SPF, DKIM, and DMARC are complementary email authentication mechanisms published in DNS. Together they help receiving mail servers verify whether a message that claims to be from your domain was sent by an authorised system—and what to do if checks fail.
They do not guarantee inbox placement alone, but they are foundational for brand trust and for reducing spoofed messages that impersonate your domain.
SPF (Sender Policy Framework)
SPF lets a domain publish which mail servers may send email for it. Receivers check whether the sending server is listed. Keep SPF concise and aligned with real senders (ESP, office suite, transactional providers).
DKIM (DomainKeys Identified Mail)
DKIM adds a cryptographic signature to messages. Receivers verify the signature using a public key in DNS. If the signed content was altered in transit, verification fails.
DMARC (Domain-based Message Authentication, Reporting and Conformance)
DMARC ties SPF/DKIM alignment together and tells receivers whether to monitor, quarantine, or reject failing messages. It also enables aggregate reports so you can see who is sending as your domain.
Email authentication checks
- Message arrives at receiving server
- SPF checks sending infrastructure
- DKIM verifies the signature
- DMARC evaluates alignment + policy
- Receiver applies deliver/quarantine/reject logic
Implementation tips
- Inventory every system that sends mail as your domain
- Publish records carefully; a wrong SPF can break legitimate mail
- Start DMARC with monitoring before enforcing
- Align marketing tools and transactional senders, not only inbox users
- Keep DNS access controlled—see what DNS is
Multiple senders, one domain
Modern companies send mail from Google/Microsoft inboxes, marketing platforms, support desks, and transactional apps. Each authorised sender must be reflected in SPF/DKIM alignment. Forgotten senders cause DMARC failures—or worse, people disable DMARC to “make it work,” inviting spoofing.
Reporting mailbox
Point DMARC aggregate reports to a mailbox or analysis service someone actually reviews. Reports without review are unused telemetry.
Subdomain strategy
Some organisations send marketing from a subdomain to protect the organisational domain’s reputation. Policy design should be intentional and documented.
FAQ
Will SPF/DKIM/DMARC stop all phishing?
No. They help stop unauthorised use of your domain and give receivers stronger signals. Users still need awareness for lookalike domains and compromised accounts.