Set Up Namecheap Private Email MX, SPF, and DKIM Records

by Fahim

You bought Namecheap Private Email, sent your first message from your shiny new custom domain, and it landed straight in the recipient’s spam folder—or bounced instantly with a 550 relay error. Namecheap sells you the mailbox, but out of the box, your DNS doesn’t have the four records Gmail, Outlook, and Apple Mail require before they’ll trust your domain.

We’ll configure the MX records so you can actually receive mail, set up a clean SPF record, extract and publish your 2048-bit DKIM key, and drop in a foundational DMARC policy. I’ll also show you how to test every single record from your terminal using dig before you start sending production emails.

Terminal screen displaying dig DNS verification commands for Namecheap Private Email records
Terminal screen displaying dig DNS verification commands for Namecheap Private Email records

1. The Four DNS Records Private Email Requires

Modern deliverability falls apart when mail servers can’t cryptographically verify that the sending machine owns the sender address. To fix this, you need four specific record types in your DNS manager:

  • MX (Mail Exchange): Tells external mail servers where to route incoming mail addressed to your domain.
  • SPF (Sender Policy Framework): A TXT record listing the specific server IPs and hostnames allowed to send mail on your domain’s behalf.
  • DKIM (DomainKeys Identified Mail): A cryptographic signature attached to the header of every outgoing email, verified against a public key in your DNS.
  • DMARC (Domain-based Message Authentication, Reporting, and Conformance): Tells receiving servers what to do when an incoming email fails SPF or DKIM verification.

If you recently moved nameservers or set up hosting elsewhere—like figuring out how to create a subdomain on Hostinger with Namecheap DNS—double-check where your zone file actually lives. If your domain points to custom nameservers (Cloudflare, AWS Route 53, or a web host), you have to add these records in that provider’s dashboard, not inside Namecheap’s BasicDNS panel.

2. Set Up Namecheap Private Email MX Records

If your domain uses Namecheap BasicDNS or Namecheap Web Hosting DNS, log into your Namecheap Dashboard, open your Domain List, hit Manage next to your domain, and click the Advanced DNS tab.

Scroll down to Mail Settings. If it’s set to “No Email Service” or “Email Forwarding”, you need to change it. Also, if you previously set up Namecheap free email forwarding to Gmail, wipe out those old forwarding aliases before changing this setting so they don’t collide.

Namecheap has a preset dropdown labeled Private Email. Picking this automatically fills in the required MX records. But if you’re on custom DNS or managing records in Cloudflare, you’ll need to enter these manually:

  • Host: @ | Value: mail.privateemail.com | Priority: 10 | TTL: Automatic (or 30 min)
  • Host: @ | Value: mail.privateemail.com | Priority: 10 | TTL: Automatic (or 30 min)

Older guides often mention a secondary server like mail2.privateemail.com. The current setup from the official Namecheap Knowledge Base simply uses mail.privateemail.com at priority 10.

Here’s how that looks in raw zone file format if you export your records:

; MX Records for Namecheap Private Email
@ 1800 IN MX 10 mail.privateemail.com.

Save your changes. At this stage, external servers know where to route your incoming mail, but you aren’t ready to send outbound mail just yet.

3. Add the Private Email SPF Record

SPF prevents attackers from spoofing your domain in the Return-Path header. Without a valid SPF record, major providers like Google and Yahoo will either reject your mail outright or dump it into the spam folder under their strict inbox policies.

In the Advanced DNS tab, click Add New Record, choose TXT Record, and fill in:

  • Type: TXT Record
  • Host: @
  • Value: v=spf1 include:spf.privateemail.com ~all
  • TTL: Automatic

The include:spf.privateemail.com directive dynamically includes Namecheap’s authorized outbound mail server IPs. The ~all flag specifies a SoftFail—receiving servers accept the email if the sending IP doesn’t match, but they flag it for closer inspection or route it to spam.

One critical mistake I see all the time: developers creating multiple separate TXT records containing v=spf1. Per RFC 7208 Section 3.2, a domain must never have more than one SPF record. If you send transactional mail from a VPS or a transactional provider alongside Private Email, combine them into a single string:

; Incorrect (breaks SPF validation completely):
; TXT @ v=spf1 include:spf.privateemail.com ~all
; TXT @ v=spf1 include:sendgrid.net ~all ; Correct (single consolidated record):
TXT @ v=spf1 include:spf.privateemail.com include:sendgrid.net ~all

Make sure you stay under the RFC limit of 10 DNS lookups. For Private Email alone, the single include:spf.privateemail.com takes just one lookup.

4. Generate and Retrieve Your DKIM Key

DKIM creates a hash of your message body and headers, signs it with a private key on Namecheap’s servers, and publishes the corresponding public key in your DNS. When Gmail receives your message, it queries your DNS for that public key to confirm the email wasn’t tampered with in transit.

Unlike shared cPanel hosts where DKIM is enabled automatically, Namecheap Private Email requires you to grab your key from the webmail admin dashboard.

  1. Log into webmail at https://privateemail.com using your admin account.
  2. Click your user avatar in the top-right corner and head to Settings.
  3. Look for the DKIM or Domain Settings tab.
  4. Select your domain. If DKIM isn’t active yet, toggle it on or click Generate DKIM Key.

Namecheap generates a selector (typically default or something like s1) and gives you a long cryptographic public key starting with v=DKIM1; k=rsa; p=....

Keep that tab open—you need to paste that exact string into your DNS next.

5. Publish the DKIM TXT Record in Namecheap DNS

Back in your Advanced DNS tab, hit Add New Record under the Host Records table.

  • Type: TXT Record
  • Host: default._domainkey (swap default for your specific selector if different)
  • Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...
  • TTL: Automatic

Here’s a subtle gotcha: don’t append your domain name to the Host field in Namecheap’s interface. If your domain is example.com, enter only default._domainkey. Namecheap appends your domain automatically. Entering default._domainkey.example.com creates a broken record at default._domainkey.example.com.example.com, and your lookups will fail.

Here’s the raw resource record equivalent:

default._domainkey 1800 IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3..."

Click the green checkmark icon to save the record.

6. Add a DMARC Record for Complete Alignment

Now that SPF and DKIM are handled, add a DMARC policy. DMARC tells receiving mail servers what to do if an incoming email claims to be from your domain but fails SPF or DKIM checks.

Add one more TXT record:

  • Type: TXT Record
  • Host: _dmarc
  • Value: v=DMARC1; p=none; sp=none; rua=mailto:admin@example.com; pct=100
  • TTL: Automatic

Swap admin@example.com for the address where you want daily aggregate XML reports sent. The p=none policy puts you in monitoring mode. It lets all emails through while generating telemetry so you can spot deliverability bugs without dropping real mail.

Once you’ve run cleanly for a couple of weeks with no false positives, bump your policy to p=quarantine or p=reject to stop spoofing entirely.

7. Verify Your Records with Terminal Commands

Don’t assume your records work just because the UI saved them. Caching delays and truncated copy-pastes happen all the time. Pop open your terminal and verify everything using dig.

First, test your MX records:

dig +short MX example.com @8.8.8.8

You should see your priority and mail host in the answer section:

10 mail.privateemail.com.

Next, query your SPF record:

dig +short TXT example.com @8.8.8.8

Check that the output returns your exact SPF string:

"v=spf1 include:spf.privateemail.com ~all"

Now verify the DKIM public key using your selector:

dig +short TXT default._domainkey.example.com @8.8.8.8

If this returns empty, your selector is wrong, the record was entered with a duplicate domain in the host field, or DNS hasn’t propagated yet. When it works, you’ll see your full public key.

Finally, inspect your DMARC record:

dig +short TXT _dmarc.example.com @8.8.8.8

For an end-to-end check, send a test email from Private Email to Mail-Tester. It evaluates your cryptographic signatures and gives you a score out of 10 with clear diagnostics.

8. The Gotcha: Third-Party DNS and Custom Nameservers

Here’s a bug that caught me out recently: a project had its domain pointed to an external web host—similar to how we point a Namecheap domain to Vercel—but the team was editing MX records inside Namecheap’s Advanced DNS page.

If your domain’s Nameservers setting in Namecheap is set to Custom DNS (pointing to Cloudflare, Vercel, or another host), any records you add in Namecheap’s Advanced DNS tab are completely ignored by resolvers.

To verify which nameservers actually own your zone, run:

whois example.com | grep -i "Name Server"

If you see anything other than dns1.registrar-servers.com and dns2.registrar-servers.com, take the MX, SPF, DKIM, and DMARC values from steps 2 through 6 and add them in that third-party provider’s dashboard instead.

9. Frequently Asked Questions

How long does it take for Namecheap Private Email DNS records to propagate?

On Namecheap BasicDNS with TTL set to Automatic, changes usually show up within 15 to 30 minutes. If your old records had a long TTL like 24 hours (86400 seconds), external resolvers might take up to a full day to drop their cached copies.

Can I send mail using third-party apps via SMTP with these records?

Yes. Once your MX, SPF, and DKIM records are resolving, you can hook up CMS plugins, web apps, or desktop clients using mail.privateemail.com on port 465 (SSL) or port 587 (TLS). Because the outgoing mail goes through Namecheap’s servers, it passes your SPF and DKIM checks automatically.

What should I do if my DKIM key string is too long for the DNS input field?

Namecheap’s dashboard handles 2048-bit keys without manual splitting. If you’re using a third-party DNS provider that enforces a 255-character TXT string limit, split the key into two quoted strings inside the same record, or ask Namecheap support for a 1024-bit key as a workaround.

Will changing my MX records affect my website traffic?

Not at all. MX records only handle inbound mail routing. Your web traffic runs entirely off your A, AAAA, and CNAME records. Updating MX, SPF, DKIM, or DMARC won’t cause any downtime for your web server.

If you ever plan to move your domain to another registrar, check our guide on how to transfer a Namecheap domain with zero DNS downtime so your web traffic and email don’t drop during the migration.

all_in_one_marketing_tool