Currently looking for international opportunities in digital marketing & design.Let’s talk

Skip to content
Kavin P

Email Marketing

SPF, DKIM and DMARC Explained for Non-Technical Marketers

By Kavin P · · 7 min read

Open-plan studio office
Photo from Unsplash (unsplash.com/license)

If you send email from your own domain, you have probably seen warnings about SPF, DKIM and DMARC in your email tool's setup screen. They sound technical, but the idea is simple: these are three ways of proving that an email claiming to come from your domain really did. This guide explains each one in plain language and gives you a safe order for setting them up.

The problem these records solve

Email was designed in a more trusting era, and it is surprisingly easy to send a message that pretends to come from someone else's address. Scammers use this trick to imitate banks, shops and small businesses. Mailbox providers fight back by checking whether a message can prove its origin. If your messages cannot, they may land in spam or be rejected, even if you are completely legitimate.

SPF, DKIM and DMARC are the proof. They live in your domain's DNS settings, which is the public directory that tells the internet how your domain works. If DNS itself is new to you, the domain name and DNS basics guide is a helpful primer.

An everyday analogy

Imagine a letter delivered to your door.

  • SPF is a list at the post office of which vans are allowed to deliver mail for your business.
  • DKIM is a tamper-evident seal on the envelope showing it was sealed by you and not opened on the way.
  • DMARC is the instruction you leave telling the receiver what to do if a letter fails those checks, and asking them to send you reports.

The analogy is not perfect, but it captures the roles.

SPF: who is allowed to send

SPF stands for Sender Policy Framework. It is a DNS record that lists the servers and services allowed to send email for your domain. When a message arrives, the receiving server checks whether the sender is on your list.

Things to know

  • Your domain should have only one SPF record. Multiple SPF records cause errors.
  • Every service that sends email on your behalf, such as your main email provider, your newsletter tool and your invoicing system, should be included in that single record.
  • SPF has a limit on how many lookups it can trigger, so adding too many services can break it. Remove services you no longer use.
  • SPF checks the technical sending address behind the scenes, not necessarily the name people see.

Typical setup

Your email tool will give you a snippet to add. Your job is to merge it into your existing SPF record rather than creating a second one. If you are unsure, ask your provider's support, or check their official documentation.

DKIM: a signature that proves the message is intact

DKIM stands for DomainKeys Identified Mail. Your sending service adds a digital signature to each email. A matching public key published in your DNS lets the receiving server verify that the message came from an authorised source and was not altered in transit.

Things to know

  • Each sending service usually has its own DKIM key. You may add several.
  • Your provider will give you the record name and value to publish. Copy them exactly. A stray space or a missing character will break verification.
  • Some DNS tools add your domain name automatically to the record name. If you add it twice, the record will not work. Check how your DNS host handles this.
  • After adding the record, use your provider's verification button. It may take some time for changes to spread.

DMARC: the policy and the reports

DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It builds on SPF and DKIM. It does two jobs:

  1. It tells receiving servers what to do when a message claiming to be from your domain fails the checks.
  2. It requests reports so you can see who is sending email using your domain.

An important idea is alignment: the domain that passes SPF or DKIM should match the domain in the visible "From" address. This stops a scammer from passing checks on their own domain while showing yours.

The three policy levels

  1. None (monitoring). Do nothing to failing messages, but send reports. This is where to start.
  2. Quarantine. Failing messages are treated as suspicious, often sent to spam.
  3. Reject. Failing messages are refused.

A gradual path is wise: start with monitoring, read the reports, fix legitimate senders that fail, and only then tighten the policy. Jumping straight to the strictest level can block your own invoices, booking system or newsletter if you forgot to set one up properly.

A safe order of setup

  1. List every service that sends email as your domain. Include your main inbox, newsletter platform, online store, CRM, booking tool, invoicing tool, contact form plug-in and any website system that sends notifications.
  2. Set up SPF as a single, merged record.
  3. Set up DKIM for each service that supports it.
  4. Publish a DMARC record at monitoring level, with an address to receive reports.
  5. Review the reports over a few weeks. Look for legitimate services that fail and fix them.
  6. Consider moving to a stricter policy once your real mail passes reliably.
  7. Re-check whenever you add or remove a sending tool.

Reports can be hard to read in raw form. Many free and paid tools translate them into readable summaries. Choose a reputable one and check its privacy terms.

Testing your setup

After making changes:

  • Send a test email to yourself at a couple of different mailbox providers and look at the message details or headers to see whether SPF, DKIM and DMARC are reported as passing.
  • Use your sending tool's built-in checker, which usually shows which records are detected.
  • Use a trusted online DNS lookup tool to confirm that your records are published.

If something fails, compare the record against your provider's instructions character by character.

Common mistakes

  • Two SPF records instead of one merged record.
  • Forgetting a sender, such as the contact form on your website, so legitimate mail starts failing.
  • Copy and paste errors in DKIM keys.
  • Jumping to a strict DMARC policy without reviewing reports.
  • Sending from a free mailbox domain through your newsletter tool. You cannot authenticate a domain you do not control, and big mailbox providers increasingly treat such mail with suspicion.
  • Forgetting to update records after changing providers.

Why this matters for marketing

Authentication is not a magic switch for the inbox. It is a foundation. Even with perfect records, poor content, bad list quality or high complaint levels will still hurt your delivery. But without authentication, you are making every email harder to trust. Providers have been tightening their expectations for senders, so check their current published guidelines for the volumes and types of mail you send.

Pair authentication with good practice elsewhere:

Keeping a record of your setup

Write down which services send email for your domain, who set them up, when you last checked the records and where the login for your DNS host is stored. A simple shared document is enough. When a developer leaves or a tool is replaced, this record saves hours of guesswork and prevents old, forgotten senders from lingering in your SPF record.

When to ask for help

DNS changes are low-risk when done carefully, but a wrong edit to the wrong record can break your website or email. Consider asking for help if:

  • You are unsure which records already exist.
  • Your domain is managed by someone else, such as a former developer.
  • You have many sending services.
  • You see sudden delivery problems after a change.

Always note the existing records before editing, so you can revert if needed.

Takeaway

SPF says who may send, DKIM signs the message and DMARC sets the policy and asks for reports. Set them up in that order, start DMARC at monitoring level, list every sending service and test the results. Treat provider documentation as the final word on exact record formats, because they can differ. If you would like help with your domain and email setup, get in touch or visit the resources.

Frequently asked questions

Do I need SPF, DKIM and DMARC if I send few emails?

Yes. Even small senders benefit, because authentication helps mailbox providers trust your messages and protects your domain from being imitated. Many providers now expect it, so check their current requirements.

Can I have more than one SPF record?

No. A domain should have a single SPF record that lists all authorised senders. Multiple records cause errors, so merge the entries from each service into one record.

What DMARC policy should I start with?

Start with the monitoring policy, which takes no action on failing mail but sends you reports. Review them, fix legitimate senders that fail, and only then consider moving to a stricter level.

How do I know if my records are working?

Send test emails to a few mailbox providers and check the message details for pass results, use your sending tool's checker, and confirm the records with a trusted DNS lookup tool.

Related articles

Enjoyed this? Get the next one.