To set up or edit your SPF record, you will need to add: include:mailcontrol.com
Edit existing SPF record
- Log in to your DNS hosting provider
- Look for a TXT containing v=spf1
- In your existing SPF record, you will append include:mailcontrol.com
- For example, if your existing record looks like v=spf1; mx; ip4:1.2.3.4; you would add the above include as follows v=spf1; mx; ip4:1.2.3.4; include:mailcontrol.com
Create a new SPF record
- Follow the instructions from our How to Create a New SPF Record Guide.
- In the Value field, enter: v=spf1 include:mailcontrol.com ~all and Save the TXT record.
Records for Subdomains
If you are creating a record for a subdomain, you will want to make sure that you specify the sub part of the domain in the Host/Name/Alias field for most DNS providers.
- Enter the sub part of the domain, for example if the subdomain is mail.mxtoolbox.com you would want to enter mail into that field.
SPF and DMARC Alignment
By default, Forcepoint-Websense will set you up for sending using one of their domains for the return-path address. This domain will NOT pass SPF Alignment. At this time, this provider does NOT provide any mechanism that will allow SPF Alignment to pass. You need to enable DKIM for this provider to ensure your email will pass DMARC Compliance.
How to Set Up/Modify DKIM for Forcepoint-Websense
You can enable DKIM for your domain from Forcepoint’s control panel after creating the required TXT record in your domain’s DNS manager. The DKIM configuration has three major steps:
1. Generate unique public DKIM Key value using default selector in Forcepoint
2. Create TXT record in your domain’s DNS Manager (domain register/DNS provider)
3. Validate selector and enable DKIM in Forcepoint
To complete the first step, follow these instructions:
1. Log in to control panel for Forcepoint using Administrator credentials
2. Click Add in DKIM Signing Keys section to open Add Signing Key page
3. Enter name for your key in Key name field
4. Select one of following options for creating your key:
- Generate key (default) to create private key (only 1024bit supported)
- Private key to enter a key you already created (paste into entry box)
5. Click OK
As a user of this outbound email provider, Forcepoint-Websense customers are afforded DKIM signing because it supports that mechanism. By utilizing Forcepoint’s self-service portal, you can manually set up DKIM at your convenience via TXT records mentioned above. Overall, this Forcepoint product provides beneficial components (e.g., DKIM signing, self-service set up with TXT records) that result in a streamlined process.