mailify

SPF, DKIM and DMARC explained

Three DNS records decide whether your email lands in the inbox or in spam. Here's what they do, what they look like, and how to check they work.

In short

  • SPF says which servers are allowed to send email for your domain.
  • DKIM puts a digital signature on every email, so the recipient can tell it's genuine and unchanged.
  • DMARC says what the recipient should do when SPF and DKIM don't match, and sends you reports about it.

Why it matters

It's easy to send email that pretends to come from another domain. SPF, DKIM and DMARC let the recipient catch that. Since February 2024, Gmail and Yahoo require senders to have SPF or DKIM, and those who send a lot of email to have all three. Without them, your email lands in spam more often, or gets rejected.

SPF: who may send

SPF is a TXT record on your domain. It lists the servers allowed to send email with addresses on the domain:

company.com.   TXT   "v=spf1 include:_spf.provider.com -all"
  • include: adds a provider's servers. If a newsletter tool or invoicing system also sends on behalf of your domain, add an include: for each.
  • -all means every other server should be rejected. ~all is softer and asks the recipient to be suspicious.

Only one SPF record: If your domain has two records starting with v=spf1, both become invalid. Merge them into one. SPF also allows at most ten lookups, so don't add more include: entries than you need.

DKIM: the signature

With DKIM, the mail server signs every email with a secret key. The public part of the key lives in DNS, so the recipient can check the signature:

selector._domainkey.company.com.   TXT   "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."

The «selector» is a name the provider chooses, and the long text after p= is the public key. You don't write it yourself, you copy it from the provider. Some providers use CNAME records instead, so they can rotate the key without you doing anything.

DMARC: the rule and the reports

DMARC ties SPF and DKIM to the address the recipient sees in the «From» field. It lives at its own address, _dmarc:

_dmarc.company.com.   TXT   "v=DMARC1; p=none; rua=mailto:dmarc@company.com"
  • p=none means «just report». Start here.
  • p=quarantine asks the recipient to put failing email in spam.
  • p=reject asks the recipient to refuse it entirely.
  • rua= is the address that receives daily reports on who sends email in your domain's name.

For DMARC to accept an email, the domain in SPF or DKIM must match the domain in the «From» field. Read the reports for a few weeks, check that all genuine email passes, then tighten to quarantine and eventually reject.

How to check everything works

  1. Send an email from your domain to a Gmail address.
  2. Open it in Gmail, click the three dots and choose «Show original».
  3. SPF, DKIM and DMARC are listed at the top. All three should show PASS.

Common mistakes

  • Two SPF records instead of one.
  • Forgetting a system that sends on behalf of the domain, like your web shop, newsletter or invoicing software.
  • Setting DMARC to p=reject before reading the reports, so genuine email gets rejected.
  • Leaving the old provider in SPF long after switching. Remove it once it no longer sends anything for you.

Frequently asked questions

Do I need all three?

Yes. SPF and DKIM prove who sent the email, and DMARC says what should happen when they don't match. Together they give the best delivery.

What does it mean when SPF shows SOFTFAIL?

That the email came from a server not listed in SPF, and SPF ends with ~all. Add the missing server, or find out who is sending.

How long before the changes take effect?

Usually from a few minutes to a few hours, depending on the TTL. It can take up to 48 hours.

SPF, DKIM and DMARC with Mailify

When you connect your domain to Mailify, you get the records to add, and we help you check that they work.

Learn more