SPF, DKIM and DMARC Explained (Without the Jargon)
SPF, DKIM and DMARC are the three records that prove your email is really from you. Get them right and you remove one of the biggest reasons legitimate mail lands in spam. Here's each one in plain English.
SPF — who's allowed to send
SPF (Sender Policy Framework) is a DNS record listing which servers are authorized to send email for your domain. When a receiving server gets your message, it checks whether the sending server is on your list. If not, the message looks forged.
An SPF record starts with v=spf1, names your senders (via include: or ip4: mechanisms), and ends with a qualifier like ~all. Keep it under 10 DNS lookups or it becomes invalid.
DKIM — proof it wasn't tampered with
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your outgoing mail. Receivers fetch your public key from DNS and verify the signature, confirming the message really came from your domain and wasn't altered in transit.
DMARC — what to do on failure
DMARC ties SPF and DKIM together. It tells receivers what to do when a message fails authentication (nothing, quarantine, or reject) and where to send reports. Start with p=none to monitor, then tighten to p=quarantine and eventually p=reject as your mail passes consistently.
How to check yours
You don't have to read raw DNS by hand. Our free SPF, DKIM and DMARC checkers read your live records and tell you exactly what's missing — with a copy-paste record to fix it.
- Publish SPF so receivers know who sends for you.
- Enable DKIM so they know your mail is intact.
- Add DMARC so they know what to do — and so you get reports.
Authentication is the foundation. Once it's solid, warmup and reputation work can do the rest.