Table of Contents
Introduction
Purpose of email authentication
If your WordPress emails land in spam, it’s usually because SPF or DKIM isn’t aligned, not because FluentSMTP is broken. Here’s the no-fluff way to set it up on common UK hosts so your domain passes checks and your invoices and resets actually arrive.
- Identify allowed sending sources
- Sign messages with a cryptographic key
- Provide policy guidance for handling unauthenticated mail
Correctly configured records reduce spam flags and improve deliverability across major providers.
Why FluentSMTP users in the UK should configure SPF and DKIM
For WordPress sites using FluentSMTP, UK hosts often run on shared or VPS environments, which can affect deliverability without clear authentication records. SPF and DKIM give receivers confidence that your emails are legitimate.
- UK hosts route mail through multiple servers; SPF lists authorized sources to prevent spoofing.
- DKIM adds a cryptographic signature to each message, boosting trust with providers like Gmail and Yahoo.
- Pairing SPF with DKIM supports DMARC policies, improving email security and inbox placement.
This guide tailors steps for UK domains and common registrars, so you can implement SPF and DKIM with FluentSMTP smoothly.

Step by Step Overview
Prepare domain and hosting details
Gather your domain, registrar, and hosting credentials. Ensure access to the DNS management panel. Note your current email sources and any SPF or DKIM records before changes.
Choose your SPF and DKIM selectors
Selectors identify the DKIM keys in DNS. Use a clear naming convention, such as s1 for the first key. Record selector names for DKIM and SPF during setup.
Generate DKIM keys and publish DNS records
Generate a 2048 bit DKIM key pair. Publish the public key as a DKIM TXT record in DNS using the chosen selector. Ensure the DNS zone includes the selector and public key entry.
Create the SPF TXT record
Draft an SPF TXT record listing all approved sending hosts. Publish it in DNS for your domain. Keep the record concise to avoid DNS lookup limits.
Configure FluentSMTP with SPF and DKIM settings
In FluentSMTP, enable SMTP sending and link the domain to the DKIM selector and SPF record. Confirm the outbound domain aligns with the From header for alignment.
Test and verify deliverability
Send tests to multiple providers. Check headers to confirm SPF pass and DKIM signing. Look for DMARC alignment reports when available.
Monitor and maintain records
Regularly verify DNS records for expiry and TTL accuracy. Watch for bounced emails or changing sending sources and update records accordingly.
Identify Your UK Hosting Requirements
UK based web hosts and DNS providers
Map where SPF and DKIM records live and who administers the zone file. UK providers range from local hosting companies to global players with UK data centres. Check if your registrar also manages DNS for your domain.
- Confirm the domain registrar and hosting plan you use in the UK
- Note whether DNS is managed separately or through the hosting control panel
- Identify any limits on TXT records or DNS lookups
Common DNS interfaces and terminology
Familiarise yourself with the DNS tools you’ll use. You’ll publish TXT records for SPF and DKIM, and you may edit MX or CNAME records during email setup.
- TXT records: used for SPF and DKIM public keys
- MX records: mail exchange records for inbound routing
- TTL: time to live, how long caches store records
- Selector: DKIM key identifier in the DNS entry
- Zone file: DNS data for a specific domain
Generate and Publish DKIM Keys
Choosing a selector for DKIM
Choose a clear, repeatable selector name such as dkim1 or s1. The selector is part of the DNS TXT record name and enables key rotation without impacting other records.
Generating public and private keys
Generate a 2048 bit RSA key pair. Store the private key securely in your hosting environment or within your email plugin. Publish the public key in DNS as the DKIM TXT record.
Publishing the DKIM TXT record in DNS
Create a TXT record named selector._domainkey.yourdomain containing the public key. Use v1, a=rsa-sha256, s=email. Ensure the record is active before sending DKIM signed messages.

Create and Publish SPF Record
List authorised sending servers
List every server that can send email for your domain. Include your hosting, transactional services, and third party apps to avoid disruption.
- Your web hosting server if it sends mail from your domain
- Any SMTP plugins or WordPress SMTP services you use
- Email marketing platforms or transactional email services
- Content delivery networks or CDN email features if applicable
Crafting the SPF TXT for UK domains
Draft a concise SPF TXT record that lists authorised hosts. Begin with v=spf1 and end with ~all or -all based on deliverability. Keep DNS lookups under limits to avoid failures.
| Element | Example | Notes |
|---|---|---|
| Version | v=spf1 | Always at the start |
| Authorized sources | ip4:203.0.113.10/32 include:mailprovider.co.uk | List each source or include |
| Mechanism | ip4, ip6, include, mx | Choose appropriate mechanisms |
| Qualifier | -all | Strict; use ~all if testing |
Configure FluentSMTP
Enable SMTP with FluentSMTP
Install and activate FluentSMTP. In Settings, select SMTP and enter the host, port, and credentials. Use a secure connection where available.
From address should align with your domain. Verify the SMTP host is reachable and the server clock is accurate.
- SMTP host: provider’s outbound server
- Port: 587 or 465
- Authentication: required
Link SPF and DKIM configuration in the plugin
Enable DKIM signing in FluentSMTP and input the selector and domain. The plugin signs messages with your DKIM private key.
Publish the SPF and DKIM records in DNS before signing. If you rotate keys, update DNS and refresh plugin settings.
Test Delivery and Troubleshoot
Send test emails and check headers
Run a controlled test to a known recipient. Check headers to confirm SPF, DKIM, and DMARC pass, and that SPF and DKIM results align with your domain setup. If any check fails, review related DNS records and plugin configuration.
Test across multiple inboxes to assess deliverability. Different providers can reveal varying signals. Note any header discrepancies for later debugging.
Common misconfigurations and fixes
- DKIM selector mismatch: ensure the selector matches the published DKIM TXT record.
- SPF misreadings: verify the TXT record lists all authorised sending servers and that the envelope from aligns with From.
- DNS propagation delays: allow time for caches to update before retesting.
- Clock drift: ensure server time is accurate to avoid signature issues.
- From domain alignment: From should match the domain used in SPF and DKIM.
Maintenance and Best Practices
Regular DNS record validation
Schedule periodic checks of SPF and DKIM TXT records to catch drift from authorised sources. DNS caching can disguise updates, so perform a fresh query from your registrar or DNS provider. Maintain a clear inventory of sending sources and review changes at least quarterly.
- Confirm SPF includes all legitimate mail sources and no unauthorized ones
- Verify DKIM selectors still point to valid public keys
- Check DMARC alignment and reporting setup
DMARC considerations and future enhancements
DMARC remains the overarching domain authentication policy. Start with a p=none policy to gain visibility, then move to quarantine or reject as deliverability stabilises. Use aggregate and forensic reports to spot misconfigurations and new sending services.
- Regularly review DMARC reports for anomalous sources
- Consider relaxing or tightening policies based on sender changes
- Plan for future enhancements like BIMI when branding requires
| Area | Best Practice | Benefit |
|---|---|---|
| SPF maintenance | List all authorised servers; monitor for new senders | Reduces spoofing and delivery failures |
| DKIM key management | Rotate keys periodically; update DNS promptly | Keeps signing resilient against key compromise |
| DMARC monitoring | Use reports; adjust policy gradually | Improves visibility and control over email authentication |
Conclusion
Configuring SPF and DKIM for FluentSMTP on UK-hosted domains is a practical step that directly improves email reliability. With correct DNS records, your messages carry verifiable provenance and resist tampering in transit.
By following these steps, you align your WordPress emails with modern authentication standards. The result is fewer deliveries landing in spam and more reaching the intended inboxes of customers and partners.
- If you run a WordPress site or use FluentSMTP, maintaining clean SPF and DKIM records pays dividends in trust and efficiency.
