Three DNS records that authenticate your sending domain. All three are required before real volume: SPF authorizes senders, DKIM signs messages, DMARC tells receivers what to do with failures. turgo generates the exact records to paste.
Get your records
Settings → Domains → [sending domain] → DNS Setup. turgo shows the exact SPF include, DKIM selector/value, and recommended DMARC record for your setup. Copy-paste into your DNS host.
SPF
One TXT record listing authorized senders. Critical rule: one SPF record per domain — merge turgo's include into an existing record rather than adding a second. Stay under 10 DNS lookups.
DKIM
A TXT (or CNAME) record publishing your signing key. turgo signs every message; receivers verify against your DNS. Without DKIM, DMARC can't pass and inboxing suffers immediately.
DMARC
Start at p=none with a reporting address (monitor without risk), verify a week of clean reports, then move to p=quarantine. The dashboard flags when your reports look clean enough to tighten.