Migrate authentication records
Move SPF, DKIM, and DMARC to a new platform without dual-record failures.
Objective
Migrate sending infrastructure
Move sending to a new ESP or provider without breaking authentication.
Starting state
New signing/sending hosts known; old records still live
Prerequisites
- Inventory of current SPF includes and DKIM selectors
Estimated time
1–2 hours
Difficulty
intermediate
Required access
- DNS
- Old and new ESP
Inputs
- Current SPF
- New DKIM selectors
- DMARC policy
Step-by-step instructions
- InventoryList every include, IP, and selector still required for legitimate mail.
- Publish dual-compatible recordsAdd new DKIM selectors and SPF mechanisms before removing old ones.
- Verify then pruneConfirm alignment on the new path, then remove obsolete mechanisms carefully.
Verification
- Samples pass SPF/DKIM/DMARC on the new path
Common mistakes
- Multiple SPF TXT records
- Removing old include too early
- Lower DMARC to monitoring during the migration window?
Rollback / recovery
- Restore prior SPF/DKIM values from backup
Expected outcome
Authentication follows the new infrastructure without PermError.
When to escalate
- Widespread DMARC failures after prune