Proofpoint SPF and DKIM Setup

Proofpoint is an American enterprise security company based in Sunnyvale, California that provides software as a service and products for inbound email security, outbound data loss prevention, social media, mobile devices, digital risk, email encryption, electronic discovery, and email archiving.

1. Proofpoint SPF Setup

Please note: To authorize Proofpoint to send emails on your behalf you will have to include it in your SPF record.

For adding Proofpoint to existing SPF record include:spf-{clusterid}


To setup DKIM on PPS, follow these steps:

2. Proofpoint DKIM Setup

  1. Navigate to Email Protection tab > Email Authentication > DKIM Signing > Keys
  2. Click Generate Key to create a key for a domain and selector. Each key must have a unique domain and a unique selector within the domain. Proofpoint-generated domain keys are 2048-bits in length.
  3. At the Generate Key Entry dialog box type or specify your domain, the selector, the scope of the key, and the policy routes. 
  4. For the policy routes, only check Disable processing for selected policy routes…
  5. Under Available scroll down and select default_inbound
  6. Click the >> to add it to Disable For Any Of:
  7. Click on Add Entry.
  8. Click View in the DNS Text Record column to see the text record for a DKIM key.
  9. A pop-up window displays the DNS text record that contains the public key. Copy the DNS text record for each domain-selector pair to your DNS servers
  10. Once the DNS record has been created, wait a few minutes to ensure the record has time to propagate.
  11. On the PPS Admin Console and click on Test to verify if the DNS record was created correctly.
  12. The feedback for the test will appear above the navigation tabs (System, Email Protection, Information Protection).
  13. Once the DNS record has been validated click the Enabled box and then click Save Changes.
  14. Turn on DKIM Signing by navigating to Email Protection tab > Email Authentication > DKIM Signing > General