SPF, DKIM and DMARC in plain words

You will be able to explain what each of the three authentication records does and add them for your domain with your email tool's instructions.

Anyone can write any name on the outside of an envelope. Email has the same weakness. Without extra checks, a scammer can send a message that claims to come from your business, and the receiving inbox has no way to tell it apart from your real newsletter. That is how a lot of phishing works, and it is why inbox providers now expect senders to prove who they are.

The proof comes from three records you add to your domain's settings: SPF, DKIM and DMARC. The names sound technical, but each one answers a simple question. This lesson explains what they do. Lesson 3.5 is where you actually add them.

Where the records live

Your domain, the name in your website and email address such as the one Mei Ling uses for her bakery, has a set of public settings called DNS records. They tell the internet where your website is, where your email should be delivered, and more. You manage them through your domain registrar or DNS host: the company you bought the domain from, or a service you pointed it to.

SPF, DKIM and DMARC are all published there as text records. Anyone can look them up, which is the point. When an inbox receives a message claiming to be from your domain, it looks up your records and checks the message against them.

SPF: who is allowed to send

SPF stands for Sender Policy Framework. Your SPF record is a list of the servers allowed to send email for your domain.

Think of it as a guest list at the door. If Mei Ling sends her newsletter through an email tool and her everyday mail through Google Workspace, her SPF record names both. A message that arrives from a server not on the list fails the check.

There is one SPF record per domain, so when you add a new sending service, you edit the existing record to include it rather than adding a second one. Your email tool's instructions give you the exact text to include.

DKIM: a signature on every message

DKIM stands for DomainKeys Identified Mail. It adds a digital signature to each email you send. Your email tool signs the message with a private key only it holds, and you publish the matching public key in your DNS.

When the message arrives, the receiving server uses your public key to check the signature. If it matches, two things are confirmed: the message really was signed for your domain, and it was not changed on the way. If someone tampers with the content in transit, the signature no longer matches.

Your email tool generates the key for you and shows you the record to add. You do not need to understand the cryptography, only to copy the record exactly.

DMARC: what to do when checks fail

SPF and DKIM give the receiving server information, but on their own they do not say what to do with a message that fails. DMARC fills that gap. Your DMARC record tells receivers what to do when a message claiming to be from your domain fails the checks, and where to send reports about it. It also checks that the domain the reader sees in the From line lines up with the domain that passed SPF or DKIM, which is what stops someone passing the checks with their own domain while pretending to be you.

A DMARC record has a policy, and there are three levels. A monitoring policy, written p=none, asks receivers to take no special action and just send you reports. A quarantine policy asks them to treat failing mail as suspicious, usually sending it to spam. A reject policy asks them to refuse it outright.

The safe way to start is with monitoring. Publish a DMARC record at p=none with an address for reports, then read what comes back. The reports show every service sending mail as your domain. Often you find one you forgot about, such as an online shop sending order confirmations or an accounting tool sending invoices. Fix those so they pass, and only then move to quarantine and later to reject. Jumping straight to reject can block your own legitimate mail.

The raw reports are hard to read. Several free and paid services turn them into a readable summary, and some email tools do this for you.

Why a free address will not work

Many small businesses send newsletters from a Gmail or Yahoo address through a marketing tool. That breaks all of the above. You cannot add SPF, DKIM or DMARC records to gmail.com, because you do not own it. Google and Yahoo publish their own DMARC policies for their consumer domains, so mail claiming to come from a Gmail or Yahoo address but sent through a different service fails the checks. Inboxes may send it to spam or refuse it.

The fix is a domain of your own. If Priya's centre already has a website domain, she sends from an address on it, such as priya@ followed by her domain. If you have no domain, buying one costs little compared with what poor delivery costs you, and your email tool will walk you through authenticating it.

In the activity below you will log in to your registrar or DNS host and look at what is already set. Note any SPF, DKIM or DMARC records that exist, and which of the three are missing.

Log in to your domain registrar or DNS host and list the SPF, DKIM and DMARC records currently set for your domain, noting any that are missing.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).