Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To authenticate SaaS email, publish the exact DNS records your provider issues, coordinate SPF with every service that sends for your domain, enable DKIM, and use DMARC to check alignment with the visible From address. First identify your authoritative DNS host and existing mail senders; changing the wrong record—especially an MX record—can disrupt incoming mail.
What DNS records do you need?
There is no universal record set for SaaS email. The provider and the feature you enable determine whether you need TXT, CNAME, or MX records. Copy each record’s name, type, and value from the selected service’s current setup page; do not reuse values from another provider’s guide.
| Record | What it does | What to watch |
|---|---|---|
| SPF (TXT) | Lists sending systems authorized for a domain. | Maintain one SPF policy per sending domain, covering all of its senders. |
| DKIM (often TXT or provider-directed CNAME) | Lets receiving servers verify a cryptographic signature using a public key published in DNS. | Use the provider-issued selector and record value. Providers may manage DKIM through CNAME records. |
| DMARC (TXT) | Sets a policy and reporting mechanism based on whether SPF or DKIM authenticates and aligns with the visible From domain. | Start with a monitoring policy if you do not yet know all legitimate senders. |
| MX | Routes incoming email to mail servers. | Do not replace existing MX records for an outbound-authentication setup unless the provider specifically requires a separate MX record for a dedicated subdomain. |
SPF, DKIM, and DMARC are related but do different jobs. DMARC passes when at least one of SPF or DKIM both passes authentication and aligns with the domain shown in the From address. Authentication helps satisfy recipient requirements, but it does not guarantee inbox placement.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteBefore editing DNS, identify your senders and DNS host
Your registrar and your authoritative DNS provider may be different companies. Make changes in the DNS zone that actually serves the domain. Then list every system that sends mail using the domain or its subdomains: mailbox hosting, website forms, password resets, invoices, support tools, marketing platforms, and the SaaS application you are configuring. Google advises including all organization senders in SPF, including third-party services (Google Workspace Admin Help: Set up SPF).
#1 Best Overall
- DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
- AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
- CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
- EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
- OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
Record the visible From domain and any separate return-path or MAIL FROM domain. This distinction matters because DMARC alignment compares the From domain with the SPF-authenticated MAIL FROM domain or the DKIM signing domain.
Publish the provider’s verification and DKIM records
- Open the SaaS provider’s domain-authentication or sending-domain setup page and select the domain or subdomain you intend to use.
- Copy each requested DNS record’s host/name, type, and value exactly. Add it in the authoritative DNS zone without changing unrelated records.
- Use the provider’s verification control after publishing the records. A provider may issue TXT records for verification or DKIM, or CNAME records that point authentication names to provider-managed infrastructure. For example, Twilio SendGrid’s domain-authentication workflow generates records that include a CNAME (Twilio SendGrid: How to Set Up Domain Authentication).
Google describes DKIM as a public/private key arrangement: the sender signs with the private key, while receivers can retrieve the public key from DNS. Google recommends a 2048-bit key when the DNS provider supports it; its guidance says personal Gmail delivery requires at least 1024 bits (Google Workspace Admin Help: Set up DKIM).
Rank #2
- 𝗢𝗻𝗲 𝗦𝘄𝗶𝘁𝗰𝗵 𝗠𝗮𝗱𝗲 𝘁𝗼 𝗘𝘅𝗽𝗮𝗻𝗱 𝗡𝗲𝘁𝘄𝗼𝗿𝗸: 5× 10/100/1000Mbps RJ45 Ports supporting Auto Negotiation and Auto MDI/MDIX.
- 𝗚𝗶𝗴𝗮𝗯𝗶𝘁 𝘁𝗵𝗮𝘁 𝗦𝗮𝘃𝗲𝘀 𝗘𝗻𝗲𝗿𝗴𝘆: Latest innovative energy-efficient technology greatly expands your network capacity with much less power consumption and helps save money.
- 𝗥𝗲𝗹𝗶𝗮𝗯𝗹𝗲 𝗮𝗻𝗱 𝗤𝘂𝗶𝗲𝘁: IEEE 802.3X flow control provides reliable data transfer and Fanless design ensures quiet operation.
- 𝗣𝗹𝘂𝗴 𝗮𝗻𝗱 𝗣𝗹𝗮𝘆: Easy setup with no software installation or configuration needed.
- 𝗔𝗱𝘃𝗮𝗻𝗰𝗲𝗱 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗙𝗲𝗮𝘁𝘂𝗿𝗲𝘀: Prioritize your traffic and guarantee high quality of video or voice data transmission with Port-based 802.1p/DSCP QoS and IGMP Snooping.
Update SPF once, accounting for every sender
For each sending domain or subdomain, publish one SPF TXT policy. If an SPF policy already exists, incorporate the new provider’s documented authorization mechanism into that policy rather than publishing a second SPF record. A second policy can cause SPF evaluation problems. Remove a sender’s authorization only after confirming that service no longer sends for the domain.
Google’s example for Google Workspace alone is v=spf1 include:_spf.google.com ~all. It is not a complete policy for a domain whose other services also send mail. Google recommends ~all in its guidance and says an SPF record should include all sending servers or services (Google Workspace Admin Help: Set up SPF).
Rank #3
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Google’s SPF guidance describes a maximum of 10 include: tags. If many services send mail, review the complete SPF lookup behavior rather than adding authorization mechanisms indefinitely. Keep an inventory of senders and their SPF requirements so future changes do not omit a legitimate service.
Add DMARC in monitoring mode, then assess alignment
DMARC is published as a TXT record at _dmarc.<domain>. Its policy can instruct receivers how to handle mail that fails DMARC, and its reporting options can help reveal authentication results. AWS recommends beginning with p=none when deploying DMARC, reviewing reports to identify legitimate traffic, and moving toward enforcement only after you understand the mail flow (Amazon SES: Authenticating email with DMARC).
Rank #4
- Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
- Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
- Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
- Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks
Do not move directly to a stricter policy simply because the record is present. First verify that legitimate senders authenticate and that either SPF or DKIM aligns with the visible From domain. An AWS example includes a quarantine policy and a reporting destination, but use a policy appropriate to your domain and follow current provider guidance rather than copying a sample blindly.
Recommended Free Tools
Keep inbound MX changes separate
MX records control where incoming mail is delivered; SPF, DKIM, and DMARC concern outbound authentication. A SaaS provider’s request for an MX record may serve a distinct purpose and does not automatically mean your normal inbound MX records should change.
Best Value
- GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
- PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
- FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
- SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
- REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
For example, Amazon SES custom MAIL FROM uses an MX record and an SPF TXT record on the selected MAIL FROM subdomain. AWS says that subdomain must belong to a verified identity’s parent domain and should not also be used to send or receive ordinary email (Amazon SES: Setting up a custom MAIL FROM domain). Keep such a dedicated subdomain separate from the domain that routes ordinary incoming mail. Google’s explanation of MX records describes their role in routing incoming email (Google Workspace Admin Help: MX records).
Verify records and test a message
- Wait for DNS changes to become visible, then use the SaaS provider’s verification or authentication-status controls.
- Send a test message to an account where you can inspect full message headers.
- Check the authentication results for SPF and DKIM. Confirm that at least one passing method aligns with the visible From domain for DMARC.
- Review DMARC aggregate reports as they arrive and identify legitimate services that still fail authentication or alignment before tightening policy.
- Document each record’s purpose, owner, and dependent service. Remove obsolete entries only after confirming that the corresponding sender has stopped using the domain.
Google says SPF may take up to 48 hours to start working after a record is added. Other records’ visibility and provider verification times depend on DNS and the provider’s process (Google Workspace Admin Help: Set up SPF).
Gmail requirements depend on volume
Google’s Gmail sender guidance, effective February 1, 2024, says all senders to Gmail accounts must configure SPF or DKIM and meet other requirements, including valid forward and reverse DNS for sending IPs and TLS in transit. Senders exceeding 5,000 messages per day to Gmail accounts must configure SPF, DKIM, and DMARC. For direct mail, the visible From domain must align with either the SPF domain or the DKIM domain. These are requirements for delivery to Gmail accounts, not a universal rule for every recipient mailbox (Google: Email sender guidelines).
Google also says bulk senders should keep the spam rate reported in Postmaster Tools below 0.30%. Marketing and subscribed messages must support one-click unsubscribe and include a visible unsubscribe link, according to the same guidance. Authentication is one part of compliance and does not itself ensure delivery to the inbox.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

