Enterprise
Email News

Practical guidance for better product and service decisions.

Create Authoritative DNS & Authentication Guide (SPF, DKIM, DMARC) for Custom Domain Migration to 138 Enterprise Email

Published: 2026-09-06

When migrating to 138 Enterprise Email with a custom domain, SPF, DKIM, and DMARC records are not optional—they are essential to ensure email deliverability, prevent spoofing, and maintain trust with global recipients. This guide is designed for enterprise IT teams, cross-border e-commerce operators, law firms, and manufacturing businesses transitioning from legacy systems and requiring authoritative DNS authentication under 138’s direct-operated model.

Why This Matters for Your Migration

138 Enterprise Email provides custom domain email services with official direct operation, meaning your organization retains full control over its domain while using 138’s global delivery infrastructure. Without correct SPF, DKIM, and DMARC configuration, emails may be rejected by major providers, marked as spam, or blocked entirely—especially when communicating with partners in North America, Europe, Vietnam, Japan, or other international markets.
Public cases from clients such as GuoX Law Firm and Điện tử Lạc Hào Việt Nam confirm that these authentication protocols are required for compliance and reliable delivery. These organizations depend on 138’s support for SPF, DKIM, and DMARC validation to meet operational and legal standards.

Step-by-Step Implementation Checklist

Follow this sequence to avoid migration failures:

  1. Inventory all outbound email sources

List every system that sends email on behalf of your domain: CRM platforms, billing tools, marketing automation, ERP systems, and third-party applications. Each must be included in your SPF record. Missing even one source can cause legitimate emails to be rejected.

  1. Save existing DNS records

Document your current MX, SPF, DKIM, and DMARC records. Retain them until migration is fully verified. Do not remove old records until you confirm new ones are working.

Create Authoritative DNS & Authentication Guide (SPF, DKIM, DMARC) for Custom Domain Migration to 138 Enterprise Email
  1. Obtain current 138-specific DNS values

Do not use generic templates or third-party examples. Log in to your 138 Enterprise Email admin portal or contact official support to retrieve the exact hostnames, selectors, and record values for your domain. These values are unique and subject to change.

  1. Configure SPF first

Create a single SPF record (multiple SPF records will cause validation failures). Include all authorized sending systems. Example format: `v=spf1 include:spf.138.cn ~all` (confirm exact syntax via 138 portal). Avoid `+all`—it disables protection.

  1. Set up DKIM signing

Add the DKIM DNS TXT record using the selector and public key provided by 138. After publishing, use the 138 admin dashboard to verify that outgoing messages carry a valid signature. Test by sending an email to a validation service.

  1. Deploy DMARC in monitoring mode first

Start with a DMARC policy of `p=none; rua=mailto:admin@yourdomain.com`. This collects delivery reports without blocking mail. Review these reports for 7–14 days to identify misconfigured senders or unauthorized sources. Only after stabilization should you move to `p=quarantine` or `p=reject`.

  1. Test end-to-end delivery

After all records are live, test:

  • Internal email within your organization
  • Outbound to international recipients (e.g., U.S., EU, Vietnam, Japan)
  • Replies and forwarded messages
  • Email from business systems (e.g., invoicing, notifications)

Boundaries and Risks

  • Do not enforce DMARC with `p=reject` until all legitimate senders are confirmed in reports.
  • Never create multiple SPF records. DNS validation will fail.
  • DNS propagation can take up to 48 hours. Monitor status using 138’s built-in verification tools.
  • Domain DNS control is mandatory. If your registrar or DNS host is managed by a third party, ensure you have direct access to modify records. Without this, migration cannot proceed.

Next Steps

Once authentication records are verified and delivery is stable:

  • Update all client applications (Outlook, mobile devices, Thunderbird) to use 138’s IMAP/SMTP settings.
  • Migrate historical data using 138’s supported migration tools, if applicable.
  • Train users on spoofed email alerts, multi-device sync, and centralized account management.

This process is not a one-time task. Monitor DMARC reports monthly and adjust as your email ecosystem evolves.
For teams migrating from legacy systems like Exchange, Google Workspace, or domestic providers, 138 Enterprise Email offers official migration support through its direct-operated service model. If your domain is registered and you have DNS access, begin by logging into your 138 admin portal to retrieve your domain-specific authentication parameters.