Who This Topic Is For
People who drafted a record and cannot see it on the live checker yet.
Fix SPF lookup warnings, a missing DMARC report address, and the case where the live checker does not match the draft.
People who drafted a record and cannot see it on the live checker yet.
Use this checklist to make sure the workflow guidance applies cleanly to your current task.
Use this section to set the right outcome before you start the workflow.
SPF over 10 lookups or 255 characters, and DMARC without a domain or report address, show a form error. Copy draft does not copy that text.
If you typed a domain, Check this domain opens the email security checker with that domain filled in. CSP and header builders open their own checkers. The checker still reads the live site, not the draft. An empty required domain or report address shows a form error instead of copying.
Follow these steps in order for a reliable and repeatable outcome.
SPF warnings are about lookups, length, or the all qualifier. DMARC warnings are about leaving p=none.
CSP warnings mean the preset still allows inline script or style.
Add the TXT record or server header at your own host. Wait for DNS if you changed a TXT record.
On the SPF and DMARC builders, use Check this domain.
On CSP, use Check the live CSP. On headers, use Check live security headers.
A mismatch means the published value differs from the draft.
These scenarios show how the workflow looks in practice, including the result you should see.
The draft was copied, but the TXT record was added on example.com instead of _dmarc.example.com.
DMARC Copy draft was clicked with an empty domain and an empty report address. The form shows Enter a domain and A reporting address (rua) is required.
Mail is sent from Microsoft 365, but Include Microsoft 365 was off. The published SPF record does not contain include:spf.protection.outlook.com.
Use this long-form guidance to execute the workflow consistently across planning, implementation, and validation.
SPF, DMARC, CSP, and security-header builders run in the browser. Copy is the last action they take. If the DNS or header checker still shows the old record, the draft has not been published at the DNS host, web server, or Cloudflare account. Mail Watch is a separate subscription and these pages do not start it.
The default ending is ~all. A warning appears when the mechanisms you typed exceed 10 DNS lookups. Nested includes are not counted here, so a short draft can still fail after publish. A second warning appears when the text exceeds 255 characters. Shorten the record or remove unused includes. Do not switch to +all to silence a warning.
The form requires a report mailbox. The host line is _dmarc plus your domain. If the domain or mailbox is missing, Copy draft shows a form error and does not copy. Choosing quarantine or reject shows a warning because that can affect mail delivery before you have read reports.
The security-headers builder writes Nginx, Apache, or Cloudflare lines. Check live security headers reads the live response. A mismatch means the server still has the old header, not that the draft was published by the builder.
Use this checklist to confirm the workflow was completed correctly.
If something does not match expectation, check these common failure modes first.
The browser may have blocked clipboard access. Select the draft and copy it manually. If the form shows an error, fix that field first. Copy does not copy invalid text.
Add the blocked script host in Extra script hosts, publish the new header, and run the CSP checker again.
The headers checker uses the target query, not the domain query. Use Check live security headers on the builder so the live URL is filled in.
Use these links to continue your workflow without losing context.
Common questions for this topic.
The builder does not publish DNS or headers. Add the text at your DNS host or server, then run the checker.
Continue to the best next page based on where you are in your workflow.