Help

Record Builders Help

Fix SPF lookup warnings, a missing DMARC report address, and the case where the live checker does not match the draft.

Who This Topic Is For

People who drafted a record and cannot see it on the live checker yet.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • You opened one of the four builders from Tools.
  • You can publish DNS or headers, or you can send the draft to the person who can.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

Copy shows a form error when the draft is invalid

SPF over 10 lookups or 255 characters, and DMARC without a domain or report address, show a form error. Copy draft does not copy that text.

The checker link can include the domain

If you typed a domain, Check this domain opens the email security checker with that domain filled in. CSP and header builders open their own checkers. The checker still reads the live site, not the draft. An empty required domain or report address shows a form error instead of copying.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Read the warning on the builder.

    SPF warnings are about lookups, length, or the all qualifier. DMARC warnings are about leaving p=none.

    CSP warnings mean the preset still allows inline script or style.

  2. Publish outside Vulnify.

    Add the TXT record or server header at your own host. Wait for DNS if you changed a TXT record.

  3. Run the linked checker.

    On the SPF and DMARC builders, use Check this domain.

    On CSP, use Check the live CSP. On headers, use Check live security headers.

    A mismatch means the published value differs from the draft.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

Checker still shows no DMARC

The draft was copied, but the TXT record was added on example.com instead of _dmarc.example.com.

Move the TXT record to the _dmarc host shown on the builder, then run the DNS checker again.

Copy showed a form error

DMARC Copy draft was clicked with an empty domain and an empty report address. The form shows Enter a domain and A reporting address (rua) is required.

Fill both fields. Alignment can stay Relaxed and percentage can stay 100. Then copy the draft.

Microsoft 365 include was left off

Mail is sent from Microsoft 365, but Include Microsoft 365 was off. The published SPF record does not contain include:spf.protection.outlook.com.

Turn the toggle on, copy the new draft, publish it, and run Check this domain again.
Operations

Operational Playbook

Use this long-form guidance to execute the workflow consistently across planning, implementation, and validation.

The Builder Only Writes Text

SPF, DMARC, CSP, and security-header builders run in the browser. Copy is the last action they take. If the DNS or header checker still shows the old record, the draft has not been published at the DNS host, web server, or Cloudflare account. Mail Watch is a separate subscription and these pages do not start it.

Read The SPF Limits Before You Publish

The default ending is ~all. A warning appears when the mechanisms you typed exceed 10 DNS lookups. Nested includes are not counted here, so a short draft can still fail after publish. A second warning appears when the text exceeds 255 characters. Shorten the record or remove unused includes. Do not switch to +all to silence a warning.

Keep The First DMARC Policy At None

The form requires a report mailbox. The host line is _dmarc plus your domain. If the domain or mailbox is missing, Copy draft shows a form error and does not copy. Choosing quarantine or reject shows a warning because that can affect mail delivery before you have read reports.

Publish The Header Draft Before The Checker

The security-headers builder writes Nginx, Apache, or Cloudflare lines. Check live security headers reads the live response. A mismatch means the server still has the old header, not that the draft was published by the builder.

Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • Copy produced the record you meant to publish.
  • The live checker matches that text.
  • Mail Watch is still a separate choice.
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

Copy did nothing

The browser may have blocked clipboard access. Select the draft and copy it manually. If the form shows an error, fix that field first. Copy does not copy invalid text.

Common failure mode

WordPress CSP breaks the theme

Add the blocked script host in Extra script hosts, publish the new header, and run the CSP checker again.

Common failure mode

The header checker ignored the domain

The headers checker uses the target query, not the domain query. Use Check live security headers on the builder so the live URL is filled in.

Common failure mode
FAQ

Record Builders Help FAQs

Common questions for this topic.

The builder does not publish DNS or headers. Add the text at your DNS host or server, then run the checker.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.