Proton Mail email configuration guide

Proton Mail: SPF record for provider sending

The SPF policy evaluated for the message may not authorize Proton Mail, or duplicate records may make SPF invalid.

Problem description

A provider setup symptom may look like:

SPF record for provider sending after a provider DNS change.

Check the sending domain

What this usually means

The SPF policy evaluated for the message may not authorize Proton Mail, or duplicate records may make SPF invalid.

Fix it

  1. Use Proton’s SPF value shown for the exact custom domain. If another service also sends for the domain, merge its authorization into the same policy rather than replacing it.
  2. Use a new message header to identify the envelope MAIL FROM domain.
  3. At that exact DNS name, locate the one TXT record beginning with v=spf1.
  4. Merge the provider mechanism into the existing policy while preserving other active senders.
  5. Publish it and confirm spf=pass for the expected envelope domain and sending IP in a new message.

Common mistake

SPF evaluates the envelope sender, not necessarily the visible From domain. More than one SPF policy at the same name causes a permanent error.

What MailFixIt can check

MailFixIt can expose missing, conflicting, or invalid public SPF records. It cannot activate Proton Mail or create recipient accounts.

Use the related guides for the exact DNS or authentication warning, then repeat the same mail-path test.

Frequently asked questions

What does MailFixIt check for Proton Mail?

It checks the public SPF record and visible conflicts. The provider console and a new delivery or message header must confirm the complete result.

Should I replace every existing DNS record with the provider values?

No. Confirm the exact record type and owner, preserve unrelated legitimate services, and change only the provider-controlled record required for the intended mail route.

Related email diagnostics

Primary sources: Proton Mail official setup guidance.