SPF, DKIM & DMARC: the complete setup guide
SPF, DKIM and DMARC are the three records that prove your mail is really yours. Set up wrong, they silently hurt deliverability. Here's how to get each one right.
SPF: who can send for you
SPF is a TXT record listing the servers allowed to send mail for your domain. Include every sending service you use, stay under the 10-DNS-lookup limit, publish only one SPF record, and end it with ~all or -all.
DKIM: sign your mail
DKIM adds a cryptographic signature using a private key, with the public key published as a TXT record at a selector under your domain. Your email provider generates the keys; you publish the record they give you so receivers can verify the signature.
DMARC: tie it together
DMARC tells receivers what to do when SPF and DKIM fail — none, quarantine or reject — and where to send reports. Start at p=none with a rua reporting address, confirm your legitimate mail passes, then tighten toward p=reject.
Verify your records
After publishing, lint each record for the common mistakes — too many SPF lookups, a missing all, a p=none DMARC you forgot to tighten. Our free SPF, DKIM and DMARC checkers catch these in seconds.