Anyone can put your address in the From field of an email. The protocol was designed in a more trusting era and it has no built-in way to prove a sender is who they claim to be. Everything since has been bolted on.
SPF, DKIM and DMARC are that bolt-on. They are three DNS records, which are settings at your domain registrar rather than anything inside your email tool. Together they let a receiving server verify that a message claiming to come from your domain genuinely did.
This is the single highest-return hour of work available in email marketing, and it is skipped constantly because it looks technical and lives somewhere unfamiliar. Without it, a well-written email from a real business is filtered before anybody reads the subject line, and no amount of better copy fixes that.
What each one proves
They answer three different questions, which is why you need all three rather than picking one.
- SPF: is this server allowed to send for you?A list of the servers permitted to send from your domain. Catches the simplest forgery.
- DKIM: was the message altered on the way?A cryptographic signature on each message. Proves it came from you and arrived unchanged.
- DMARC: what should happen when the first two fail?Your instruction to receiving servers, plus reports on who is sending as you.
Setting them up, in order
Your email provider will give you the exact values. The work is pasting them into DNS at whoever manages your domain, and the order matters.
Start with SPF. One record, listing every service that sends email as you. That includes your marketing tool, your transactional email, your helpdesk, and your office email if it sends from the same domain. A common failure is forgetting one, so write the list down before you start. You may have only one SPF record on a domain, so multiple services go into that single record rather than into several.
Then DKIM. Your provider generates a key pair and gives you a public key to publish. Some services need more than one entry. This one is copy and paste with no thinking required.
Then DMARC, and start it in monitoring mode. That tells receiving servers to take no action but to send you reports. Read those reports for a few weeks before tightening the policy, because they will reveal legitimate senders you forgot about, and moving straight to a strict policy is how companies accidentally block their own invoices.
- List every service that sends email using your domain, before touching DNS
- SPF first, one record only, covering all of them
- DKIM second, straight from your provider's values
- DMARC last, starting with a monitoring policy
- Read the DMARC reports for a few weeks before tightening
- Recheck after adding any new tool that sends email
Why this matters more than it did
The large mailbox providers have been steadily raising the bar. Bulk senders are now expected to authenticate properly, offer one-click unsubscribe, and keep complaint rates low, and messages that fail those expectations are rejected rather than merely filtered.
The practical implication is that authentication has moved from an advantage to a floor. It used to be the thing that separated careful senders from careless ones. It is now closer to a requirement for reaching an inbox at all.
There is a second benefit that has nothing to do with marketing. Authentication makes it substantially harder for anyone to send convincing phishing email using your domain, which protects your customers and your reputation more than any brand campaign will.
What authentication does not fix
Being clear about the limit: these three records prove you are who you say you are. They do not make you welcome.
If you mail people who never asked, they will mark you as spam, and a well-authenticated sender with a high complaint rate gets filtered just as thoroughly as an unauthenticated one. Reputation is built by sending things people want, to people who asked, and removing those who stop opening.
Authentication is the entry ticket. What you do with it is still the job.
Common questions
- What are SPF, DKIM and DMARC?
- Three DNS records that prove your email is genuinely from you. SPF lists the servers allowed to send using your domain. DKIM adds a cryptographic signature proving a message was not altered in transit. DMARC tells receiving servers what to do when the first two fail, and sends you reports on who is sending as you.
- Do I really need all three?
- Yes, because they answer different questions and each covers a gap the others leave. SPF alone can be defeated by forwarding. DKIM alone does not tell a receiving server what to do about a failure. DMARC without the other two has nothing to enforce. Major mailbox providers increasingly expect all three from anyone sending in volume.
- Will setting these up fix my emails going to spam?
- It removes the most common technical cause, and for many senders that alone is the fix. It will not help if the underlying problem is behavioural. Mailing people who never opted in, or continuing to mail people who never open, produces complaints, and a perfectly authenticated sender with a high complaint rate is filtered just as firmly as an unauthenticated one.
- What DMARC policy should I start with?
- Start with monitoring, which tells receiving servers to take no action but send you reports. Read those for a few weeks first. They almost always reveal a legitimate sender nobody remembered, such as an invoicing tool or a helpdesk, and going straight to a strict policy is how businesses accidentally block their own mail.
Keep reading