SPF, DKIM and DMARC: how to set all three up and what each one stops
Three DNS records that are usually explained as an acronym soup. Explained instead by what goes wrong when each is missing, they are straightforward — and the order to add them in is not the order they are usually listed.
Google and Yahoo both require authentication from bulk senders, so this is no longer a best practice with a deadline somewhere in the future. It is the floor, and a shop without all three is a shop whose mail is increasingly treated as suspicious.
The acronyms obscure three simple and different jobs: who may send, whether the message was altered, and what to do when the answer is no.
SPF: which servers may send as you
One TXT record on your domain listing the services allowed to send mail with your address in the envelope sender. Without it, anybody can, and receivers have nothing to check against.
- One SPF record per domain. Two records is not twice as good, it is a permanent failure. Merge them.
- The ten-lookup limit is the classic silent killer. Every
include:costs lookups and providers nest their own. Exceed ten and SPF returns permerror, which many receivers treat as a fail — and nothing in your tooling tells you. - End with
-all(hard fail) once you are confident, not?all, which asserts nothing. - SPF breaks on forwarding. That is expected, and it is exactly why DKIM exists.
DKIM: proof the message was not altered
A cryptographic signature over the headers and body, with the public key published in DNS. The receiver verifies it and knows the message genuinely came from a holder of that key and arrived unmodified.
- A selector per sending service.
campaigns._domainkey,receipts._domainkey. This lets you rotate or remove one provider without touching the others. - 2048-bit keys where your DNS provider allows the record length.
- Rotate annually, and keep the old key published for a fortnight so mail in flight still verifies.
- DKIM survives forwarding, which SPF does not. This is why a message forwarded through a mailing list can still authenticate.
DMARC: what to do when the checks fail
DMARC also adds alignment: it is not enough for SPF or DKIM to pass, the passing domain has to match the one in the visible From address. This is what actually stops somebody spoofing your brand.
- Start at
p=nonewithrua=pointing at a mailbox you will read. - Read the aggregate reports for two to four weeks. You will find sending services you had forgotten — the invoicing tool, the helpdesk, the shop plugin.
- Fix or authorise each one, then move to
p=quarantine, thenp=reject. - Go gradually with
pct=if your volume is large.
Stopping at p=none is the most common outcome and it protects nobody. It is a monitoring mode, not a destination.
The order to do it in
Not the order the acronyms are usually listed. DMARC monitoring first tells you what you actually have before you change anything.
- Publish
p=noneDMARC with a reporting address. - Read reports for a fortnight. Inventory every service sending as you.
- Fix SPF into a single record inside the lookup limit.
- Set up DKIM with a per-service selector for each legitimate sender.
- Confirm alignment in the reports, then move to quarantine, then reject.
How to verify it actually works
Do not trust a tool that checks DNS syntax. Send a real message to a real mailbox at Gmail, Outlook and one more provider, and read the raw headers. You want spf=pass, dkim=pass and dmarc=pass, with the DKIM domain aligned to your From domain.
Do this again after any change of sending provider, any DNS migration and any new tool that sends on your behalf — those are the three moments this breaks, and none of them produce an error anywhere you are looking.
Sources and further reading (4)
- RFC 7208 — Sender Policy Framework (SPF)
- RFC 6376 — DomainKeys Identified Mail (DKIM)
- RFC 7489 — DMARC
- Google — Email sender guidelines
Checked on 23 September 2026. Provider prices, mailbox rules and legal guidance change — verify anything you plan to act on.
Marketing and receipts that cannot break each other
Auralata sends campaigns from their own subdomain with their own DKIM selector, so a marketing problem can never stop an order confirmation reaching a customer — and Settings shows what each shop is actually authenticated for.