SPF, DKIM & DMARC for Wix.
Wix authenticates your sending domain through CNAME records, not by having you paste a shared SPF line. The flow lives inside Wix Email Marketing (formerly part of Ascend by Wix): you add a sender address, click "Authenticate this domain," and Wix shows five CNAME records that delegate DKIM signing and the Return-Path back to its email backend (which runs on SendGrid). Once those CNAMEs resolve, Wix can send campaigns as your domain, DKIM aligns to you, and SPF passes on the sending subdomain — all without an "include:wix" entry ever touching your root SPF. The nuance most guides miss: this only covers Wix Email Marketing. Your Wix mailbox and Wix's automated site emails authenticate differently, and one of the five records — the auto-DMARC CNAME (CNAME 5) — is a trap you should skip.
Why authenticate Wix?
Authenticating your Wix sending domain is what decides whether campaigns reach the inbox at all. Since February 2024, Gmail and Yahoo require every sender to pass SPF or DKIM with a valid, aligned From address, and any bulk sender (roughly 5,000+ messages a day to Gmail/Yahoo consumer addresses) must additionally pass DKIM and publish a DMARC policy — Microsoft began enforcing similar rules for high-volume senders in 2025. Until you authenticate, Wix sends your campaigns on its own shared domain from a pooled IP: recipients see mail that isn't aligned to you, DMARC can't pass, and your reputation is mixed in with every other unauthenticated Wix sender. Wix itself states in its deliverability guidance that, as of February 2024, business-email users "must set up SPF," and DKIM plus DMARC once you cross the bulk threshold. Completing domain authentication moves that reputation onto your own domain, makes DKIM align to your From address, and clears the Gmail/Yahoo/Microsoft gate in one pass.
The SPF reality for Wix
Wix is a CNAME-based authentication provider, so for Wix Email Marketing there is NO "include:" mechanism to add to your root SPF — nothing "Wix" goes into your v=spf1 line at all. When you authenticate the domain, Wix hands you a Return-Path/mail CNAME (its "CNAME 3") that points a sending subdomain into its SendGrid backend. Because that subdomain resolves into SendGrid's own SPF-authorized space, SPF is satisfied there automatically, and DMARC passes via relaxed SPF alignment (the Return-Path subdomain shares your organizational domain with the From address) — you never publish a Wix SPF include on your root domain. The only time a shared SPF include enters the picture on a Wix domain is if you ALSO run a Wix mailbox: Wix Business Email is powered by Google Workspace, so that path uses include:_spf.google.com — a Google include, not a Wix one. And Wix's automated site emails (order confirmations, form notifications, automation triggers) send from Wix's own domain on shared infrastructure; those can't be SPF-aligned to your domain, so authenticating your marketing domain does not retroactively cover them. Bottom line: Email Marketing = CNAME delegation with zero root-SPF changes; a Wix mailbox = Google Workspace records; automated site mail = Wix's own domain, outside your control.
Step by step
- 1
Decide which Wix email you're authenticating
Wix has three separate email streams and each authenticates differently. This guide covers Wix Email Marketing campaigns (the CNAME flow below). Your Wix mailbox is a separate product powered by Google Workspace and uses Google's MX, SPF include, and DKIM instead. Automated site emails (order confirmations, form notifications, automations) send from Wix's own domain and can't be aligned to yours. Sort out which one you actually send from before touching DNS.
- 2
Open the sender authentication screen
In your Wix dashboard, open Email Marketing. On the right, under Sender Details, click Manage Senders (or Add Sender if you have none yet). This is where custom sending domains are added and authenticated.
- 3
Add and confirm your sender address
Enter the From address you'll send campaigns from (for example hello@yourdomain.com) and confirm it with the code Wix emails to that mailbox. Until the address is confirmed, the domain shows as 'Not authenticated' and the CNAME records won't be offered.
- 4
Reveal the five CNAME records
With the sender confirmed, click Authenticate this domain. Wix opens a list of five CNAME records: three DKIM key delegations (its CNAME 1, 2 and 4), one Return-Path/mail link into Wix's SendGrid backend (CNAME 3), and an optional auto-DMARC CNAME (CNAME 5). Keep this screen open to copy the exact Host and Points-to values — they're generated per account.
- 5
Add the CNAMEs at your DNS host
In your DNS provider, add each record as type CNAME, pasting Wix's Host value into the host/name field and the Points-to value into the target/value field. Copy only the first part of the Host (the prefix without your domain) — most DNS panels append your domain automatically. If your domain uses Wix nameservers, add them under Wix Domains > your domain > DNS Records instead; if the domain is pointed to another registrar, add them there.
- 6
Skip Wix's DMARC CNAME and publish your own
Wix's CNAME 5 auto-creates a DMARC record for you — but with no rua reporting address, giving you compliance-on-paper and zero visibility into who's sending as you. Instead of adding CNAME 5, publish your own TXT record at _dmarc with a reporting address: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. Never add both — DNS forbids a CNAME alongside any other record at the same name, so a CNAME and a TXT at _dmarc collide and break DMARC.
- 7
Verify inside Wix
Back on the authentication screen, click Verify (or refresh the Domain status). DNS usually resolves within a few hours but Wix allows up to 24-48 hours. When every record is found the status flips to 'Authenticated.' If it stalls, re-check that you pasted only the Host prefix and that no record has a doubled domain suffix.
- 8
Confirm alignment independently
Don't trust the Wix badge alone — send a test campaign to a Gmail account, open 'Show original,' and confirm SPF and DKIM both show PASS and that the DKIM d= domain and the Return-Path are your domain (aligned), not a bare sendgrid.net address. Then run your domain through an external checker so you know the records resolve on the public internet.
Records to add
Wix generates the exact values in its setup wizard — these show the shape of what you'll add at your DNS host.
| Type | Host | Value |
|---|---|---|
| CNAME | s1._domainkey | s1.domainkey.u1234567.wl123.sendgrid.netDKIM key #1 (Wix's CNAME 1). Delegates a DKIM public key to Wix's SendGrid backend so campaigns are DKIM-signed with d=yourdomain and align to your From address. Host prefix and target are generated per account — copy the exact values Wix shows you. |
| CNAME | s2._domainkey | s2.domainkey.u1234567.wl123.sendgrid.netDKIM key #2 (CNAME 2). Wix also hands you a third DKIM CNAME (its CNAME 4, same s#._domainkey pattern) — add all three. The keys live behind the CNAMEs, so Wix/SendGrid can rotate them without you ever republishing DNS. Illustrative selector/target — use the values in the dashboard. |
| CNAME | em1234 | u1234567.wl123.sendgrid.netReturn-Path / mail link (CNAME 3). Points a sending subdomain of your domain into Wix's SendGrid servers; because that subdomain resolves into SendGrid's SPF-authorized space, SPF passes there and aligns to your domain under relaxed alignment. This is why there is NO include: line to add to your root SPF. |
| CNAME | _dmarc | (Wix-generated DMARC target — shown in dashboard)Wix's optional CNAME 5. Delegates DMARC to a Wix/SendGrid-managed record with no rua reporting address, so you get zero visibility into who sends as you. Recommended: do NOT add this — publish the self-managed TXT below instead. A CNAME here also blocks you from adding your own _dmarc TXT. |
| TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comRecommended self-managed DMARC in place of Wix's CNAME 5, so aggregate reports actually reach you. Never publish both a CNAME and a TXT at _dmarc — DNS forbids a CNAME alongside any other record at the same name, so they collide. Start at p=none, read the reports, then tighten to quarantine/reject. |
Keep exactly one SPF (v=spf1) TXT record on your root domain — merge every sender into it. Two SPF records is itself an error.
The 10-lookup budget
SPF is capped at a hard 10 DNS lookups — go over and it returns a permerror and stops validating everywhere. Here's what Wix's setup costs against that budget.
Wix's recommended setup adds 0 lookups — all 10 stay free for the senders that do need an include.
DKIM
DKIM is the heart of Wix's authentication and it's fully CNAME-delegated. When you authenticate the domain, Wix gives you three DKIM CNAME records (its CNAME 1, 2 and 4) at selector hosts like s1._domainkey and s2._domainkey that point into its SendGrid backend (targets such as s1.domainkey.u1234567.wl123.sendgrid.net). Because the key lives behind a CNAME rather than a TXT record you paste, Wix/SendGrid can rotate the underlying public key on their side without you ever editing DNS again — you just publish the pointers once, and the signature's d= is your own domain so it aligns. There's nothing to generate on your end: don't invent a p= value, and don't convert these to TXT records. Copy each Host prefix and Points-to target exactly. If you send from a Wix mailbox rather than Email Marketing, DKIM is Google Workspace's instead — a google selector turned on in the Google admin console — which is a completely separate key from the SendGrid ones above.
DMARC
DMARC is the one place to be deliberate on Wix. Wix offers to set DMARC up for you automatically through its fifth CNAME (CNAME 5), but that shortcut delegates to a Wix/SendGrid-managed record with no rua reporting address — it satisfies 'a DMARC record exists' for the Gmail/Yahoo checkbox while giving you no enforcement and, crucially, no reports about who is sending as your domain. Skip it. Instead publish your own TXT record at host _dmarc: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. Never publish both Wix's DMARC CNAME and your own _dmarc TXT — DNS does not allow a CNAME to coexist with any other record type at the same name, so they collide and break DMARC resolution. Start at p=none so aggregate reports flow in without affecting delivery, confirm every legitimate stream (Email Marketing, your mailbox, any other ESP) is aligning, then step up to p=quarantine and finally p=reject. Build the record with a generator so the tags are valid, and never jump straight to reject before the monitoring phase.
Check it actually worked
Confirm authentication in two places, not one. First, the Wix screen: after DNS propagates (a few hours, up to 24-48), refresh the Domain status under Sender Details until it reads 'Authenticated' — that means Wix found all its CNAMEs. Second, and more important, verify real alignment: send a test campaign to a Gmail address, open the message, choose 'Show original,' and check that SPF = PASS, DKIM = PASS, and that the DKIM d= domain and the Return-Path both show your domain (aligned) rather than a bare sendgrid.net address. Then run your domain through an external SPF/DKIM/DMARC checker to confirm the records resolve publicly and your _dmarc is the self-managed TXT, not an accidental Wix CNAME. Green in Wix plus PASS-and-aligned in the headers is the real finish line.
Common gotchas
- DNS setup
Wix's auto-DMARC (CNAME 5) is a trap: it publishes a policy with no rua address, so you get compliance-on-paper and zero visibility. Skip it and publish your own _dmarc TXT with a reporting mailbox instead.
- DNS setup
Never put both a CNAME and a TXT at _dmarc. If you added Wix's DMARC CNAME 5 and also want your own policy, delete the CNAME first — DNS forbids a CNAME beside any other record at the same name, so the collision breaks DMARC lookups entirely.
- Breaks auth
Email Marketing and your Wix mailbox are different products. Authenticating campaigns (SendGrid CNAMEs) does nothing for your mailbox, which is Google Workspace and needs Google's MX, SPF include (include:_spf.google.com), and DKIM — and vice versa.
- Coverage
Automated site emails (order confirmations, form/contact notifications, automations) send from Wix's own domain on shared infrastructure and can't be aligned to yours. Don't expect domain authentication to fix their From address or DMARC alignment.
- Coverage
Enter only the Host prefix, not the full domain. Wix shows the whole hostname but most DNS panels append your domain automatically — pasting the full FQDN creates a broken record like s1._domainkey.yourdomain.com.yourdomain.com.
- DNS setup
Check whether your domain is connected to Wix (Wix nameservers) or just pointed to another registrar. If it's pointed, add the CNAMEs at that registrar — records added inside Wix are ignored when Wix isn't your authoritative DNS host.
- DNS setup
These are CNAMEs, not TXT records. Don't try to 'read' a DKIM public key out of them or paste them into an SPF include — there is no Wix SPF include, and the keys are delegated, not published by you.
- DNS setup
A bare Wix auto-DMARC is not enough once you cross the bulk threshold (~5,000 messages/day to Gmail/Yahoo). The requirement is a working, monitored DMARC policy with DKIM alignment — self-manage the _dmarc TXT so you can actually see the reports and tighten the policy.
Build your SPF record
Wix doesn't need an SPF include: on your root domain — use the generator to assemble one clean record for your other senders, and keep it to a single line.
Sending sources
Search for each platform you send email through and tick it.
Search for your email platform above, or .
This domain's own servers
Authorize the domain itself, if it sends mail directly (not through a platform above).
Other senders & IPs
Anything not in the list — another provider's SPF host, or specific IP addresses.
We add the include: prefix — enter the hostname your provider documents.
Policy for everyone else
What receivers should do with mail from any server not listed above (the all mechanism).
No senders yet, so every message would hit the ~all policy. Add the platforms you send through in step 1.
- Publish it as a TXT record at your root domain — host @ (the bare domain), value the full string above.
- Keep only one SPF record per domain. Merge every sending source into this single line — a second TXT record starting v=spf1 makes both invalid.
- Stay at or under 10 DNS lookups. Each include:, a and mx counts, and an include can trigger more lookups inside itself — ip4: and ip6: are free.
Authentication published? The next step is sending to a clean, verified list.
Verify a listWix SPF — FAQ
Related reading
Once it's published, confirm everything resolves with the domain health check, then read who's sending as you with the DMARC report analyzer. Browse all sending sources in the generator. Authentication is only half of deliverability, though — a listed sending IP or domain still lands you in spam no matter how clean your SPF is, so it's worth watching the blacklists with blacklist monitoring.
Authenticated — now keep the list clean
Passing SPF, DKIM, and DMARC gets you to the inbox; a clean list keeps you there. Verify yours — start free with 100 credits, no card required.