← All installation guides Email authentication and DNS

Set up cPanel Email Deliverability for an Email Sender Seal

Use cPanel Email Deliverability to find or repair DKIM and SPF, then identify the selector for VerifySeal.

CP✉
Recommended methodEmail DNS and seal setup
Email authentication setup

Configure email DNS and find the selector

  1. 1

    Open Email Deliverability

    In cPanel open Email, Email Deliverability, locate the sender domain and choose Manage. Review the DKIM and SPF status shown for that domain.

  2. 2

    Repair or copy the records

    If cPanel controls DNS, review and apply Repair. If the domain uses external nameservers, copy the Suggested DKIM and SPF names and values into the actual DNS provider instead.

  3. 3

    Find the selector

    Read the DKIM record name shown by cPanel. The text before ._domainkey is the selector. Confirm it against s= in a DKIM-Signature header from a newly sent external message.

  4. 4

    Publish DMARC carefully

    Use Zone Editor or the authoritative DNS provider to publish one DMARC TXT record at _dmarc. Start with the policy approved by the domain owner and review reports before strengthening enforcement.

  5. 5

    Run VerifySeal and add the signature

    Enter the selector, run the SPF, DKIM and DMARC check, then follow the Roundcube, Gmail, Outlook, Apple Mail or Thunderbird guide for the issued seal.

Open cPanel Email Deliverability documentation ↗
Email Sender Verification Seal

Complete authentication before installing the seal

The sender domain must continue to publish a valid SPF record, the selected DKIM key and a DMARC policy. VerifySeal automatically rechecks these records according to the administrator schedule. For High Security messages, DKIM must cover the final Message-ID, VEM header and completed body.

  • SPF authorizes sending services
  • DKIM verifies the signed message domain
  • DMARC publishes the domain policy
Testing checklist

Confirm the installation is working

01

SPF

The sender domain has one valid SPF record containing every authorized sending service.

02

DKIM

A new external message reports DKIM pass and its matching signature contains the selector entered in VerifySeal.

03

DMARC

A DMARC record is published at _dmarc and its policy matches the organization’s approved rollout.

04

VerifySeal

The customer order reports SPF, DKIM and DMARC as verified before the Email Sender Seal is issued.

Platform notes
  • A cPanel Repair button cannot change records when another provider hosts the authoritative DNS zone.