AppRiver (Zix) Email Authentication Guide: SPF, DKIM, and DMARC

by

Last Updated:
5 min read
AppRiver (Zix) Email Authentication Guide: SPF, DKIM, and DMARC

Key Takeaways

  • Properly configuring SPF, DKIM, and DMARC authorizes AppRiver/Zix mail servers to send on your behalf, preventing legitimate business correspondence from landing in the spam folder.
  • For AppRiver environments utilizing outbound relay or hosted Exchange, the standard authorization mechanism is include:edgepilot.com.
  • Never publish multiple SPF records on your domain. If an SPF record already exists, simply merge include:edgepilot.com into your existing string.
  • AppRiver generates tenant-specific DKIM key pairs. You must coordinate with AppRiver support to obtain your public DNS key and enable cryptographic outbound signing.
  • Always begin your DMARC journey with a p=none monitoring policy to evaluate your mail flow and third-party services safely before enforcing stricter rules.

When your organization relies on AppRiver (now part of Zix) for cloud email security, hosted Exchange, or secure outbound relay, your messages are dispatched through AppRiver’s EdgePilot delivery infrastructure.

Without verified DNS authorization, receiving mail systems (like Google and Yahoo) cannot confirm that your domain authorized AppRiver to route messages on your behalf. Implementing an aligned SPF, DKIM, and DMARC policy cryptographically proves message authenticity, prevents domain spoofing, and secures reliable inbox placement.

Why Authenticate Your Domain for AppRiver?

If AppRiver handles outbound email relay or hosted Exchange for your domain, configuring these authentication protocols provides critical operational safeguards:

  • Bypasses Spam Filters: Receiving mail servers verify the sending server against your published records. Alignment across SPF and DKIM guarantees messages aren’t categorized as untrusted or suspicious.
  • Secures Your Brand Identity: Strict authentication prevents cybercriminals from sending fraudulent messages mimicking your executive team or domain.
  • Ensures Compliance: Meets mandatory sender requirements enacted by major mailbox providers (e.g., Google and Yahoo bulk-sender guidelines).

Steps to Configure AppRiver SPF

SPF defines which IP ranges and mail servers are permitted to send messages using your domain name. AppRiver uses the EdgePilot infrastructure for outbound routing.

Scenario A: If you DO NOT have an existing SPF record

If your domain does not have an active SPF entry in DNS, create a new TXT record in your DNS management console (e.g., Cloudflare, GoDaddy, Route 53):

  • Type: TXT
  • Host/Name: @ (or leave blank if required by your provider)
  • Value:

v=spf1 include:edgepilot.com ~all

(Note: We recommend utilizing ~all (soft fail) during initial deployment rather than -all to ensure mail delivery is not disrupted while all sending sources are inventoried).

Scenario B: If you DO have an existing SPF record (Most Common)

If your domain already sends mail through other platforms (such as Microsoft 365, Google Workspace, or Amazon SES), never publish a second SPF record. Publishing multiple SPF TXT records violates standard RFC specifications and results in an immediate PermError.

Instead, edit your existing TXT record and insert include:edgepilot.com right before the closing mechanism:

  • Before:

v=spf1 include:spf.protection.outlook.com ~all

  • After:

v=spf1 include:spf.protection.outlook.com include:edgepilot.com ~all

Pro Tip: Keep an eye on your DNS lookup count. SPF permits a maximum of 10 DNS lookups. If your organization utilizes multiple outbound marketing or transactional tools, consider utilizing PowerDMARC’s Hosted SPF / SPF Flattening to compress your lookups and prevent authentication failure. You can audit your current lookup count anytime using PowerDMARC’s SPF checker.

SPF checker

Steps to Configure DKIM for AppRiver

DKIM provides cryptographic assurance that an email message originated from your domain and remained untampered with during transit. While SPF authenticates the sending server, DKIM signs the actual message headers and body.

Step 1: Request Your DKIM Key Pair from AppRiver Support

AppRiver coordinates unique cryptographic key pairs on an account basis.

1. Contact the AppRiver Support Team (via your admin portal or at [email protected]).

2. Request custom DKIM signing for your sending domain.

3. The support team will provide you with:

  • A DKIM Public Key (and selector name) to be published in your public DNS.
  • Confirmation that your matching private key is applied on their outbound mail servers.

Step 2: Publish the DKIM Record in Your DNS

Once you receive the selector and key details, sign in to your DNS provider and add the required record:

  • Type: TXT (or CNAME, depending on whether AppRiver provides a direct public key or a CNAME delegation)
  • Host Record / Name: [selector]._domainkey (e.g., if the selector is appriver, use appriver._domainkey)
  • TXT Value:

v=DKIM1; k=rsa; p=[public-key-provided-by-appriver]

(Note for Cloudflare users: If AppRiver provides a CNAME record, ensure that the Proxy Status is set to DNS Only (Grey Cloud) to avoid authentication errors).

Step 3: Confirm Activation

Notify AppRiver support that your DNS record has been published so they can toggle outbound signing for your account. Once confirmed, use PowerDMARC’s DKIM checker to verify that your selector resolves correctly.

DKIM checker

Steps to Configure Your DMARC Record

With SPF and DKIM configured, you must implement DMARC. DMARC instructs receiving mail servers how to treat incoming messages that fail SPF or DKIM checks, providing full visibility into domain activity.

Use PowerDMARC’s free DMARC Record Generator to build your starting record.

DMARC Record Generator

1. Access your DNS settings and create a new record:

2. Save your record.

Starting with p=none allows you to monitor all email sent on behalf of your domain without rejecting or quarantining legitimate business emails while your setup is finalized.

Verify Your Setup and Troubleshoot

DNS changes can take between 15 minutes and 24–48 hours to propagate globally.

1. Run a Domain Health Check: Validate your published records using PowerDMARC’s free DMARC Record Checker.

DMARC Record Checker

2. Send a Live Test Email: Dispatch a test email through your AppRiver outbound service to an external account (e.g., Gmail).

3. Inspect Message Headers: Open the raw headers (“Show original”) and inspect the Authentication-Results field:

  • SPF: Expect spf=pass with the domain matching your Return-Path.
  • DKIM: Expect dkim=pass with the d= tag aligning with your domain.
  • DMARC: Expect dmarc=pass.

Moving to Enforcement (p=reject)

Once your PowerDMARC aggregate reports confirm that 100% of your legitimate outbound traffic via AppRiver and other tools consistently passes aligned SPF and DKIM, you can transition to enforcement:

Final Words

Ready to maximize your email security? PowerDMARC helps organizations seamlessly monitor AppRiver outbound streams, eliminate SPF lookup limits with automatic flattening, and safely transition to full DMARC enforcement.

Reach out to our team or book a PowerDMARC demo today to secure your business communications!

CTA

Latest posts by Yunes Tarada (see all)