SPF, DKIM, and DMARC are the three records that prove your email is really from you. Since 2024, Gmail and Yahoo have effectively required all three from bulk senders. Get them wrong and no amount of good content or reputation work will keep you out of spam reliably.
What each record does
SPF lists the servers allowed to send mail for your domain; a receiver checks the sending server against it. DKIM adds a cryptographic signature so the receiver can confirm the message wasn't altered and really came from your domain. DMARC ties SPF and DKIM to your visible From address and tells receivers what to do when a message fails, plus it sends you reports. Individually useful; together they're the standard.
The misconfigurations that pass a glance and still fail
The dangerous problems aren't missing records, they're records that look fine and don't align. A DKIM signature that verifies but whose domain doesn't match your From domain fails DMARC anyway. An SPF record with too many nested DNS lookups quietly stops evaluating past the limit. A DMARC record stuck at p=none that monitors forever but never protects. Each of these reads as "set up" and still costs you placement. This is the layer where a second set of eyes earns its keep.
How setup and correction work
Publish or fix the three records, confirm alignment against your actual sending, then move DMARC from monitoring to enforcement in stages, reading the reports at each step so legitimate mail never gets caught. The goal isn't just "records exist," it's "records pass on every stream you send." Once the auth layer is known-good, you can finally diagnose reputation and list problems cleanly, because you've ruled out the foundation.
Check yours in seconds
The free deliverability check reads your SPF, DKIM, DMARC, and MX and shows you what's present, what's missing, and where alignment breaks, no signup. Most teams learn something from it. If it's a quick DNS fix, you may not need us at all. If it's an alignment or enforcement problem, that's exactly the part worth getting right the first time.
Common questions
Do I need all three of SPF, DKIM, and DMARC?
Yes, and they work together. SPF says which servers may send for your domain. DKIM cryptographically signs your mail so it can't be tampered with. DMARC ties the two to your visible From address and tells receivers what to do when something fails. Gmail and Yahoo now effectively require all three for bulk senders. Two out of three leaves a gap that shows up as spam foldering.
Can I set this up myself?
Often, yes. Publishing SPF, DKIM, and a basic DMARC record is a DNS task most technical teams can do. Where people get stuck is alignment, the subtle requirement that the domains in your SPF and DKIM line up with your visible From domain, and moving DMARC from monitoring to enforcement without breaking legitimate mail. If those sentences sound fuzzy, that's exactly where help pays off.
What does a misconfiguration actually look like?
The nasty ones pass a naive check but fail alignment. Your DKIM signature verifies, but the signing domain doesn't match your From domain, so DMARC fails anyway. Or your SPF record has too many DNS lookups and silently stops evaluating. Or DMARC is published at p=none forever, monitoring but never protecting. All of these look 'set up' at a glance and still hurt deliverability.
Will fixing this stop my emails going to spam?
Sometimes completely, sometimes partly. Authentication is the foundation, if it's broken, nothing else you do will hold. But placement also depends on reputation and list quality. Fixing auth removes one major cause and is always worth doing first, because you can't diagnose the rest cleanly until the auth layer is known-good.
What is DMARC enforcement and should I turn it on?
DMARC has three policies: none (monitor), quarantine (send failures to spam), and reject (block them). Most domains should progress to quarantine or reject, but only after monitoring shows your legitimate mail passes. Jumping straight to reject without checking can block your own real email. The safe path is monitor, read the reports, fix what fails, then enforce.
Related
- SPF, DKIM, DMARC: each record, defined
- Email Authentication: how the three fit together
- Return-Path: why SPF alignment can surprise you
- Emails going to spam?: when auth is only part of it