SPF, DKIM and DMARC Explained: Set Them Up Right
Three DNS records prove your emails are really yours. A plain explanation of each and a safe order to set them up.
SPF, DKIM and DMARC are three DNS-based checks that tell receiving servers your mail is legitimate. Together they are the foundation of deliverability.
SPF: who may send
An SPF record lists the servers allowed to send mail for your domain. A receiving server compares the sending IP with that list. Keep it to one record and stay under the 10 DNS lookup limit.
DKIM: was it altered
DKIM adds a cryptographic signature to each message. The public key sits in your DNS. If the signature checks out, the message is proven to come from your domain and to be unchanged.
DMARC: what to do on failure
DMARC ties the two together. It tells receivers what to do when SPF and DKIM fail to align with your From domain (none, quarantine or reject) and where to send reports.
A safe setup order
- Publish SPF for every service that sends your mail.
- Enable DKIM in each sending service.
- Add DMARC with p=none and a reporting address.
- Read the reports for a few weeks and fix unaligned senders.
- Move to quarantine, then reject, when reports are clean.
Check your work
Send a test to a Gmail address and read the original message headers. SPF, DKIM and DMARC should show PASS.
Clean your list before you send
Verify 100 email addresses free every month. Plans start at $19.90 a month for 25,000 verifications.