logo
Deliverability

SPF, DKIM and DMARC Explained: Set Them Up Right

Three DNS records prove your emails are really yours. A plain explanation of each and a safe order to set them up.

23 May 20262 min read
SPF, DKIM and DMARC Explained: Set Them Up Right

SPF, DKIM and DMARC are three DNS-based checks that tell receiving servers your mail is legitimate. Together they are the foundation of deliverability.

SPF: who may send

An SPF record lists the servers allowed to send mail for your domain. A receiving server compares the sending IP with that list. Keep it to one record and stay under the 10 DNS lookup limit.

DKIM: was it altered

DKIM adds a cryptographic signature to each message. The public key sits in your DNS. If the signature checks out, the message is proven to come from your domain and to be unchanged.

DMARC: what to do on failure

DMARC ties the two together. It tells receivers what to do when SPF and DKIM fail to align with your From domain (none, quarantine or reject) and where to send reports.

A safe setup order

  1. Publish SPF for every service that sends your mail.
  2. Enable DKIM in each sending service.
  3. Add DMARC with p=none and a reporting address.
  4. Read the reports for a few weeks and fix unaligned senders.
  5. Move to quarantine, then reject, when reports are clean.

Check your work

Send a test to a Gmail address and read the original message headers. SPF, DKIM and DMARC should show PASS.

Mailbite Editorial TeamPractical guides on email verification and deliverability.

Clean your list before you send

Verify 100 email addresses free every month. Plans start at $19.90 a month for 25,000 verifications.

Start free