Authenticate your domain when sending
For e-mails sent via OVH to be accepted by recipients, authenticate your domain with SPF, DKIM and DMARC.
SPF configuration (Sender Policy Framework)
SPF authenticates your e-mails by declaring which servers are allowed to send on behalf of your domain.
When possible, SPF is configured automatically when the email service is created. If the configuration is incorrect, go to the OVHcloud Manager, on your email service’s page, to re-trigger the automatic configuration; you can also configure SPF yourself in your domain’s DNS zone.
Example SPF record for OVH:
v=spf1 include:mx.ovh.net ~all
Recommendation: Use
~all(softfail) during the testing phase, then switch to-all(hardfail) once your configuration is validated.
DKIM configuration (DomainKeys Identified Mail)
DKIM adds a cryptographic signature to your e-mails to prove their authenticity.
When possible, DKIM is configured automatically when the email service is created. If the configuration is incorrect, go to the OVHcloud Manager, on your email service’s page, to re-trigger the automatic configuration: OVHcloud generates the keys and publishes the matching DNS record.
DMARC configuration
DMARC combines SPF and DKIM to provide a policy for handling unauthenticated e-mails.
🚧 In progress. A recommended standard DMARC configuration is being prepared. It is not proposed yet, because redirections and mailing lists can break DMARC alignment: a policy that is too strict could cause legitimate forwarded messages to be rejected.
| Policy (p) | Description |
|---|---|
| none | Monitoring only, no special handling |
| quarantine | Failed e-mails are placed in spam |
| reject | Failed e-mails are rejected |
ARC (Authenticated Received Chain)
ARC preserves authentication results (SPF, DKIM, DMARC) when a message passes through an intermediary that forwards it — typically a forward (redirection) or a mailing list. These intermediaries often alter the message or the envelope, which breaks SPF and DMARC alignment; ARC lets the final server see that authentication was valid before that hop.
Nothing to configure on your side. OVHcloud automatically adds the ARC signature on the forward and mailing-list traffic it handles.
General recommendations
- OVH’s email services are intended for individual mailbox use. Transactional and communication use is tolerated but limited in volume.
- Keep a low spam complaint ratio
- Implement a clear unsubscribe process
- Only send to recipients who have explicitly opted in — no purchased or harvested lists
- Segment your sends based on recipient engagement
- Monitor your reputation via feedback loops
- Split bulk sending