Cloudflare

Set up DMARC on Cloudflare with your AI assistant

Palisade gives your assistant the exact records for the domain, tells it Cloudflare is the host answering for that zone, and confirms against live DNS once they are published. You approve every record, and no Cloudflare API token ever reaches Palisade.

Manual setup

Adding the DMARC record in Cloudflare

The record is one TXT entry at _dmarc. This is the short version of the click path, and it is worth knowing even if you never use it again.

1

Confirm Cloudflare answers for the zone

The DNS tab only edits records Cloudflare serves. On a full setup the domain's nameservers point at Cloudflare; on a partial setup another host is still authoritative and the record has to go there instead.

2

Add the TXT record

Open DNS, then Records, then Add record. Choose TXT, set the name to _dmarc, and paste the policy into Content. Proxy status is an A, AAAA and CNAME setting, so a TXT record has none.

3

Or let Cloudflare manage the record

DMARC Management, under Email, can publish and maintain the record for an apex domain that uses Cloudflare DNS, and adds its own aggregate-report address to it.

4

Save, then check what resolves

Saving proves the record exists in the zone. It does not prove a sender passes DMARC, which is what the reports tell you over the following days.

Cloudflare dashboard, your domain, DNS, Records, Add record is the path as Cloudflare labels it today. Provider dashboards get renamed, so the current official reference is Cloudflare: create DNS records. For the full walkthrough, including what to check before you move the policy past monitoring, read Cloudflare DMARC: how to add a DMARC record.

Assistant setup

The same setup, without the dashboard

Connect Palisade's MCP server to Claude, ChatGPT, Copilot, or any MCP client, and the record values stop being something you transcribe.

1

Add the domain

Your assistant calls add_domain and the domain starts being monitored. Adding a domain is free and never gated, so a whole portfolio can go in before anything is set up.

2

Get the exact records

get_dns_records returns each record to publish with its host, type, value, recommended TTL and whether it needs creating, replacing or deleting. It also reports the DNS host resolved from the domain's live nameservers, so your assistant is told this zone is on Cloudflare rather than guessing from the registrar.

3

Publish them where the zone lives

The Palisade MCP server has no tool that writes a record at Cloudflare. It hands your assistant the values, and your assistant publishes them with the DNS tooling it already has. In the Palisade app, Smart DNS Deployment is the other route: you authorise the connection in the provider's own window and approve each record, and Palisade writes it into your own zone.

4

Verify against live DNS

verify_domain re-checks from outside your account, so a record saved into the wrong zone or still inside its TTL shows as unverified rather than done. Setup is finished when every required record verifies.

Connecting takes one step and no API key to create first. The setup for each client is on the Palisade MCP server page.

At a glance

What Palisade knows about your Cloudflare zone

The question worth asking before you connect anything, answered first.

Cloudflare credentialsNever requested, never stored, never seen. Palisade has no field for a Cloudflare API token or password.
How the provider is identifiedFrom the domain's live NS records. Cloudflare is recognised by nameservers ending in ns.cloudflare.com, and that lookup is public information about your domain rather than access to your account. A domain on Cloudflare's partial (CNAME) setup keeps its old nameservers, so detection reports whoever still answers for the zone rather than Cloudflare.
What the MCP server can changeNothing in your zone. No tool in the server writes a record at an external provider; it returns the values and your own tooling publishes them.
If you want Palisade to publish insteadSmart DNS Deployment, in the Palisade app, covers 64 providers. You authorise the connection in the provider's own window, the access covers email-authentication records only, you approve each record, and you can disconnect at any time.
Your registrar and nameserversUnchanged. Nothing is transferred and Palisade never takes over the zone.
In the app

What publishing to Cloudflare looks like

You approve the exact record. The connection is authorised in the provider's own window, and nothing else in the zone is touched.

  1. Setting up acme-corp.com: its email-authentication records are unconfigured, and instead of setting them up by hand you choose Configure.
  2. Palisade recognises Cloudflare as the provider answering for the domain, and you authorise the connection in Cloudflare’s own window. No password is shared with Palisade, and access is scoped to email-authentication records only.
  3. The exact records are shown as a before-and-after diff: the SPF value gaining a sender, plus new DKIM and DMARC records. Nothing is published until you press Approve and publish.
  4. Every record is live and verified in your own zone, monitoring stays on, and nothing else in the zone was touched.
Monitoring

Publishing DMARC is the start, not the finish

A published record proves the policy exists. Whether your mail actually authenticates is a question the record UI never answers.

Drift, including the record you just published

A record that is edited, overwritten by another tool, or dropped during a Cloudflare change stops matching what Palisade generated. Monitoring keeps checking live DNS after the write, so a change that silently did not take becomes a task instead of something you learn from a bounce weeks later.

Senders that are failing authentication

Aggregate reports name the services sending as your domain and show which of them pass SPF and DKIM with alignment. A new marketing platform someone signed up for without telling you shows up here first.

Remediation as tasks, with the fix already drafted

Palisade opens a task for each failing source and record issue, ordered by priority, and a task can carry provider-specific instructions for the sender involved. The agent investigates every sender, drafts every fix, and proposes each policy step. You approve before anything ships.

Readiness to tighten the policy

Moving from p=none toward quarantine and then reject is safe only once the legitimate senders are accounted for. Palisade tracks when that is true for the domain and proposes the step rather than taking it.

Questions

Cloudflare DMARC: FAQ

Set up DMARC on Cloudflare from the assistant you already use

1 domain free up to 1,000 emails/month