asks for @ and you manage DNS at Wix, leave the Host Name blank. Save after each record. Records can take a few hours to propagate, and Wix says to allow up to 24 hours before the status under Sender Details flips to authenticated (refresh the page to see it).
There is no SPF record to add. Wix does not publish an SPF include for email marketing, and its DNS help article tells you to get any SPF value from your mailbox provider, not from Wix. The CNAMEs above are the whole setup: the DKIM CNAME lets Wix sign with d=yourdomain.com, which is what DMARC needs to pass and align.
If Wix hosts your DNS (you bought the domain from Wix, or connected it by pointing your nameservers at Wix), you do not do any of this. Wix adds the records itself and the authentication starts automatically. If you connected the domain by pointing instead, your DNS stays with your registrar and you follow the manual steps above there.
Add DMARC
If you want your own reporting address and your own policy, publish a standard _dmarc TXT record and start in monitor-only mode:
Type: TXT Host: _dmarc Value: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
Build it with our DMARC builder and progress past p=none once your reports are clean. Read the gotcha below before you publish it, because Wix may already have claimed that name.
The Wix gotcha
The fifth CNAME is a DMARC record, and it wants the same name as yours. Wix says that with the “CNAME 5” record your DMARC record is set up automatically. A DMARC record can only live at _dmarc.yourdomain.com, and a name cannot hold a CNAME and a TXT record at the same time. So if you already publish your own _dmarc TXT (the one that sends aggregate reports to trustyourinbox), the DNS host will refuse the fifth CNAME, or worse, replace your record with Wix's and your reports stop arriving. Publish the DKIM and other CNAMEs, keep your own DMARC TXT, and accept that Wix shows the fifth record as pending; DKIM alone is enough for your Wix mail to pass DMARC. On a Wix-hosted domain, check Domains > Domain Actions > Manage DNS Records for a _dmarc CNAME that Wix added automatically before you add a TXT there.
The smaller trap is the s1._domainkey name itself. It is a common selector, and if another service already owns that CNAME on your domain, the Wix record cannot be added alongside it. Wix has no option to pick a different selector, so the other service has to move first.
Confirm it worked
- Check the status in Wix. Under Sender Details, the domain status should change from “Not authenticated” once the CNAMEs resolve, and the Wix signature disappears from your campaigns.
- Send a test and read the headers. Send a campaign to yourself, open the message, and confirm the DKIM signature shows
d=yourdomain.comanddmarc=pass. Our header analyzer reads it back plainly. - Watch the reports. Wix should appear as an aligned, passing source in your DMARC aggregate reports, labeled as a known sender in trustyourinbox. If you still see it failing, check that your
_dmarcTXT survived the Wix setup.
Connect your DNS once and we publish the Wix records above in a single click, with a five-minute window to undo. Then we keep watching this sender in your DMARC reports and tell you the moment Wix mail starts failing, so a typo in a record never quietly costs you the inbox.
Keep reading
Run a free DMARC audit
Paste your domain and see your published SPF, DKIM, and DMARC in plain English.
DMARC alignment, in plain English
Why a DKIM signature at s1._domainkey aligns your Wix campaigns to your domain.
DKIM record checker
Confirm the s1._domainkey CNAME resolves and is signing your Wix mail.
Squarespace SPF and DKIM setup
The other site builder with a built-in campaign sender and CNAME-delegated DKIM.
Last verified 2026-08-30 against the official Wix documentation.
Was this page helpful?
Free for one domain. Set up in five minutes. We parse the reports; you read plain-English summaries.