Skip to content

Explainer · 9 min read

SPF, DKIM, DMARCProving the mail is yours

Diagrams
02
Tools
02
Sections
06

The short answer

SPF, DKIM and DMARC are DNS-based standards that let receiving mail servers verify an email really comes from the domain it claims. SPF lists which servers may send for your domain, DKIM adds a cryptographic signature, and DMARC ties both to the visible From address and tells receivers what to do when checks fail.

Why email needs authentication at all

Email was designed in an era of trust. The basic protocol lets anyone claim to send from any address, which is why phishing emails can appear to come from your bank or your own company. Authentication standards were added later to close that gap: they let the receiving server check whether a message really comes from the domain in the From line.

For marketers, authentication matters for two reasons. It protects your brand from being impersonated, and it is now an expectation of major mailbox providers for anyone sending in volume. Unauthenticated bulk mail is increasingly likely to be filtered or rejected. Check the current sender requirements published by the major providers, as they are updated from time to time.

The three standards in plain English

StandardWhat it doesWhere it livesWhat it cannot do alone
SPFLists the servers and services allowed to send mail for a domainA TXT record on the sending domainIt checks the hidden envelope sender, not the visible From address, and can break when mail is forwarded
DKIMAdds a digital signature to each message that receivers verify with a public keyA public key published in DNS under a selectorIt proves the signing domain, which may differ from the visible From domain
DMARCRequires SPF or DKIM to pass and align with the visible From domain, sets a policy for failures and requests reportsA TXT record at _dmarc on your domainIt depends on SPF and DKIM being set up correctly first

SPF: the guest list

SPF, Sender Policy Framework, is a list of who is allowed to send mail for your domain: your own mail servers, your email marketing platform, your help desk, your billing system. Receiving servers compare the sending server against that list. The standard limits the number of DNS lookups an SPF check may trigger to ten, so adding every tool you have ever tried can break the record.

DKIM: the tamper-evident seal

DKIM, DomainKeys Identified Mail, signs each message with a private key held by the sending service. The matching public key is published in your DNS. The receiver checks the signature, which proves the message was authorised by the signing domain and not altered in transit. Each sending service typically has its own selector and key.

DMARC: the policy and the reporting

DMARC, Domain-based Message Authentication, Reporting and Conformance, connects SPF and DKIM to the address people actually see. A message passes DMARC when SPF or DKIM passes and the domain it authenticated is aligned with the From domain. DMARC also lets you tell receivers what to do with failures and ask them to send you reports.

How a receiving server checks a message

Fig. 01 · Process

The authentication check, simplified

Alignment is the step most often misunderstood. Passing SPF or DKIM is not enough unless the domain matches.

The alignment step is why a message can 'pass SPF' and still fail DMARC. If your email platform authenticates with its own domain rather than yours, SPF passes for the platform's domain, but that domain does not match your From address. The fix is usually to set up custom authentication, sometimes called a branded or custom sending domain, in the platform.

Moving DMARC to enforcement safely

DMARC has three policy levels. None means monitor only; failures are reported but delivered as normal. Quarantine asks receivers to treat failures as suspicious, usually sending them to spam. Reject asks receivers to refuse them. Enforcement, meaning quarantine or reject, is what actually protects your domain from spoofing.

Fig. 02 · Timeline

A cautious path to DMARC enforcement

Durations depend on how many systems send for you. Do not rush past monitoring.

Reading DMARC reports

Aggregate reports arrive as XML files from receiving providers, which are hard to read directly. Most teams use a DMARC reporting service or a feature in their email security tools to turn them into readable dashboards. Look for three things: which sources send as your domain, which of them pass and align, and whether there are sources you do not recognise, which may be spoofing.

Common mistakes

  • Multiple SPF records on one domain. There should be exactly one; multiple records cause failures.
  • Exceeding the SPF lookup limit by stacking includes for every service.
  • Using the platform's default domain for DKIM, so mail authenticates but does not align.
  • Leaving DMARC at p=none forever, which reports problems but protects nothing.
  • Forgetting subdomains used by other teams or tools.
  • Changing DNS without a record of what was there, making faults hard to trace.

Checklist

0/8

Email authentication setup checklist

Self-diagnostic

0/5

Where does your domain stand?

A quick status check. Your IT or email provider can confirm each answer.

  1. 01Do you have exactly one SPF record that includes all your sending services?

    If yes: Check it stays within the lookup limit as you add tools. If no: Consolidate into one record and remove services you no longer use.
  2. 02Is DKIM signing with your own domain in every sending platform?

    If yes: Your mail can align for DMARC. If no: Configure custom authentication in each platform.
  3. 03Is a DMARC record published with reports going somewhere you read?

    If yes: Review reports regularly, not just at setup. If no: Publish one at p=none with a reporting address now.
  4. 04Is your DMARC policy at quarantine or reject?

    If yes: Your domain is protected against spoofing. If no: Plan the path to enforcement once reports show legitimate mail passing.
  5. 05Is there a rule that new tools must be authenticated before sending?

    If yes: You will avoid most future failures. If no: Add it to your procurement or IT onboarding process.

Authentication is the foundation layer of email deliverability and protects your transactional emails. It is also a prerequisite for showing a brand logo next to messages in some inboxes through a standard called BIMI; check each provider's current requirements if that interests you, and see brand guidelines for logo use.

Authentication will not make anyone want your email, but without it, nobody will be allowed to decide.

Key takeaways

  1. 01SPF lists permitted senders, DKIM signs messages and DMARC ties both to the visible From address.
  2. 02A message passes DMARC only when SPF or DKIM passes and the authenticated domain aligns with the From domain.
  3. 03Start DMARC at p=none with reporting, fix every legitimate source, then move gradually to enforcement.
  4. 04Forgotten services such as billing, help desk and event tools cause most legitimate failures.
  5. 05Make authentication a required step before any new tool is allowed to send as your domain.

Frequently asked

What are SPF, DKIM and DMARC?
They are email authentication standards published in DNS. SPF lists which servers may send for your domain. DKIM adds a cryptographic signature that receivers verify with your public key. DMARC requires SPF or DKIM to pass and align with the visible From domain, and tells receivers how to handle failures.
Do I need all three: SPF, DKIM and DMARC?
Yes, for any business sending marketing or transactional email at volume. Each covers gaps in the others, and major mailbox providers increasingly expect all three from bulk senders. DMARC in particular is what protects your domain from being spoofed by others.
What does DMARC alignment mean?
Alignment means the domain verified by SPF or DKIM matches the domain in the visible From address. A message can pass SPF or DKIM for an email platform's own domain yet fail DMARC because that domain is not yours. Setting up custom authentication in each platform fixes this.
What DMARC policy should I use?
Start with p=none and reporting to see who sends as your domain. Authenticate every legitimate source, then move to quarantine and finally reject once reports show legitimate mail passing consistently. Only quarantine and reject actually protect against spoofing.
How do I check if my SPF, DKIM and DMARC are set up correctly?
Send a test email to a mailbox you control and inspect the message headers for authentication results, use a reputable DNS or email authentication checker, and read your DMARC aggregate reports. Your email platform's setup pages usually also show whether its authentication is verified.

Published by Fabulous.Media, a network of specialist marketing agencies. Updated 9 October 2026. Platform features change often; check current official documentation before acting on platform-specific detail.

Read next

Prefer a specialist to do this with you? The network has a house for every discipline in this library.

Request an Introduction