Published on · By the IT LABS PRO team
E-mail was designed at a time when everyone trusted everyone: by default, anybody can send a message that claims to come from your address. Mailbox providers such as Gmail and Outlook protect their users by checking three records published in your domain’s DNS: SPF, DKIM and DMARC. If they are missing or wrong, your legitimate e-mails look suspicious and land in spam, and fraudsters can impersonate you more easily.
Check your domain in seconds with our free SPF, DKIM and DMARC checker: every result is explained in plain language.
SPF: who is allowed to send
SPF (Sender Policy Framework) is a TXT record that lists the servers allowed to send e-mail for your domain. For example:
v=spf1 include:_spf.google.com include:servers.mcsv.net ~all
Here, Google Workspace and Mailchimp are allowed. The ending matters:
- ~all (softfail): other senders are marked as suspicious. The most common setting.
- -all (fail): other senders should be rejected. Strict, for when every sender is listed.
- +all: lets the whole internet send as you. Never use it.
Common SPF mistakes
- Two SPF records: only one is allowed; with two, SPF is invalid. Merge them.
- More than 10 DNS lookups: each “include” can trigger several lookups. Above 10, SPF is treated as invalid. Our checker counts them for you.
- A forgotten sender: your website’s contact form, your invoicing software or your newsletter tool also send e-mail in your name.
DKIM: a signature that proves the message was not altered
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each e-mail you send. The receiving server checks it against a public key published in your DNS, at an address that depends on a selector chosen by your mail service: for example google._domainkey.your-domain.com for Google Workspace, selector1 and selector2 for Microsoft 365, often default on cPanel hosts.
You do not write the DKIM key yourself: you switch DKIM on in your mail service, which gives you the record to publish. Use a 2048-bit key; 1024 bits is still accepted but weaker. To find your selector, open an e-mail you sent and look for s= in the “DKIM-Signature” header.
DMARC: the policy, and the reports
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a TXT record at _dmarc.your-domain.com. It tells receiving servers what to do with messages that fail SPF and DKIM checks, and where to send reports. For example:
v=DMARC1; p=none; rua=mailto:dmarc-reports@your-domain.com
- p=none: monitor only. You receive reports, but fraudulent e-mail is not blocked.
- p=quarantine: failing messages go to spam.
- p=reject: failing messages are refused. Maximum protection.
- rua: the address that receives the aggregate reports, which show who sends e-mail using your domain.
Since February 2024, Gmail and Yahoo require bulk senders to authenticate their e-mail with SPF and DKIM and to publish a DMARC record. Even if you only send a few messages a day, having all three is now the norm.
Reading our checker’s results
- “SPF: no record”: add one listing your senders, ending with ~all.
- “Several SPF records”: merge them into one.
- “The SPF needs more than 10 DNS lookups”: remove unused includes or ask your providers for a flatter setup.
- “DMARC: no record”: start with p=none and a report address.
- “Policy none”: fine to start; move to quarantine, then reject, once your legitimate senders pass.
- “DKIM: no key for selector”: check the selector, or switch DKIM on in your mail service and publish the key.
- “No mail server (MX)”: the domain does not receive e-mail. If it does not send any either, publish
v=spf1 -allto stop it being spoofed.
Setting them up, step by step
- List every service that sends e-mail as you: mailboxes, website forms, invoicing, CRM, newsletter, ticketing.
- Publish one SPF record that includes them all, ending with ~all.
- Switch on DKIM in each service that offers it and publish the keys.
- Publish DMARC with p=none and a report address.
- Read the reports for a few weeks (a DMARC report service makes them readable) and fix any legitimate sender that fails.
- Move to p=quarantine, then p=reject.
You publish these records in your DNS zone: in cPanel’s Zone Editor, or in your registrar’s or DNS provider’s control panel. Changes can take from a few minutes to a few hours to propagate. Our DNS lookup shows what is currently published.
Frequently asked questions
Will SPF, DKIM and DMARC guarantee my e-mails reach the inbox?
They are the foundation, not a guarantee: content, sending reputation and recipients’ engagement also count. But without them, deliverability problems are almost certain.
Can DMARC block my own e-mails?
Yes, if you move to quarantine or reject before every legitimate sender passes SPF or DKIM. That is why you start with p=none and read the reports.
My website’s contact form e-mails go to spam. Why?
The form often sends from your web server, which is not in your SPF and does not sign with DKIM. Send through your mail service with authentication (SMTP), or add the server to SPF and switch on DKIM for it.
In short
SPF lists who may send for your domain, DKIM signs your messages, and DMARC sets the policy and sends you reports. Publish all three, start DMARC in monitoring mode, then tighten it. Check your domain with our SPF, DKIM and DMARC checker, and if your website’s forms are involved, our development team can set them up properly.
Sources
- Google, “Email sender guidelines”: support.google.com
- RFC 7208 (SPF): rfc-editor.org
- RFC 6376 (DKIM): rfc-editor.org
- RFC 7489 (DMARC): rfc-editor.org
