Email Deliverability for Associations: Setting Up SPF, DKIM, and DMARC on Virtualmin GDPR-Compliant Without Cloud Services and Sending Newsletters Legally Securely

Learn how, as an association, to set up SPF, DKIM, and DMARC with Virtualmin to reliably deliver emails and send newsletters in a GDPR-compliant way—without cloud services.

virtualmingdprspfemailnewsletter

Why Email Deliverability Matters for Associations

Associations communicate a lot via email: invitations to meetings, minutes, newsletters, and notifications. But more and more often, these important messages end up in the spam folder. The reasons are varied: missing authentication, poor server IP reputation, or inadequate technical setup. Especially if you don't use a cloud service like Google Workspace or Microsoft 365, you have to take care of the correct configuration yourself. In this article, we'll show you how to use Virtualmin—a powerful open-source server management tool—to set up SPF, DKIM, and DMARC to improve your email deliverability while complying with the GDPR.

Basics: SPF, DKIM, and DMARC

Before we dive into practice, let's clarify the three most important email authentication methods:

  • SPF (Sender Policy Framework): Specifies which servers are allowed to send emails for your domain. This prevents spammers from abusing your domain.
  • DKIM (DomainKeys Identified Mail): Adds a digital signature to emails that the recipient can verify. This confirms the authenticity of the message.
  • DMARC (Domain-based Message Authentication, Reporting & Conformance): Builds on SPF and DKIM and defines how to handle emails that fail the checks. It also enables reports on deliverability.

The combination of these three methods significantly increases the chance that your emails land in the inbox—and not in spam.

Virtualmin: The Ideal Solution for Associations

Virtualmin is a comprehensive web hosting and server management software based on Webmin. It allows you to conveniently manage virtual servers, domains, email accounts, and much more via a web interface. For associations, Virtualmin is particularly attractive because it is free (in the Community version), can be run on your own servers, and thus keeps data sovereignty with the association—an important aspect of the GDPR.

If you don't have your own server yet, you can rent a virtual server from dezhost and install Virtualmin on it. Alternatively, we also offer web hosting with Virtualmin pre-installed.

Step-by-Step: Setting Up SPF, DKIM, and DMARC on Virtualmin

1. Configure SPF Record

Log in to Virtualmin and navigate to Email Settings > DomainKeys Identified Mail. There you can enable SPF. Alternatively, you can set the SPF record manually in your DNS management area. A typical SPF record looks like this:

v=spf1 a mx ip4:YOUR_SERVER_IP ~all

This record states that emails from the domain, the MX servers, and the specified IP address are legitimate. All others are marked as "softfail".

2. Set Up DKIM

Virtualmin can set up DKIM automatically for you. Go to Email Settings > DomainKeys Identified Mail and enable the "Enable DKIM signing" option. Virtualmin will then generate a private key and show you the public key, which you must store as a TXT record in your DNS. The record looks something like this:

mail._domainkey IN TXT ( "v=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY" )

After you save the record, Virtualmin will automatically sign all outgoing emails with DKIM.

3. Define DMARC Policy

DMARC is also configured via a TXT record in your DNS. A simple DMARC record looks like this:

_dmarc IN TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@your-domain.de"

With p=quarantine, you specify that emails that fail SPF and DKIM should be moved to the quarantine folder. rua specifies an email address to which reports are sent. This allows you to monitor deliverability and make adjustments as needed.

GDPR Compliance: Why Your Own Servers Are the Better Choice

The GDPR requires that personal data be processed securely and traceably. When using cloud services like Gmail or Outlook, data is often stored on servers outside the EU—which can be problematic. With your own server and Virtualmin, you retain full control over your data. You determine where the data is stored and who has access. You can also conclude data processing agreements (DPA) with your hosting provider, which is complicated with many cloud services.

If you send your emails and newsletters via your own server, you ensure that no data is passed on to third parties—unless you use an external newsletter service. But even here, there are GDPR-compliant solutions that run on your server.

Sending Newsletters Legally Securely

For sending newsletters, you must observe some legal requirements:

  • Double opt-in: The recipient must actively confirm the newsletter. This protects against misuse and is mandatory in the EU.
  • Unsubscribe option: Every newsletter must offer an easy way to unsubscribe (e.g., via a link).
  • Imprint: The newsletter must contain an imprint.
  • Privacy policy: Recipients must be informed about the processing of their data.

With Virtualmin, you can install, for example, PHPList or Mailtrain—both newsletter tools that run on your own server and can be operated in a GDPR-compliant manner. This way, the data stays with you and you don't have to use external services.

Don't forget to link to your privacy policy and your imprint in your newsletters.

Monitoring and Optimizing Deliverability

After setup, you should regularly monitor deliverability. DMARC reports provide information about which emails are authenticated and which are not. Use tools like Postfix (used by Virtualmin) and analyze the logs. Pay attention to the following points:

  • Reputation of your server IP: Avoid sending bulk emails from a new IP. Build up reputation slowly.
  • Correct DNS records: Regularly check whether SPF, DKIM, and DMARC are still set correctly.
  • Bounce management: Respond to undeliverability messages and remove invalid addresses from your list.

Over time, you will find that your emails are reliably delivered and the spam folder becomes less of a problem.

Conclusion: Own Email Infrastructure for Associations

Setting up SPF, DKIM, and DMARC on Virtualmin is not rocket science. With some technical understanding and the right guidance, you can significantly improve your association's email deliverability. At the same time, you remain GDPR-compliant because you don't have to use cloud services. If you need support with the setup, check out our knowledge base or contact us. We're happy to help.