All postsAuthentication

SPF, DKIM and DMARC Explained (Without the Jargon)

June 8, 2026 6 min read

SPF, DKIM and DMARC are the three records that prove your email is really from you. Get them right and you remove one of the biggest reasons legitimate mail lands in spam. Here's each one in plain English.

SPF — who's allowed to send

SPF (Sender Policy Framework) is a DNS record listing which servers are authorized to send email for your domain. When a receiving server gets your message, it checks whether the sending server is on your list. If not, the message looks forged.

An SPF record starts with v=spf1, names your senders (via include: or ip4: mechanisms), and ends with a qualifier like ~all. Keep it under 10 DNS lookups or it becomes invalid.

DKIM — proof it wasn't tampered with

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your outgoing mail. Receivers fetch your public key from DNS and verify the signature, confirming the message really came from your domain and wasn't altered in transit.

DMARC — what to do on failure

DMARC ties SPF and DKIM together. It tells receivers what to do when a message fails authentication (nothing, quarantine, or reject) and where to send reports. Start with p=none to monitor, then tighten to p=quarantine and eventually p=reject as your mail passes consistently.

How to check yours

You don't have to read raw DNS by hand. Our free SPF, DKIM and DMARC checkers read your live records and tell you exactly what's missing — with a copy-paste record to fix it.

  • Publish SPF so receivers know who sends for you.
  • Enable DKIM so they know your mail is intact.
  • Add DMARC so they know what to do — and so you get reports.

Authentication is the foundation. Once it's solid, warmup and reputation work can do the rest.

Keep reading

Ready to land in the inbox

Connect your inbox in seconds and start building real sender reputation today. Free to start — no card required.

Secured by OAuth 2.0 · Disconnect anytime