SPF, DKIM and DMARC: three complementary protections
When you send an e-mail, the recipient’s mail service (Gmail, Outlook, Yahoo…) checks that it really comes from your domain, using three DNS records. Without them, your quotes and invoices may land in spam, and fraudsters can send messages that appear to come from your company. Since 2024, Gmail and Yahoo require SPF, DKIM and DMARC from senders who send a lot of messages.
- SPF (Sender Policy Framework) lists the servers allowed to send e-mail for your domain: your host, Google Workspace, Microsoft 365, your newsletter tool… Only one SPF record is allowed, and it must not need more than 10 DNS lookups.
- DKIM (DomainKeys Identified Mail) adds a digital signature to each message. The public key is published in DNS under a “selector”; recipients use it to check that the message has not been altered.
- DMARC says what to do with messages that fail SPF and DKIM (let them through, send them to spam or reject them) and where to send reports.
Finding your DKIM selector
Open an e-mail you sent from your business address, show the original message (“Show original” in Gmail, “View source” elsewhere) and look for the DKIM-Signature line: the value after s= is the selector. The most common are “google” for Google Workspace, “selector1” and “selector2” for Microsoft 365, and “default” on many cPanel hosts.
Rolling out DMARC safely
Start with a p=none policy and a report address: nothing is blocked, but you find out which services send e-mail on your behalf. Once all your legitimate senders are in the SPF record and sign with DKIM, move to p=quarantine, then p=reject. To see every record of your domain, use the DNS lookup.
Read our guide: SPF, DKIM and DMARC explained.
Are you an agency? We work white-label →
Frequently asked questions
Why do my e-mails go to spam?
Often because SPF, DKIM or DMARC are missing or wrong, so the recipient cannot verify that the message comes from you. Content, IP reputation and blocklists also play a part.
Where do I find my DKIM selector?
In the “DKIM-Signature” header of an e-mail you sent: it is the value after “s=”. Common ones are “google”, “selector1” and “default”.
Can I have several SPF records?
No. A domain must have a single SPF record: merge all your senders into one.
Which DMARC policy should I start with?
“p=none” with a report address, to observe without blocking anything. Then move to “quarantine” and “reject” once all legitimate senders pass.
