# MailBaby Cloudflare DNS: 3 Records (SPF, DKIM, DMARC)

Source: https://srvscripts.com/guides/mailbaby-cloudflare-dns-spf-dkim-dmarc/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

When a customer’s DNS lives at Cloudflare, the panel’s automatic zone updates never reach the live records, so every mail authentication record has to be entered by hand. That is a frequent source of tickets after a move to MailBaby: the relay is configured, Exim is authenticating, and mail still lands in spam because the SPF record at Cloudflare was never updated. This guide lists every record a MailBaby-relayed domain needs and how to enter each one in the Cloudflare dashboard or through the API.

In short: A MailBaby-relayed domain needs four TXT records in Cloudflare: an SPF record on @ reading v=spf1 a mx include:spf-c.mailbaby.net ip4:SERVER_IP ~all, an optional _mailbaby record with v=1 user=mbXXXXX, the panel’s DKIM key on…

**Short answer:** A MailBaby-relayed domain needs four TXT records in Cloudflare: an SPF record on `@` reading `v=spf1 a mx include:spf-c.mailbaby.net ip4:SERVER_IP ~all`, an optional `_mailbaby` record with `v=1 user=mbXXXXX`, the panel’s DKIM key on `default._domainkey` (cPanel) or `x._domainkey` (DirectAdmin), and a `_dmarc` record starting at `p=none`. Enter the DKIM value without the quotes and escapes from the panel’s zone file, keep the MX target’s A record set to DNS only, and confirm each record with `dig` against 1.1.1.1.

## Gather the values from the panel

Before opening Cloudflare, collect what the server expects. On cPanel:

```
whmapi1 fetch_dkim_private_key domain=example.com >/dev/null && \
uapi --user=USER EmailAuth fetch_dkim_records domain=example.com
```

This prints the `default._domainkey` name and the `v=DKIM1; k=rsa; p=...` value. On DirectAdmin, the public key is in `/etc/virtual/example.com/dkim.public.key` and the selector is `x`. Note the server’s public IP; it must remain authorised in SPF because MailBaby checks the origin against the domain’s record. Record also the MailBaby username, `mb12345` in the examples below.

## SPF

Create or edit a TXT record on the apex name. Cloudflare’s editor labels the name field; enter `@` for the apex.

- Type: TXT

- Name: `@`

- Content: `v=spf1 a mx include:spf-c.mailbaby.net ip4:203.0.113.10 ~all`

- TTL: Auto

Replace the IP with the server’s. If the site is proxied through Cloudflare, the `a` mechanism resolves to Cloudflare’s edge IPs rather than the server, so the explicit `ip4:` is essential. There must be exactly one TXT record on the apex that begins `v=spf1`; if the customer already has one for a marketing tool, edit it to add the include rather than creating a second record. Delete any legacy record of type SPF, which resolvers ignore. The lookup-count and long-record considerations are in [the SPF and verification guide](/guides/mailbaby-spf-record-domain-verification/).

The `_mailbaby` ownership record is optional for SMTP relay but required when the domain will be used with the REST API or must be tied to a specific account:

- Type: TXT

- Name: `_mailbaby`

- Content: `v=1 user=mb12345`

Cloudflare appends the zone name automatically, so the resulting record is `_mailbaby.example.com`.

## DKIM

- Type: TXT

- Name: `default._domainkey` (cPanel) or `x._domainkey` (DirectAdmin)

- Content: `v=DKIM1; k=rsa; p=MIIBIjANBgkq...` exactly as the panel printed it, on one line

Cloudflare accepts values longer than 255 characters in a single field and splits them into strings internally, so a 2048-bit key pastes in without manual quoting. Remove any quotation marks or line breaks the panel’s output wrapped around the value. Keep the panel’s selector name; renaming it means the signature Exim applies will point at a record that does not exist.

MailBaby passes your DKIM signature through and only adds its own if yours is absent, so this record is what stops the “via mailbaby.net” label. The reasoning is in [the transport signing guide](/guides/mailbaby-dkim-transport-signing/).

## DMARC

- Type: TXT

- Name: `_dmarc`

- Content: `v=DMARC1; p=none; rua=mailto:dmarc@example.com; adkim=r; aspf=r; pct=100`

Start with `p=none` and read the aggregate reports for two weeks. Move to `p=quarantine` only when the reports show every legitimate source aligned, and to `p=reject` after that. With MailBaby, SPF alignment holds for direct mail because the envelope sender is on the domain, but forwarded mail rewritten by SRS aligns only through DKIM, so make sure DKIM is signing before tightening the policy.

## Proxy status and MX

Mail records are never proxied; TXT records have no proxy option, but the MX target’s A record must be set to DNS only (grey cloud). A proxied `mail.example.com` breaks inbound mail and confuses the `a` mechanism. Check the MX target while you are in the zone. The interaction between Cloudflare’s proxy and a cPanel server, including real visitor IPs, is covered in [our Cloudflare cPanel guide](/guides/cloudflare-cpanel-dns-proxy-real-ip/).

## Doing it with the API

For a provider managing many zones, the Cloudflare API is faster than the dashboard. Creating the SPF record:

```
curl -s -X POST "https://api.cloudflare.com/client/v4/zones/ZONE_ID/dns_records" \
  -H "Authorization: Bearer CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  --data '{"type":"TXT","name":"example.com","content":"v=spf1 a mx include:spf-c.mailbaby.net ip4:203.0.113.10 ~all","ttl":1}'
```

Use a token scoped to DNS edit on the specific zones rather than a global key, and store it outside any customer-accessible path.

## Verify

Query the live records through a public resolver rather than the server, which may cache stale answers:

```
dig +short TXT example.com @1.1.1.1
dig +short TXT _mailbaby.example.com @1.1.1.1
dig +short TXT default._domainkey.example.com @1.1.1.1
dig +short TXT _dmarc.example.com @1.1.1.1
```

Each should return exactly one string of the expected form. Then send a message through the relay and read `Authentication-Results:` at the destination for `spf=pass`, `dkim=pass header.d=example.com` and `dmarc=pass`. The common pitfall is pasting the DKIM value with the surrounding quotes and the `\"` escapes that the panel’s zone file uses; Cloudflare stores them literally, the record looks fine in the dashboard, and DKIM fails with a key syntax error at every recipient.

## MailBaby Cloudflare DNS at a glance

**Official documentation:** [Cloudflare developer docs](https://developers.cloudflare.com/), [RFC 7489 (DMARC)](https://www.rfc-editor.org/rfc/rfc7489), [RFC 7208 (SPF)](https://www.rfc-editor.org/rfc/rfc7208).

**Related guides:** [Cloudflare in front of cPanel: DNS, proxy mode and real visitor IPs done right](https://srvscripts.com/guides/cloudflare-cpanel-dns-proxy-real-ip/) · [MailBaby SPF and domain verification: the spf-c include vs the _mailbaby TXT record](https://srvscripts.com/guides/mailbaby-spf-record-domain-verification/) · [Issuing wildcard certificates with DNS challenges on DirectAdmin](https://srvscripts.com/guides/directadmin-wildcard-certificate-dns/).

## Frequently asked questions

### Do I still need the server IP in SPF if MailBaby is the relay?

Yes. MailBaby checks that the origin server is authorised for the domain, and when the site is proxied through Cloudflare the `a` mechanism resolves to Cloudflare’s edge rather than your server, so an explicit `ip4:` for the server’s public address must stay in the record alongside `include:spf-c.mailbaby.net`.

### Why does my DKIM record fail in Cloudflare when it looks correct?

Almost always because the value was pasted with the surrounding quotes and `\"` escapes from the panel’s zone file. Cloudflare stores them literally, which breaks the key syntax at every recipient. Re-enter the `v=DKIM1; k=rsa; p=...` value as one unquoted line; Cloudflare handles the 255-character splitting itself.

### Should the MX record be proxied in Cloudflare?

No. TXT records have no proxy option, but the hostname the MX points at must be set to DNS only (grey cloud). A proxied `mail.example.com` breaks inbound SMTP and makes the `a` mechanism in SPF point at Cloudflare’s addresses.
