SPF, DKIM and DMARC explained: stop your business e-mails landing in spam

SPF, DKIM and DMARC explained: stop your business e-mails landing in spam

Your quotes end up in spam, or someone sends fake e-mails in your company’s name? The cause is often three missing DNS records.

SPF, DKIM and DMARC explained in plain English, how to read our checker, and how to set them up step by step.

Request a quote
Services (optional)

✓ Free quote · ✓ Reply within 1 business day · ✓ 5/5 on Google (31 reviews)

Published on · By the IT LABS PRO team

E-mail was designed at a time when everyone trusted everyone: by default, anybody can send a message that claims to come from your address. Mailbox providers such as Gmail and Outlook protect their users by checking three records published in your domain’s DNS: SPF, DKIM and DMARC. If they are missing or wrong, your legitimate e-mails look suspicious and land in spam, and fraudsters can impersonate you more easily.

Check your domain in seconds with our free SPF, DKIM and DMARC checker: every result is explained in plain language.

SPF: who is allowed to send

SPF (Sender Policy Framework) is a TXT record that lists the servers allowed to send e-mail for your domain. For example:

v=spf1 include:_spf.google.com include:servers.mcsv.net ~all

Here, Google Workspace and Mailchimp are allowed. The ending matters:

Common SPF mistakes

DKIM: a signature that proves the message was not altered

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each e-mail you send. The receiving server checks it against a public key published in your DNS, at an address that depends on a selector chosen by your mail service: for example google._domainkey.your-domain.com for Google Workspace, selector1 and selector2 for Microsoft 365, often default on cPanel hosts.

You do not write the DKIM key yourself: you switch DKIM on in your mail service, which gives you the record to publish. Use a 2048-bit key; 1024 bits is still accepted but weaker. To find your selector, open an e-mail you sent and look for s= in the “DKIM-Signature” header.

DMARC: the policy, and the reports

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a TXT record at _dmarc.your-domain.com. It tells receiving servers what to do with messages that fail SPF and DKIM checks, and where to send reports. For example:

v=DMARC1; p=none; rua=mailto:dmarc-reports@your-domain.com

Since February 2024, Gmail and Yahoo require bulk senders to authenticate their e-mail with SPF and DKIM and to publish a DMARC record. Even if you only send a few messages a day, having all three is now the norm.

Reading our checker’s results

Setting them up, step by step

  1. List every service that sends e-mail as you: mailboxes, website forms, invoicing, CRM, newsletter, ticketing.
  2. Publish one SPF record that includes them all, ending with ~all.
  3. Switch on DKIM in each service that offers it and publish the keys.
  4. Publish DMARC with p=none and a report address.
  5. Read the reports for a few weeks (a DMARC report service makes them readable) and fix any legitimate sender that fails.
  6. Move to p=quarantine, then p=reject.

You publish these records in your DNS zone: in cPanel’s Zone Editor, or in your registrar’s or DNS provider’s control panel. Changes can take from a few minutes to a few hours to propagate. Our DNS lookup shows what is currently published.

Frequently asked questions

Will SPF, DKIM and DMARC guarantee my e-mails reach the inbox?

They are the foundation, not a guarantee: content, sending reputation and recipients’ engagement also count. But without them, deliverability problems are almost certain.

Can DMARC block my own e-mails?

Yes, if you move to quarantine or reject before every legitimate sender passes SPF or DKIM. That is why you start with p=none and read the reports.

My website’s contact form e-mails go to spam. Why?

The form often sends from your web server, which is not in your SPF and does not sign with DKIM. Send through your mail service with authentication (SMTP), or add the server to SPF and switch on DKIM for it.

In short

SPF lists who may send for your domain, DKIM signs your messages, and DMARC sets the policy and sends you reports. Publish all three, start DMARC in monitoring mode, then tighten it. Check your domain with our SPF, DKIM and DMARC checker, and if your website’s forms are involved, our development team can set them up properly.

Sources