Without protection, anyone can send an email that appears to come from your address: a fake invoice “from you” to your customers, or a fake message from the managing director to the accounts team. Three settings on your domain name prevent this spoofing: SPF, DKIM and DMARC. They also help your legitimate messages stay out of spam.

The problem: email address spoofing

The protocol that carries email was designed at a time when people trusted each other: on its own, it does not check that the sender shown is the real one. Phishing campaigns exploit exactly this. SPF, DKIM and DMARC add that check. They are simple DNS records, in other words lines added to your domain name’s configuration.

SPF: who is allowed to send for your domain

SPF publishes the list of servers allowed to send email using your domain. It is a TXT record, placed at the root of the domain. For example, for a domain that sends through Google Workspace:

v=spf1 include:_spf.google.com -all

With Microsoft 365, you include spf.protection.outlook.com. The end of the line says what to do with other servers: -all asks for them to be rejected, ~all for them to be treated as suspicious.

Three pitfalls to avoid:

  • Only one SPF record per domain. Two records make both invalid: everything must be combined into a single line.
  • Ten DNS lookups at most. Each include triggers at least one; beyond ten, the SPF check fails with an error.
  • Don’t leave out any sending service: newsletter tool, CRM, invoicing software, website form.

DKIM: a signature that proves where the message comes from

With DKIM, the sending server signs each message with a secret key. The matching public key is published in the DNS, at an address such as selector._domainkey.yourdomain.com. The recipient checks the signature, which confirms that the message really comes from an authorised server and has not been altered in transit.

DKIM is switched on in the tool that sends your emails (the Google Workspace admin console, the Microsoft 365 security portal…), which gives you the key to publish. Choose a 2,048-bit key when the tool offers one, and turn on DKIM for every service that sends email using your domain.

DMARC: the rules of the game, and the reports

DMARC tells recipients what to do with a message that fails the checks, and asks them to send you reports. It is a TXT record placed at _dmarc.yourdomain.com:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
  • Alignment: to pass DMARC, the domain shown in the “From” field must match the domain validated by SPF or the one in the DKIM signature.
  • The policy (p=): none to monitor without blocking anything, quarantine to send suspicious messages to spam, reject to refuse them.
  • The reports (rua=): the major email providers send a daily report, in XML format, listing the servers that have sent email using your domain. A DMARC report reader makes them easy to read.

Why it has become essential

Since February 2024, Gmail and Yahoo have imposed rules on senders. Gmail asks all senders to set up at least SPF or DKIM. Bulk senders (more than 5,000 messages per day to Gmail addresses, as defined by Google) must set up SPF and DKIM, publish a DMARC policy (at least p=none) aligned with one of the two, and offer one-click unsubscribe for marketing emails. Yahoo applies comparable requirements.

Since 5 May 2025, Microsoft has applied comparable rules to senders sending more than 5,000 messages per day to Outlook.com, Hotmail and Live.com: SPF, DKIM and DMARC (at least p=none) are required, and non-compliant messages are initially sent to the junk folder.

Even if you send much less email, these three settings protect your name and help your messages reach the inbox.

Setting up SPF, DKIM and DMARC step by step

  1. Take stock of everything that sends email using your domain: email service, newsletter, CRM, invoicing, website.
  2. Create or fix your SPF record: a single record that includes all these services.
  3. Turn on DKIM in each service and publish the keys in the DNS.
  4. Publish DMARC with p=none and an address for the reports.
  5. Read the reports for a few weeks and fix any services you missed.
  6. Move to quarantine, then to reject once all your legitimate email passes the checks.
  7. Check with an online testing tool, or from the command line:
dig TXT yourdomain.com +short
dig TXT _dmarc.yourdomain.com +short

Common mistakes

  • Two SPF records: both become invalid.
  • More than ten DNS lookups in the SPF record.
  • Jumping straight to p=reject without taking stock: your own invoices or newsletters may be rejected.
  • Forgetting domains that never send email. They can be spoofed too: publish v=spf1 -all and a DMARC policy of p=reject for them.
  • Never reading the reports: they are how you spot spoofing attempts and forgotten services.

In summary

Setting What it does Where?
SPF List of servers allowed to send TXT record at the root of the domain
DKIM Signature that proves origin and integrity TXT record selector._domainkey
DMARC Rule to apply on failure, and reports TXT record _dmarc

Would you rather hand it over? We set up domain protection with SPF, DKIM and DMARC from €490 excl. VAT, and we also create your business email addresses.

Let’s talk about your project

Tell us what you need in a few lines: we reply within 24 hours, then send you a detailed quote.

  • Reply within 24 hours, 7 days a week
  • Detailed quote before you commit
  • 3 months of bug fixes included
  • You own the code