SPF, DKIM and DMARC are DNS records that let receiving mail servers check that an email claiming to be from your domain really is. Without them, your mail is more likely to land in spam, and anyone can forge your address. Large mailbox providers now require them for anyone sending in volume.
| Record | Answers the question | Where it lives |
|---|---|---|
| SPF | Which servers may send mail for this domain? | TXT on the domain |
| DKIM | Was this message signed by the domain, and is it unchanged? | TXT on selector._domainkey |
| DMARC | What should receivers do when checks fail, and who gets reports? | TXT on _dmarc |
1. SPF
List every service that sends mail as your domain: your mailbox provider, your website’s mail, newsletter tools, helpdesks. Each provider documents the include: value to add. Then publish one TXT record on the bare domain:
v=spf1 include:_spf.mailprovider.example include:newsletter.example -all
- Only one SPF record is allowed. Two records make SPF fail entirely; merge them into one.
-allmeans “reject everything else”.~all(softfail) is gentler while you test.- SPF allows at most 10 DNS lookups; every
include:counts.
2. DKIM
DKIM signs each message with a private key; the public key goes in DNS. Your mail provider generates the key pair and gives you a record to add, something like:
Name: selector1._domainkey
Type: TXT (or CNAME, if the provider asks)
Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqh...
Turn on signing in the provider’s settings after the record is live. Each sending service has its own selector and record.
3. DMARC
Start in monitoring mode so nothing is blocked while you check results:
Name: _dmarc
Type: TXT
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
Receivers send daily reports to that address, showing which servers sent mail as you and whether they passed. After a few weeks of clean reports, tighten the policy to p=quarantine, then p=reject.
Check your work
dig TXT example.com +short
dig TXT _dmarc.example.com +short
dig TXT selector1._domainkey.example.com +short
Then send a message to a mailbox you control and view the original headers. Look for spf=pass, dkim=pass and dmarc=pass in the Authentication-Results line.
A domain that never sends email should still say so: publish v=spf1 -all and a DMARC record with p=reject. That stops it being used for spoofing.
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.
