SPF, DKIM and DMARC explained

Three DNS records decide whether inboxes trust email from your domain. Each answers a different question, and you need all three.

Last reviewed 7 October 2026

The short version

  • SPF answers: is this server allowed to send email for this domain? It’s a published list of approved senders.
  • DKIM answers: was this message really sent by this domain, and unchanged on the way? It’s a digital signature on every message.
  • DMARC answers: does SPF or DKIM pass for the domain in the From address, and what should happen if not? It ties the other two to the name people see, and tells inboxes what to do with fakes.

Side by side

SPFDKIMDMARC
What it checksThe sending server’s IP addressA cryptographic signature on the messageThat SPF or DKIM passed for the From domain
Where it livesTXT record at yourdomainTXT or CNAME at selector._domainkey.yourdomainTXT record at _dmarc.yourdomain
Domain it checksThe hidden return addressThe signing domain (d=)The visible From address
Survives forwarding?Usually notUsually yesYes, if DKIM passes
Stops spoofing alone?NoNoYes, at quarantine or reject
StandardRFC 7208RFC 6376RFC 7489

Why one isn’t enough

SPF checks the hidden return address (the “envelope sender”), not the From address people see. A fraudster can pass SPF for their own domain while putting your company’s name in the From line. SPF also breaks when email is forwarded, because the forwarding server isn’t on your list.

DKIM proves a message was signed by a domain and not altered, and it survives forwarding. But on its own it doesn’t require that domain to match the From address either.

DMARC closes the gap. It only counts an SPF or DKIM pass if the domain that passed aligns with the From domain. Then your policy tells inboxes what to do with messages that don’t: deliver them (p=none), send them to spam (p=quarantine) or refuse them (p=reject). DMARC also sends you reports showing every server using your domain.

A simple way to picture it

Think of a letter from your company. SPF is the list of post offices allowed to send your mail. DKIM is a tamper-proof seal on the envelope. DMARC is the instruction to the recipient: “only trust letters with our name on them if they came from an approved post office or carry our seal, and shred any that don’t.”

The order to set them up

  1. SPF: list your email provider and every service that sends email on your behalf.
  2. DKIM: switch on signing in your email service and in each sending tool, so they sign with your domain.
  3. DMARC at p=none with a report address, to see what’s passing and failing.
  4. Move to quarantine, then reject once your real email passes. Our none-to-reject plan sets out the steps.

Run the email health check to see which of the three your domain already has, or use the individual SPF, DKIM and DMARC checkers.

Do I need all three?

Yes. Gmail, Yahoo and Outlook.com require SPF, DKIM and DMARC from anyone sending email to their users at volume, and only DMARC actually stops others sending email that appears to come from you.

Which is most important?

DMARC protects you, but it depends on the other two. DKIM matters most for delivery because it survives forwarding. Set up all three, in the order SPF, DKIM, DMARC.

What is alignment?

DMARC’s rule that SPF or DKIM must pass for the same domain as the From address. Relaxed alignment treats subdomains such as mail.yourdomain as a match.

Will setting these up break my email?

Not if you follow the order above. Start DMARC at p=none, which blocks nothing, and only tighten it once reports show your own email passing.