{"id":11678,"date":"2025-08-12T14:48:57","date_gmt":"2025-08-12T14:48:57","guid":{"rendered":"https:\/\/boostedhost.com\/blog\/fixing-email-deliverability-on-cpanel-2025-spf-dkim-dmarc-and-rdns\/"},"modified":"2025-08-12T14:49:01","modified_gmt":"2025-08-12T14:49:01","slug":"fixing-email-deliverability-on-cpanel-2025-spf-dkim-dmarc-and-rdns","status":"publish","type":"post","link":"https:\/\/boostedhost.com\/blog\/en\/fixing-email-deliverability-on-cpanel-2025-spf-dkim-dmarc-and-rdns\/","title":{"rendered":"Fixing Email Deliverability on cPanel (2025): SPF, DKIM, DMARC, and rDNS"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"11678\" class=\"elementor elementor-11678\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52180 e-con-full e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no e-con e-parent\" data-id=\"19b52180\" data-element_type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-19b5211 elementor-widget elementor-widget-text-editor\" data-id=\"19b5211\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><strong>Surprising fact:<\/strong> nearly 30% of sent messages fail authentication checks because DNS records are missing or misconfigured.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b5212 elementor-widget elementor-widget-text-editor\" data-id=\"19b5212\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><em>You<\/em> can stop that by using the Email Deliverability tool inside cPanel. The interface appears after your host enables the Feature Manager in WHM. It scans domains, checks SPF and DKIM, and shows status with action buttons.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b5213 elementor-widget elementor-widget-text-editor\" data-id=\"19b5213\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >The tool needs a DNS server authoritative for the domain. If you use third\u2011party mail like Gmail or Microsoft 365, follow their setup to add SPF and DKIM. Use <strong>Repair<\/strong> to auto-fix simple invalid records or <strong>Manage<\/strong> to edit Mail HELO, DKIM, SPF, DMARC, and PTR details.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b5214 elementor-widget elementor-widget-text-editor\" data-id=\"19b5214\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >This short guide gives a clear roadmap: what you\u2019ll click, what name\/value pairs to copy to external DNS, and when to coordinate with your provider for PTR. By the end, you\u2019ll know how to get to a passing status fast.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b5215 elementor-widget elementor-widget-text-editor\" data-id=\"19b5215\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p style=\"text-align:center\"><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b5216 elementor-widget elementor-widget-heading\" data-id=\"19b5216\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Key Takeaways<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b5217 elementor-widget elementor-widget-text-editor\" data-id=\"19b5217\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul >   <li>Find the Email Deliverability interface after your host enables the WHM Feature Manager.<\/li>   <li>The system relies on SPF and DKIM and requires authoritative DNS for the domain.<\/li>   <li>Use Repair for quick fixes; open Manage to edit HELO, DKIM, SPF, DMARC, and PTR.<\/li>   <li>Copy name\/value pairs to external DNS when you host records elsewhere.<\/li>   <li>Third\u2011party services need their own DKIM\/SPF steps; follow provider docs for best results.<\/li> <\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b5218 elementor-widget elementor-widget-heading\" data-id=\"19b5218\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Why your emails bounce or hit spam today<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b5219 elementor-widget elementor-widget-text-editor\" data-id=\"19b5219\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Receiving hosts inspect published DNS entries to confirm your domain really sent the message. When SPF, DKIM, DMARC, or PTR records are missing or wrong, remote servers may reject or mark your mail as risky.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52110 elementor-widget elementor-widget-text-editor\" data-id=\"19b52110\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><strong>Common problems<\/strong> include missing includes for third\u2011party services, a DKIM TXT stored under the wrong name, or a PTR that doesn&#8217;t map back to an A record. Misaligned HELO\/EHLO names also draw extra checks and reduce trust.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52111 elementor-widget elementor-widget-text-editor\" data-id=\"19b52111\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><em>Quick tip:<\/em> treat authentication as a group. Auditing SPF, DKIM, DMARC, and rDNS together fixes most issues faster than changing subject lines or content.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52112 elementor-widget elementor-widget-text-editor\" data-id=\"19b52112\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >For more background and practical steps, see this guide: <a href=\"https:\/\/www.namecheap.com\/support\/knowledgebase\/article.aspx\/9984\/2216\/why-emails-go-to-spam-and-what-to-do\/\" target=\"_blank\" rel=\"nofollow noopener\">why messages go to spam<\/a> and what to.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52113 elementor-widget elementor-widget-text-editor\" data-id=\"19b52113\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<table >   <tr>     <th>Failing record<\/th>     <th>Typical symptom<\/th>     <th>Quick fix<\/th>   <\/tr>   <tr>     <td>SPF (TXT)<\/td>     <td>Softfail or fail from third\u2011party sends<\/td>     <td>Add the provider&#8217;s <strong>include<\/strong> to the TXT value<\/td>   <\/tr>   <tr>     <td>DKIM (TXT)<\/td>     <td>Broken signature or unsigned messages<\/td>     <td>Publish the full key under the correct selector host<\/td>   <\/tr>   <tr>     <td>PTR (rDNS)<\/td>     <td>Rejected by strict servers<\/td>     <td>Ask the IP owner to set PTR pointing to a matching A record<\/td>   <\/tr>   <tr>     <td>DMARC (TXT)<\/td>     <td>No policy or reporting<\/td>     <td>Install a reporting policy after SPF and DKIM validate<\/td>   <\/tr> <\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52114 elementor-widget elementor-widget-heading\" data-id=\"19b52114\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Accessing the Email Deliverability interface and prerequisites in cPanel and WHM<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52115 elementor-widget elementor-widget-text-editor\" data-id=\"19b52115\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><strong>You\u2019ll see the Email Deliverability entry in cPanel once your host flips the switch in WHM\u2019s Feature Manager.<\/strong> Check WHM \u00bb Home \u00bb Packages \u00bb Feature Manager \u00bb Feature Lists to confirm the feature is enabled for your plan.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52116 elementor-widget elementor-widget-text-editor\" data-id=\"19b52116\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><em>If the interface is missing, contact support.<\/em> The system needs to know where DNS is authoritative before it can install TXT records. If your server does not host nameservers for the domain, cPanel will still generate suggested TXT Name and Value pairs that you must paste at your DNS provider.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52117 elementor-widget elementor-widget-text-editor\" data-id=\"19b52117\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52118 elementor-widget elementor-widget-text-editor\" data-id=\"19b52118\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><div class=\"ast-oembed-container \" style=\"height: 100%;\"><iframe title=\"WHM Tutorials - Email Deliverability\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/SA6YenGO8_M?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/div><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52119 elementor-widget elementor-widget-heading\" data-id=\"19b52119\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Third\u2011party providers and where settings live<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52120 elementor-widget elementor-widget-text-editor\" data-id=\"19b52120\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >When you use Gmail or Microsoft 365, follow the provider documentation and instructions to publish SPF and DKIM in your external DNS. cPanel can show the suggested mail-related dns records, but the authoritative nameservers win.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52121 elementor-widget elementor-widget-heading\" data-id=\"19b52121\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Understanding the domains table, Status, Repair vs Manage<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52122 elementor-widget elementor-widget-text-editor\" data-id=\"19b52122\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >The table lists each domain, its status, and action buttons. Click <strong>Repair<\/strong> to attempt an auto-fix (recheck may take up to five minutes). Use <strong>Manage<\/strong> to view HELO, copy suggested TXT records, or customize records manually. The gear icon changes pagination and refreshes the system view.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52123 elementor-widget elementor-widget-heading\" data-id=\"19b52123\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Set up SPF in cPanel: the foundation for trusted sending<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52124 elementor-widget elementor-widget-text-editor\" data-id=\"19b52124\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Start by locating the Suggested SPF (TXT) entry in Manage the Domain so you can copy the exact <strong>Name<\/strong> and <strong>Value<\/strong> to publish. Use the <em>View<\/em> toggle to show Full or Split formats if your DNS host limits 255 characters.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52125 elementor-widget elementor-widget-text-editor\" data-id=\"19b52125\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52126 elementor-widget elementor-widget-text-editor\" data-id=\"19b52126\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Click <strong>Customize<\/strong> to add Additional Hosts (+a) and Additional MX Servers (+mx). Add any dedicated gateways or marketing systems so the logic matches where you send from.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52127 elementor-widget elementor-widget-text-editor\" data-id=\"19b52127\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Under IP Address Settings, enter IPv4 or IPv6 blocks in CIDR form for fixed servers. The system already includes your server\u2019s main IPv4\/IPv6 addresses automatically.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52128 elementor-widget elementor-widget-text-editor\" data-id=\"19b52128\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Use the Include List (+include) for platforms like Mailchimp so their senders are authorized. Choose <strong>~all<\/strong> while rolling out for flexibility, and switch to <strong>-all<\/strong> when you confirm only authorized hosts are listed.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52129 elementor-widget elementor-widget-text-editor\" data-id=\"19b52129\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Preview the updated SPF record, then Install if your server is authoritative. If not, paste the suggested Name and Value at your external DNS host. Allow a few minutes for propagation, then recheck the status in the system.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52130 elementor-widget elementor-widget-heading\" data-id=\"19b52130\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Configure DKIM correctly: keys, TXT format, and provider considerations<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52131 elementor-widget elementor-widget-text-editor\" data-id=\"19b52131\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >If your domain has no DKIM key, generate one in Manage the Domain and copy the Suggested \u201cDKIM\u201d (TXT) Record exactly as shown.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52132 elementor-widget elementor-widget-text-editor\" data-id=\"19b52132\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><strong>Use the View tool<\/strong> to pick Full if your DNS host auto-splits long strings. Choose Split to paste 255-character chunks when your provider requires separate fields.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52133 elementor-widget elementor-widget-text-editor\" data-id=\"19b52133\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><em>Keep the private DKIM key secret.<\/em> Treat the private dkim key like a password. If it leaks, attackers can sign messages as your domain and harm your reputation.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52134 elementor-widget elementor-widget-text-editor\" data-id=\"19b52134\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >If DKIM fails for messages sent by PHP apps, check the PHP handler. For DSO without MPM ITK, enable two Exim options in WHM\u2019s Exim Configuration Manager to let the system attribute the sender correctly.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52136 aligncenter size-large wp-image-11692 elementor-widget elementor-widget-image\" data-id=\"19b52136\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/boostedhost.com\/blog\/wp-content\/uploads\/2025\/08\/A-detailed-technical-diagram-of-a-DKIM-DomainKeys-Identified-Mail-record-presented-in-a-1024x585.jpeg\" title=\"\" alt=\"A detailed technical diagram of a DKIM (DomainKeys Identified Mail) record, presented in a clean, minimalist style. The image should feature a prominent BoostedHost logo in the top-right corner, conveying a professional, enterprise-grade presentation. The diagram should include a clear visualization of the key components of a DKIM record, such as the selector, public key, and the TXT format, all rendered with precision and clarity. The overall mood should be one of informative, authoritative, and visually appealing, reflecting the subject matter and the section title.\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52137 elementor-widget elementor-widget-text-editor\" data-id=\"19b52137\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<blockquote > <p>&#8220;Create or regenerate your DKIM key pair, copy the suggested TXT Name and Value, and publish where your authoritative nameserver lives.&#8221;<\/p> <\/blockquote>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52138 elementor-widget elementor-widget-text-editor\" data-id=\"19b52138\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<table > <tr> <th>Action<\/th> <th>What to copy<\/th> <th>When to choose Full vs Split<\/th> <\/tr> <tr> <td>Generate Local DKIM Key<\/td> <td>Name and Value (Suggested DKIM TXT)<\/td> <td>Full if provider auto-splits<\/td> <\/tr> <tr> <td>Publish to authoritative DNS<\/td> <td>Exact TXT record value<\/td> <td>Split for 255-char limits<\/td> <\/tr> <tr> <td>Handle PHP-sent messages<\/td> <td>Adjust Exim options in WHM<\/td> <td>After changing PHP handler or enabling trust options<\/td> <\/tr> <\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52139 elementor-widget elementor-widget-text-editor\" data-id=\"19b52139\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><strong>Quick checklist:<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52140 elementor-widget elementor-widget-text-editor\" data-id=\"19b52140\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul > <li>Copy the TXT Name and Value exactly.<\/li> <li>Publish at the authoritative DNS or paste locally for reference.<\/li> <li>Test after propagation and rotate keys if compromised.<\/li> <\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52141 elementor-widget elementor-widget-heading\" data-id=\"19b52141\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">DMARC policy that enforces your SPF and DKIM<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52142 elementor-widget elementor-widget-text-editor\" data-id=\"19b52142\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><em>A DMARC policy turns authentication results into action and gives you reporting so you can see who sends for your domain.<\/em><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52143 elementor-widget elementor-widget-text-editor\" data-id=\"19b52143\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><strong>Prerequisites:<\/strong> make sure valid spf and dkim records are in place and passing for the domain before you enforce a policy. If either fails, DMARC will not effectively protect mail and may not activate enforcement.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52144 elementor-widget elementor-widget-text-editor\" data-id=\"19b52144\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p style=\"text-align:center\"><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52145 elementor-widget elementor-widget-heading\" data-id=\"19b52145\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Install the Suggested DMARC (TXT) Record<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52146 elementor-widget elementor-widget-text-editor\" data-id=\"19b52146\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >The interface shows a suggested record you can use to start. If the system hosts your zone, click <strong>Install the Suggested Record<\/strong> to add the TXT automatically.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52147 elementor-widget elementor-widget-text-editor\" data-id=\"19b52147\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >If your nameservers are external, copy the Suggested TXT Name and Value exactly and publish them at your DNS provider. Contact your provider if you need help adding the dns record.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52148 elementor-widget elementor-widget-text-editor\" data-id=\"19b52148\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul > <li>Begin with <strong>p=none<\/strong> to collect reports and verify sources.<\/li> <li>Publish <strong>rua<\/strong> (aggregate) and <strong>ruf<\/strong> (forensic) addresses so you can monitor pass\/fail rates.<\/li> <li>Gradually move to <strong>quarantine<\/strong> or <strong>reject<\/strong> once alignment and pass rates are stable.<\/li> <li>Recheck the system status after propagation; the interface may take a few minutes to update.<\/li> <\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52149 elementor-widget elementor-widget-text-editor\" data-id=\"19b52149\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<blockquote > <p>&#8220;Keep your DMARC record in sync with changes to SPF includes and DKIM selectors so legitimate sends aren&#8217;t blocked.&#8221;<\/p> <\/blockquote>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52150 elementor-widget elementor-widget-heading\" data-id=\"19b52150\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Reverse DNS (PTR) and HELO alignment: stop rDNS-related rejections<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52151 elementor-widget elementor-widget-text-editor\" data-id=\"19b52151\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Reverse DNS ties an IP back to a hostname, and it only works if that hostname also resolves forward. A PTR resolves an IP to a name, and that name must have a matching A record for the check to pass.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52152 elementor-widget elementor-widget-text-editor\" data-id=\"19b52152\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><strong>Who can set PTR:<\/strong> the owner of the IP space \u2014 usually your data center or hosting provider. If you cannot edit the PTR yourself, open a support ticket and ask the provider to set the desired mapping.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52153 elementor-widget elementor-widget-text-editor\" data-id=\"19b52153\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><em>Tip:<\/em> make your Mail HELO\/EHLO match the PTR\/A hostname. When the HELO and the reverse mapping align, receiving servers are much less likely to flag your traffic.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52155 aligncenter size-large wp-image-11704 elementor-widget elementor-widget-image\" data-id=\"19b52155\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/boostedhost.com\/blog\/wp-content\/uploads\/2025\/08\/A-realistic-and-detailed-image-of-a-reverse-DNS-PTR-record-for-the-domain-BoostedHost-1024x585.jpeg\" title=\"\" alt=\"A realistic and detailed image of a reverse DNS (PTR) record for the domain BoostedHost, showcased against a backdrop of a server rack and network equipment. The foreground features the PTR record prominently displayed, with the IP address and hostname clearly visible. The middle ground depicts the server rack, with its various network ports, cables, and cooling fans, conveying a sense of the technical infrastructure behind email deliverability. The background showcases a dimly lit data center environment, with subdued lighting and a subtle haze, creating a moody, technical atmosphere. The overall composition emphasizes the importance of proper rDNS (PTR) configuration in ensuring email deliverability for the BoostedHost platform.\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52156 elementor-widget elementor-widget-text-editor\" data-id=\"19b52156\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul >   <li>Check that your sending IP\u2019s PTR maps to a hostname that has a forward A record.<\/li>   <li>If PTR is missing or incorrect, contact the IP owner (data center or provider) to update the record.<\/li>   <li>Use the system\u2019s Email Deliverability page to see rDNS issues and follow the shown remediation steps.<\/li>   <li>Expect PTR changes to take time to propagate; plan a recheck after a few hours.<\/li> <\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52157 elementor-widget elementor-widget-text-editor\" data-id=\"19b52157\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<blockquote >   <p>&#8220;Keep PTRs consistent for each dedicated IP and align HELO with the PTR hostname to reduce rejections.&#8221;<\/p> <\/blockquote>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52158 elementor-widget elementor-widget-heading\" data-id=\"19b52158\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">email deliverability on cpanel: verification, fixes, and edge cases<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52159 elementor-widget elementor-widget-text-editor\" data-id=\"19b52159\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Use the Manage view to inspect HELO details and copy the exact suggested record Name and Value when the server isn\u2019t authoritative. This panel lists the Mail HELO and shows the Suggested &#8220;SPF\/DKIM\/DMARC&#8221; TXT entries you can publish elsewhere.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52160 elementor-widget elementor-widget-text-editor\" data-id=\"19b52160\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52161 elementor-widget elementor-widget-heading\" data-id=\"19b52161\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Use Manage the Domain: HELO info, suggested records, and manual edits<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52162 elementor-widget elementor-widget-text-editor\" data-id=\"19b52162\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Open Manage to get HELO info and the precise name value strings. Use the View toggle to pick Full or Split so long TXT values match your DNS host limits.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52163 elementor-widget elementor-widget-heading\" data-id=\"19b52163\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">When to click Repair: what it changes and timing of rechecks<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52164 elementor-widget elementor-widget-text-editor\" data-id=\"19b52164\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Click <strong>Repair<\/strong> for straightforward fixes. The system rechecks repaired records within about five minutes.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52165 elementor-widget elementor-widget-text-editor\" data-id=\"19b52165\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><em>Note:<\/em> you cannot update multiple domains that share the same zone at once.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52166 elementor-widget elementor-widget-heading\" data-id=\"19b52166\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Hostname vs domain in WHM: server-level SPF, DKIM, and DMARC<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52167 elementor-widget elementor-widget-text-editor\" data-id=\"19b52167\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >WHM\u2019s feature covers the server hostname separately from each domain name. Use that server-level area to install SPF, DKIM, and DMARC for the host itself.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52168 elementor-widget elementor-widget-heading\" data-id=\"19b52168\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Nameservers not controlled by cPanel: copying Name\/Value to your DNS host<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52169 elementor-widget elementor-widget-text-editor\" data-id=\"19b52169\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >If the system does not host nameservers for a domain, copy the suggested TXT name and value and paste them at the provider that manages your DNS. Track any problem exists flags and clear SPF and DKIM first, then DMARC and rDNS.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52170 elementor-widget elementor-widget-heading\" data-id=\"19b52170\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Smart host scenarios and why PTR might not appear<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52171 elementor-widget elementor-widget-text-editor\" data-id=\"19b52171\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >If you relay through a smart host, PTR details may be omitted in the UI. The outbound IP is set by the relay provider, so request PTR changes from them when needed.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52172 elementor-widget elementor-widget-text-editor\" data-id=\"19b52172\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<blockquote > <p>&#8220;Open Manage, copy the suggested record text exactly, and verify with the gear icon refresh after propagation.&#8221;<\/p> <\/blockquote>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52173 elementor-widget elementor-widget-text-editor\" data-id=\"19b52173\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<table > <tr> <th>Action<\/th> <th>What to copy<\/th> <th>Timing \/ Notes<\/th> <\/tr> <tr> <td>Open Manage<\/td> <td>Suggested TXT Name &amp; Value<\/td> <td>Use Full\/Split before pasting to nameservers<\/td> <\/tr> <tr> <td>Click Repair<\/td> <td>System auto-fixes invalid records<\/td> <td>Recheck ~5 minutes; no bulk edits per zone<\/td> <\/tr> <tr> <td>WHM Hostname<\/td> <td>Server\u2011level SPF\/DKIM\/DMARC records<\/td> <td>Separate from each domain name<\/td> <\/tr> <tr> <td>Smart host<\/td> <td>Request PTR from provider<\/td> <td>PTR may not show if relay controls IP<\/td> <\/tr> <\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52174 elementor-widget elementor-widget-heading\" data-id=\"19b52174\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Conclusion<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52175 elementor-widget elementor-widget-text-editor\" data-id=\"19b52175\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><strong>,<\/strong>Wrap up the setup by confirming TXT entries are published and propagated for every domain you manage.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52176 elementor-widget elementor-widget-text-editor\" data-id=\"19b52176\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p ><strong>Quick checklist:<\/strong> set spf to cover all senders, publish the dkim record correctly, then add dmarc at <em>p=none<\/em> while you collect reports.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52177 elementor-widget elementor-widget-text-editor\" data-id=\"19b52177\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Copy the Suggested Name and Value from the interface when your system is not authoritative. Ask the IP owner to set PTR so HELO and forward A records match.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52178 elementor-widget elementor-widget-text-editor\" data-id=\"19b52178\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p >Protect your private dkim key, rotate when needed, and test by sending to a major provider. Inspect headers for spf=pass, dkim=pass, and dmarc=pass to confirm success.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b52179 schema-section elementor-widget elementor-widget-text-editor\" data-id=\"19b52179\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<section class=\"schema-section\"><h2>FAQ<\/h2><div><h3>What should you check first if messages bounce or land in spam?<\/h3><div><div><p>Start by verifying your SPF, DKIM, and DMARC records in DNS. Confirm your server IP has a proper PTR record and that your HELO\/EHLO name matches a forward-resolving A record. Also check whether your DNS host is authoritative so suggested TXT records actually publish.<\/p><\/div><\/div><\/div><div><h3>How do you access the Email Deliverability interface and what prerequisites matter?<\/h3><div><div><p>Open the Email Deliverability section in cPanel or WHM. Ensure the feature is enabled in WHM\u2019s Feature Manager and that the domain uses an authoritative nameserver. If you use Gmail or Microsoft 365, some settings live at those providers instead of your control panel.<\/p><\/div><\/div><\/div><div><h3>What does the interface table show and when should you use Manage vs Repair?<\/h3><div><div><p>The table lists domains with statuses and suggested records. Click Manage to view name\/value pairs and make manual edits. Use Repair to let the system attempt automatic fixes\u2014ideal for common missing or malformed TXT records, but allow time for DNS propagation.<\/p><\/div><\/div><\/div><div><h3>How do you view and copy the suggested SPF TXT record?<\/h3><div><div><p>In Manage, the suggested SPF shows the TXT record\u2019s Name and Value fields. Copy both exactly, then paste into your DNS host\u2019s TXT entry if cPanel isn\u2019t authoritative. Verify the record with a DNS lookup after propagation.<\/p><\/div><\/div><\/div><div><h3>Can you customize the SPF record for additional hosts or services?<\/h3><div><div><p>Yes. Add entries like +a for extra hostnames, +mx for extra mail exchangers, or +include: for services such as Mailchimp. Ensure you don\u2019t exceed DNS TXT length limits and choose the right all mechanism (~all for softfail, -all for strict fail) based on your risk tolerance.<\/p><\/div><\/div><\/div><div><h3>How do you add IPs with CIDR notation, and are server IPs included automatically?<\/h3><div><div><p>Add IPv4 or IPv6 addresses using CIDR (\/32, \/128, etc.) into the IP Address settings when customizing SPF. cPanel often auto-includes the server\u2019s primary sending IP; verify the final TXT includes any other outbound IPs you use.<\/p><\/div><\/div><\/div><div><h3>How do you generate and install a DKIM key locally?<\/h3><div><div><p>Use the Email Deliverability or WHM key-generation option to create a local DKIM key. Copy the suggested DKIM TXT name and value into your DNS host or let cPanel install it if authoritative. After publishing, test with a DKIM validator to confirm the public key resolves.<\/p><\/div><\/div><\/div><div><h3>What about long DKIM TXT values\u2014full vs split records?<\/h3><div><div><p>DNS limits single-string TXT parts to about 255 characters. Some DNS providers automatically split long values; others require you to add quoted fragments. If your host doesn\u2019t auto-split, paste the DKIM value as multiple quoted strings as instructed by the provider.<\/p><\/div><\/div><\/div><div><h3>When might you need the private DKIM key and what are the risks?<\/h3><div><div><p>You typically don\u2019t share the private key. Only retrieve it if you must migrate signing to another server or for backup. Keep it secure\u2014exposure lets others sign mail as your domain and can destroy reputation.<\/p><\/div><\/div><\/div><div><h3>Are there server-side caveats for PHP scripts that affect signing?<\/h3><div><div><p>Yes. If PHP runs under certain handlers (DSO, Mod_Ruid2, MPM ITK), scripts might send mail as the system user instead of the domain user. Review Exim Configuration Manager and PHP handler behavior to ensure messages get proper SPF\/DKIM alignment.<\/p><\/div><\/div><\/div><div><h3>What must be true before you install a DMARC record?<\/h3><div><div><p>Ensure valid SPF and DKIM records exist and pass checks. Once those are in place, add the suggested DMARC TXT (policy, aggregate\/reporting addresses). Remember that DMARC is enforced only when the receiving system evaluates alignment and the DNS record is authoritative.<\/p><\/div><\/div><\/div><div><h3>Who controls reverse DNS (PTR) and why does it matter?<\/h3><div><div><p>PTR records map IPs back to hostnames and are controlled by the IP owner\u2014usually your hosting provider or data center. PTR must resolve to an A record and match HELO to avoid rejections from strict receivers.<\/p><\/div><\/div><\/div><div><h3>How do you handle nameservers that aren\u2019t managed in cPanel?<\/h3><div><div><p>Copy the Name and Value fields from Manage and add them at your DNS provider\u2019s dashboard. If your domain uses third-party DNS, changes made in cPanel won\u2019t publish\u2014use the authoritative host instead.<\/p><\/div><\/div><\/div><div><h3>Why might PTR not appear for smart host setups or relay scenarios?<\/h3><div><div><p>If you send through a smart host or relay, the sending IP belongs to that relay provider. PTR entries and HELO alignment are then the relay operator\u2019s responsibility, and you must coordinate with them for proper reverse DNS.<\/p><\/div><\/div><\/div><div><h3>When should you click Repair and what happens afterward?<\/h3><div><div><p>Click Repair when suggested records are missing or malformed and you want cPanel to attempt an automatic fix. The system updates DNS if authoritative; otherwise it provides the records for you to add. Allow time for TTL and DNS propagation before rechecking status.<\/p><\/div><\/div><\/div><div><h3>How do server hostname records differ from domain records in WHM?<\/h3><div><div><p>The server hostname uses server-level SPF\/DKIM\/DMARC that affect system-generated mail (cron, notifications). Domain records govern user mail. Keep both consistent to minimize alignment issues and reputation hits.<\/p><\/div><\/div><\/div><div><h3>How can you verify that records have propagated and work correctly?<\/h3><div><div><p>Use public DNS lookup tools to fetch TXT and PTR records, and online validators for SPF, DKIM, and DMARC. Send test messages to check header authentication results and review bounce or spam reports for clues.<\/p><\/div><\/div><\/div><\/section>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Surprising fact: nearly 30% of sent messages fail authentication checks because DNS records are missing or misconfigured. You can stop that by using the Email Deliverability tool inside cPanel. The interface appears after your host enables the Feature Manager in WHM. It scans domains, checks SPF and DKIM, and shows status with action buttons. The tool needs a DNS server authoritative for the domain. If you use third\u2011party mail like Gmail or Microsoft 365, follow their setup to add SPF and DKIM. Use Repair to auto-fix simple invalid records or Manage to edit Mail HELO, DKIM, SPF, DMARC, and PTR details. This short guide gives a clear roadmap: what you\u2019ll click, what name\/value pairs to copy to external DNS, and when to coordinate with your provider for PTR. By the end, you\u2019ll know how to get to a passing status fast. Key Takeaways Find the Email Deliverability interface after your host enables the WHM Feature Manager. The system relies on SPF and DKIM and requires authoritative DNS for the domain. Use Repair for quick fixes; open Manage to edit HELO, DKIM, SPF, DMARC, and PTR. Copy name\/value pairs to external DNS when you host records elsewhere. Third\u2011party services need their own DKIM\/SPF steps; follow provider docs for best results. Why your emails bounce or hit spam today Receiving hosts inspect published DNS entries to confirm your domain really sent the message. When SPF, DKIM, DMARC, or PTR records are missing or wrong, remote servers may reject or mark your mail as risky. Common problems include missing includes for third\u2011party services, a DKIM TXT stored under the wrong name, or a PTR that doesn&#8217;t map back to an A record. Misaligned HELO\/EHLO names also draw extra checks and reduce trust. Quick tip: treat authentication as a group. Auditing SPF, DKIM, DMARC, and rDNS together fixes most issues faster than changing subject lines or content. For more background and practical steps, see this guide: why messages go to spam and what to. Failing record Typical symptom Quick fix SPF (TXT) Softfail or fail from third\u2011party sends Add the provider&#8217;s include to the TXT value DKIM (TXT) Broken signature or unsigned messages Publish the full key under the correct selector host PTR (rDNS) Rejected by strict servers Ask the IP owner to set PTR pointing to a matching A record DMARC (TXT) No policy or reporting Install a reporting policy after SPF and DKIM validate Accessing the Email Deliverability interface and prerequisites in cPanel and WHM You\u2019ll see the Email Deliverability entry in cPanel once your host flips the switch in WHM\u2019s Feature Manager. Check WHM \u00bb Home \u00bb Packages \u00bb Feature Manager \u00bb Feature Lists to confirm the feature is enabled for your plan. If the interface is missing, contact support. The system needs to know where DNS is authoritative before it can install TXT records. If your server does not host nameservers for the domain, cPanel will still generate suggested TXT Name and Value pairs that you must paste at your DNS provider. Third\u2011party providers and where settings live When you use Gmail or Microsoft 365, follow the provider documentation and instructions to publish SPF and DKIM in your external DNS. cPanel can show the suggested mail-related dns records, but the authoritative nameservers win. Understanding the domains table, Status, Repair vs Manage The table lists each domain, its status, and action buttons. Click Repair to attempt an auto-fix (recheck may take up to five minutes). Use Manage to view HELO, copy suggested TXT records, or customize records manually. The gear icon changes pagination and refreshes the system view. Set up SPF in cPanel: the foundation for trusted sending Start by locating the Suggested SPF (TXT) entry in Manage the Domain so you can copy the exact Name and Value to publish. Use the View toggle to show Full or Split formats if your DNS host limits 255 characters. Click Customize to add Additional Hosts (+a) and Additional MX Servers (+mx). Add any dedicated gateways or marketing systems so the logic matches where you send from. Under IP Address Settings, enter IPv4 or IPv6 blocks in CIDR form for fixed servers. The system already includes your server\u2019s main IPv4\/IPv6 addresses automatically. Use the Include List (+include) for platforms like Mailchimp so their senders are authorized. Choose ~all while rolling out for flexibility, and switch to -all when you confirm only authorized hosts are listed. Preview the updated SPF record, then Install if your server is authoritative. If not, paste the suggested Name and Value at your external DNS host. Allow a few minutes for propagation, then recheck the status in the system. Configure DKIM correctly: keys, TXT format, and provider considerations If your domain has no DKIM key, generate one in Manage the Domain and copy the Suggested \u201cDKIM\u201d (TXT) Record exactly as shown. Use the View tool to pick Full if your DNS host auto-splits long strings. Choose Split to paste 255-character chunks when your provider requires separate fields. Keep the private DKIM key secret. Treat the private dkim key like a password. If it leaks, attackers can sign messages as your domain and harm your reputation. If DKIM fails for messages sent by PHP apps, check the PHP handler. For DSO without MPM ITK, enable two Exim options in WHM\u2019s Exim Configuration Manager to let the system attribute the sender correctly. &#8220;Create or regenerate your DKIM key pair, copy the suggested TXT Name and Value, and publish where your authoritative nameserver lives.&#8221; Action What to copy When to choose Full vs Split Generate Local DKIM Key Name and Value (Suggested DKIM TXT) Full if provider auto-splits Publish to authoritative DNS Exact TXT record value Split for 255-char limits Handle PHP-sent messages Adjust Exim options in WHM After changing PHP handler or enabling trust options Quick checklist: Copy the TXT Name and Value exactly. Publish at the authoritative DNS or paste locally for reference. Test after propagation and rotate keys if compromised. DMARC policy that enforces your SPF and DKIM<\/p>\n","protected":false},"author":2,"featured_media":11680,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[19,16,1],"tags":[415,408,410,411,413,414,412,409],"class_list":["post-11678","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hosting","category-web-hosting","category-wordpress","tag-cpanel-email-hosting","tag-cpanel-email-setup","tag-dkim-authentication","tag-dmarc-policy","tag-email-authentication-protocols","tag-email-deliverability-solutions","tag-rdns-configuration","tag-spf-record-configuration"],"_links":{"self":[{"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/posts\/11678","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/comments?post=11678"}],"version-history":[{"count":1,"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/posts\/11678\/revisions"}],"predecessor-version":[{"id":11716,"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/posts\/11678\/revisions\/11716"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/media\/11680"}],"wp:attachment":[{"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/media?parent=11678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/categories?post=11678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/boostedhost.com\/blog\/en\/wp-json\/wp\/v2\/tags?post=11678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}