Without protection, anyone can send an email that appears to come from your address: a fake invoice “from you” to your customers, or a fake message from the managing director to the accounts team. Three settings on your domain name prevent this spoofing: SPF, DKIM and DMARC. They also help your legitimate messages stay out of spam.
The problem: email address spoofing
The protocol that carries email was designed at a time when people trusted each other: on its own, it does not check that the sender shown is the real one. Phishing campaigns exploit exactly this. SPF, DKIM and DMARC add that check. They are simple DNS records, in other words lines added to your domain name’s configuration.
SPF: who is allowed to send for your domain
SPF publishes the list of servers allowed to send email using your domain. It is a TXT record, placed at the root of the domain. For example, for a domain that sends through Google Workspace:
v=spf1 include:_spf.google.com -all
With Microsoft 365, you include spf.protection.outlook.com. The end of the line says what to do with other servers: -all asks for them to be rejected, ~all for them to be treated as suspicious.
Three pitfalls to avoid:
- Only one SPF record per domain. Two records make both invalid: everything must be combined into a single line.
- Ten DNS lookups at most. Each
includetriggers at least one; beyond ten, the SPF check fails with an error. - Don’t leave out any sending service: newsletter tool, CRM, invoicing software, website form.
DKIM: a signature that proves where the message comes from
With DKIM, the sending server signs each message with a secret key. The matching public key is published in the DNS, at an address such as selector._domainkey.yourdomain.com. The recipient checks the signature, which confirms that the message really comes from an authorised server and has not been altered in transit.
DKIM is switched on in the tool that sends your emails (the Google Workspace admin console, the Microsoft 365 security portal…), which gives you the key to publish. Choose a 2,048-bit key when the tool offers one, and turn on DKIM for every service that sends email using your domain.
DMARC: the rules of the game, and the reports
DMARC tells recipients what to do with a message that fails the checks, and asks them to send you reports. It is a TXT record placed at _dmarc.yourdomain.com:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
- Alignment: to pass DMARC, the domain shown in the “From” field must match the domain validated by SPF or the one in the DKIM signature.
- The policy (
p=):noneto monitor without blocking anything,quarantineto send suspicious messages to spam,rejectto refuse them. - The reports (
rua=): the major email providers send a daily report, in XML format, listing the servers that have sent email using your domain. A DMARC report reader makes them easy to read.
Why it has become essential
Since February 2024, Gmail and Yahoo have imposed rules on senders. Gmail asks all senders to set up at least SPF or DKIM. Bulk senders (more than 5,000 messages per day to Gmail addresses, as defined by Google) must set up SPF and DKIM, publish a DMARC policy (at least p=none) aligned with one of the two, and offer one-click unsubscribe for marketing emails. Yahoo applies comparable requirements.
Since 5 May 2025, Microsoft has applied comparable rules to senders sending more than 5,000 messages per day to Outlook.com, Hotmail and Live.com: SPF, DKIM and DMARC (at least p=none) are required, and non-compliant messages are initially sent to the junk folder.
Even if you send much less email, these three settings protect your name and help your messages reach the inbox.
Setting up SPF, DKIM and DMARC step by step
- Take stock of everything that sends email using your domain: email service, newsletter, CRM, invoicing, website.
- Create or fix your SPF record: a single record that includes all these services.
- Turn on DKIM in each service and publish the keys in the DNS.
- Publish DMARC with
p=noneand an address for the reports. - Read the reports for a few weeks and fix any services you missed.
- Move to
quarantine, then torejectonce all your legitimate email passes the checks. - Check with an online testing tool, or from the command line:
dig TXT yourdomain.com +short
dig TXT _dmarc.yourdomain.com +short
Common mistakes
- Two SPF records: both become invalid.
- More than ten DNS lookups in the SPF record.
- Jumping straight to
p=rejectwithout taking stock: your own invoices or newsletters may be rejected. - Forgetting domains that never send email. They can be spoofed too: publish
v=spf1 -alland a DMARC policy ofp=rejectfor them. - Never reading the reports: they are how you spot spoofing attempts and forgotten services.
In summary
| Setting | What it does | Where? |
|---|---|---|
| SPF | List of servers allowed to send | TXT record at the root of the domain |
| DKIM | Signature that proves origin and integrity | TXT record selector._domainkey |
| DMARC | Rule to apply on failure, and reports | TXT record _dmarc |
Would you rather hand it over? We set up domain protection with SPF, DKIM and DMARC from €490 excl. VAT, and we also create your business email addresses.