What are SPF, DKIM and DMARC (in plain English)?
SPF, DKIM and DMARC are three DNS records that prove your emails are genuine, so they reach inboxes instead of spam and stop scammers spoofing your domain.
Quick answer
SPF, DKIM and DMARC are three email authentication records you add to your domain's DNS. SPF lists who's allowed to send email for you, DKIM adds a tamper-proof signature, and DMARC tells inboxes what to do with messages that fail those checks, together improving deliverability and blocking spoofing.
3 records
SPF, DKIM and DMARC: the standard set every business domain should have
Required
Gmail and Yahoo require all three for bulk senders since February 2024
Source: Google & Yahoo, 2024
none to reject
DMARC has three policies, from monitor-only to fully blocking spoofed mail
Three cryptic acronyms, and most business owners’ eyes glaze over before the explanation starts. But here’s why they’re worth five minutes: since February 2024, Gmail and Yahoo require them for anyone sending email in volume, and without them your genuine emails drift to spam while scammers can send fakes in your name. They’re not optional plumbing anymore. The good news is the idea behind each is genuinely simple.
SPF, DKIM and DMARC are three records you add to your domain’s DNS that prove your emails are genuine: SPF lists which servers are allowed to send email for you, DKIM adds a tamper-proof digital signature to each message, and DMARC tells receiving inboxes what to do when an email fails those checks. Together they keep your real emails out of the spam folder and stop scammers sending fake emails in your name.
The one-line version
SPF says who can send, DKIM proves the message wasn’t tampered with, and DMARC decides what happens when a check fails, and emails you a report.
SPF, the guest list
SPF (Sender Policy Framework) is a list of the mail servers allowed to send email using your domain. Think of it as the guest list at a door.
- You publish one SPF record in your DNS.
- It names every service that legitimately sends on your behalf, your email provider (Google Workspace or Microsoft 365), your booking system, your invoicing tool, your newsletter platform.
- When an inbox receives an email claiming to be from you, it checks whether the sending server’s on that list.
If the server isn’t on the list, the email looks suspicious. The catch: SPF alone is easy to slip past, because the visible “from” address can be faked even when SPF passes on a hidden technical address. That’s why it never works alone.
DKIM, the tamper-proof seal
DKIM (DomainKeys Identified Mail) adds an invisible digital signature to every email you send. It’s like a wax seal on a letter that proves two things: the email genuinely came from your domain, and nobody changed it in transit.
- Your email provider signs each message with a private key.
- A matching public key sits in your DNS for inboxes to check against.
- If the signature matches, the message is verified. If even a word was altered, the seal breaks and the check fails.
DKIM is what gives your domain a trustworthy sending reputation over time. The more authenticated mail you send, the more inboxes learn to trust you.
DMARC, the rulebook and the report
DMARC (Domain-based Message Authentication, Reporting and Conformance) is the policy that ties SPF and DKIM together. It does two jobs:
- Sets the rule, it tells receiving inboxes what to do with email that fails SPF and DKIM.
- Sends you reports, it emails you a summary of who’s sending mail using your domain, including impostors.
DMARC has three policy levels, and the safe path is to move through them in order:
| Policy | What it does | When to use it |
|---|---|---|
| p=none | Monitor only, nothing's blocked, but you get reports | Start here, watch for a few weeks |
| p=quarantine | Failing email goes to the spam folder | Once you confirm your real mail passes |
| p=reject | Failing email is blocked completely | The end goal, full protection |
Jumping straight to reject can block your own emails if a sending service was missed. Starting at none lets you see everything first.
Don't go straight to reject
Always begin DMARC on p=none and read the reports for a few weeks. Confirm every legitimate sender, your invoicing app, your CRM, your newsletter, passes before you tighten the policy. Rush it and you risk blocking your own invoices.
Why this matters for your business
Two real risks come from skipping email authentication:
- Your genuine emails land in spam. Quotes, invoices and replies get missed, and you look unprofessional or unreliable through no fault of your own. (More in why your emails land in spam.)
- Scammers spoof your domain. Without DMARC set to quarantine or reject, anyone can send emails that appear to come from your address, invoice fraud, phishing your customers, damaging your name. (See how to stop domain spoofing.)
Key takeaway
SPF, DKIM and DMARC are a set, not a menu. SPF lists your senders, DKIM seals each message, and DMARC enforces the rules and reports back. All three are simple DNS records, set up once and reviewed before you tighten them.
These records live in your DNS, not your email app, and getting the syntax exactly right matters, a misplaced character can break delivery. We configure SPF, DKIM and DMARC as part of setting up branded email at your domain, then move DMARC up to a blocking policy safely. If you’d rather not touch DNS yourself, see how done-for-you works.
Simplest next step: check whether your domain has all three set up today. If you’ve only got one, or none, your emails are working harder than they need to, and your name’s easier to fake than it should be.
Frequently asked questions
Do I need all three, or is one enough?
You need all three working together. SPF and DKIM each prove a different thing about your email, and DMARC ties them together and tells inboxes what to do when a check fails. With only one or two, providers like Gmail and Yahoo may still send your mail to spam, and scammers can more easily spoof your domain.
Where do they actually live?
All three are text records in your domain's DNS settings, usually managed where your domain's registered or through your DNS provider. They're not set inside your email app. Adding them is a one-time configuration job, though DMARC is best reviewed over a few weeks before you tighten it.
Will setting up DMARC block my own emails?
It can if you rush it. The safe approach is to start DMARC on the monitor-only policy (p=none), watch the reports for a few weeks to confirm every legitimate sending service passes, then move to quarantine and finally reject. Done in that order, your own mail keeps flowing while spoofed mail gets blocked.
What happens if I skip email authentication?
Two things go wrong. Your genuine emails are more likely to land in customers' spam folders, so invoices and replies get missed. And without DMARC, anyone can send emails that appear to come from your address, putting your reputation and your customers at risk of scams.
Written by the A1 Digital team
We handle the entire online presence for small businesses, website, branded email, Google, AI search, content and reviews, for one simple monthly plan. No tech headaches, no lock-in.
On this page
Keep reading
Why your emails land in spam (and how to fix it)
Emails land in spam from missing SPF/DKIM/DMARC, sending via free Gmail, and poor habits. Fix all three and the inbox stops being a guessing game.
How-toHow to stop your domain being spoofed
Stop domain spoofing by setting up SPF, DKIM and DMARC in your DNS, so mailbox providers can reject fake email sent in your name. The fix is free.
How-toHow to set up email at your own domain
Set up email at your own domain: pick a host (Google Workspace or Microsoft 365), add your domain, create addresses, then add the DNS records.