Deliverability

Why does my domain fail its DNS check?

In short

Why does Reply say my DNS records are wrong?

Almost always one of three things; a second SPF record where there must be exactly one, a DKIM selector that does not match the provider actually sending, or a change that has not propagated yet. Fix the record, then allow up to 48 hours before re-checking.

Quick fix

  1. Check you have exactly one SPF record on the domain. Two is the single most common failure, and it invalidates both.
  2. Check that your sending provider is included in that one record; if you send through Google or Microsoft, their include must be in it.
  3. Check the DKIM selector matches the provider that actually sends. A selector from an old provider fails even though the record looks present.
  4. Confirm a DMARC record exists on the domain.
  5. Re-check after propagation – up to 48 hours. Re-checking after ten minutes tells you nothing.

Didn't work? Contact Reply support; the team can check your account directly.

Symptom

A sending domain shows an authentication warning, a mailbox's health check reports a DNS problem, or deliverability degrades and the check is the first place it shows.

Most likely causes

CauseHow to recognize it
More than one SPF recordThe check fails even though an SPF record exists and looks correct. Two records is invalid by the standard, so both stop counting
The sending provider is not included in SPFSPF is valid but your provider's mail is not authorized by it. Common after switching provider
The DKIM selector does not matchA DKIM record exists but for a selector the current provider does not use – usually left over from a previous setup
The record has not propagatedEverything is correct at your DNS host and the check still fails. Propagation can take up to 48 hours
DMARC is missingSPF and DKIM pass, the check still reports the domain as incomplete
The record is on the wrong namePasted at the root when it belongs on a subdomain, or the host field includes the domain twice
You do not control the DNSThe domain is managed by an IT team or a mailbox provider, so nothing you change locally reaches it

Diagnostic checklist

  1. Count your SPF records first. One TXT record beginning v=spf1. If there are two, that alone is the answer, and merging them fixes it.
  2. Read the one SPF record you have and confirm it includes whichever provider actually sends; that is the provider your mailbox is connected through, not the one you used last year.
  3. Compare the DKIM selector with the one your provider gives you today. Providers change selectors between setups.
  4. Check the timestamp of your last change. Under 48 hours means wait, not fix.
  5. Check who owns the DNS. If a provider or an internal team manages it, your changes are requests, not edits.

Resolution

Two SPF records

Merge them into one. Combine the include: entries from both into a single record and delete the other. Two records is not "more coverage"; it is invalid, and it makes the domain unauthenticated.

The provider is missing from SPF

Add your provider's include to the single SPF record. Take the exact value from the provider's own documentation rather than copying it from another domain.

The DKIM selector is wrong

Generate DKIM at the provider that currently sends, and publish the record it gives you at the name it specifies. Remove selectors from providers you no longer use.

DMARC is missing

Publish a DMARC record on the domain. Start in a monitoring-only mode so you learn what is failing before you ask receivers to reject anything.

You do not control the DNS

Send the exact records to whoever does (your IT team, your registrar, or the provider that supplied the mailboxes) and ask them to publish them verbatim. Vague requests produce wrong records.

Nothing is wrong and it still fails

Wait out propagation. Re-check after 24 to 48 hours before changing anything else. Changing records repeatedly during propagation is the most common way to turn a small problem into a long one.

Verification

Re-run the check after propagation. It should report SPF, DKIM and DMARC as present and valid. Then send a test message to a mailbox on a different provider and confirm it arrives and is authenticated.

Prevention

  • Keep one SPF record per domain, always. Add includes to it rather than adding records.
  • Review DNS when you change email provider – old selectors and old includes are what fail later.
  • Publish DMARC early in monitoring mode, before you need it.
  • Record which team owns the DNS for each sending domain, so the next fix does not start with finding out.

FAQ

Can I have two SPF records if both are correct?

No. The standard allows exactly one. Two invalidates the domain's SPF entirely, however correct each looks.

How long until a change takes effect?

Up to 48 hours. Most changes are faster, but treat a failing re-check inside that window as inconclusive rather than as a new problem.

Do I need DMARC?

Yes, for reliable delivery to the major providers. Start in monitoring mode.

Still stuck? Contact Reply support

If these steps didn't solve the problem, the Reply support team can look at your account directly. Open the Reply Help Center and send the team a message.

To get an answer faster, include:

  • the sending domain and which provider sends its mail
  • your current SPF, DKIM and DMARC records as published
  • when you last changed them
  • who controls the domain's DNS

Don't send passwords, API keys, or access tokens.

Build with Reply