SPF and DKIM for Resend

Resend needs include:amazonses.com in your SPF record. Resend sends through Amazon SES: the include goes on its send subdomain (send.example.com), with an MX record there for bounces. Check your domain below once the records are in.

  • Free
  • No Sign-Up
  • Live Lookup

Examples:

SPF Checker

Resend records

SPF Includeinclude:amazonses.com
SPF Record (on Its Own)v=spf1 include:amazonses.com ~all
With Another Providerv=spf1 include:amazonses.com include:other.example ~all
DKIM Selectorsresend._domainkey (TXT)
Starter DMARC (_dmarc)v=DMARC1; p=none; rua=mailto:[email protected]

Resend sends through Amazon SES: the include goes on its send subdomain (send.example.com), with an MX record there for bounces.

DKIM: A TXT record at resend._domainkey with the key from the Resend dashboard.

A domain can have only one SPF record. If you already send through another service, add the include to your existing record rather than creating a second one, and keep the total under 10 DNS lookups.

Once SPF and DKIM pass, add a DMARC record at _dmarc with p=none and a reporting address, read the reports for a couple of weeks, then move to quarantine and reject.

Questions

What is the SPF record for Resend?
v=spf1 include:amazonses.com ~all. If you also send through other services, add their includes to the same record.
Where do I find the DKIM record for Resend?
A TXT record at resend._domainkey with the key from the Resend dashboard.
Do I need DMARC with Resend?
Yes. Gmail and Yahoo require DMARC for bulk senders, and it is what stops others sending as your domain. Start with p=none and move to reject.
How long do new SPF and DKIM records take to work?
As soon as resolvers see them, usually within minutes; at most the old record's TTL. Use the checker above to confirm.

Your customers' VMs sending spam?

Frabs spots outbound spam from any VM within seconds and stops it, before your IPs end up on a blocklist.