Resources · Guide · Free download
EMAIL AUTHENTICATION IN PLAIN ENGLISH
SPF, DKIM and DMARC, explained for people who run a business, not a mail server.
What each record does, why the major mailbox providers require them from senders, and a ten-minute walkthrough for checking your own domain. Dated, and reviewed when provider requirements move.
Goes well with
You are probably paying for software nobody logs into.
Get the worksheetIf you would rather have this done with you than to you, this is the work I do. See services
SPF, DKIM and DMARC without the mail server
Three records that tell the world which servers may send email as your domain. Get them wrong and your invoices land in spam, or worse, somebody else sends convincing email as you. The guide explains what each record does, in what order to set them up, and what the settings actually mean, without assuming you administer a mail server. MarTech work covers the setup itself.
The order matters more than people expect
SPF and DKIM first, DMARC last, and DMARC starts in monitoring mode. Going straight to an enforcing DMARC policy is the standard way businesses accidentally block their own booking confirmations for a fortnight before anyone notices.
COMMON QUESTIONS
What do SPF, DKIM and DMARC actually do?
SPF lists which servers may send mail for your domain. DKIM signs messages so tampering is detectable. DMARC tells receiving servers what to do when a message fails those checks, and where to send reports.
Why are my emails going to spam?
Missing or misconfigured authentication is the most common cause for business senders, particularly after moving email providers or adding [a new sending tool](/resources/software-buying-questions) that was never added to your SPF record.
Do I need DMARC if I already have SPF and DKIM?
Increasingly yes. Major providers have tightened requirements for bulk senders, and without DMARC you have no visibility of who is sending as your domain or whether the other two records are working.