Ravindra BagaleCourses & study guides Track your progress

Guides

How to Set Up SPF, DKIM and DMARC for Email

SPF, DKIM and DMARC are DNS-based email authentication controls. SPF lists which servers may send mail for your domain, DKIM cryptographically signs messages, and DMARC tells receivers what to do when checks fail and where to send reports. Publish TXT records carefully, start DMARC at p=none, monitor, then tighten to quarantine or reject.

Friends, mail for your domain lands in spam or others spoof your domain. The fix: SPF + DKIM + DMARC — three DNS TXT records. Today we set them up with a vertical checklist. US-friendly examples (example.com); DNS UI may look like GoDaddy / Route 53 / Cloudflare.

Quick answer

Rollout order:

  1. Inventory every system that sends mail as @yourdomain (Google Workspace, Microsoft 365, ESP, servers).
  2. Publish SPF TXT on the apex (one SPF record only).
  3. Enable DKIM signing at your provider; publish the DKIM CNAMEs/TXT they give you.
  4. Publish DMARC at _dmarc.yourdomain with p=none and a reporting address.
  5. Read aggregate reports for 1–2 weeks; fix remaining senders.
  6. Move DMARC policy to quarantine, then reject when clean.

Example shapes (replace domains and values with your provider’s):

; SPF (TXT at example.com) — one record only
v=spf1 include:_spf.google.com include:spf.protection.outlook.com -all

; DKIM — follow your provider (selector._domainkey TXT or CNAME)

; DMARC (TXT at _dmarc.example.com)
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s; pct=100

What do I need before this guide?

  • Control of DNS for your domain.
  • A mailbox that can receive DMARC aggregate reports (or a DMARC report service).
  • List of legitimate senders (Workspace, M365, SendGrid, mail server, billing tools, and similar).
  • Patience for DNS TTL propagation.

How do SPF, DKIM and DMARC work together?

Vertical flow for one outbound message:

  1. Your sending service transmits the message.
  2. The receiver looks up SPF for the envelope domain and checks whether the sending IP is allowed.
  3. The receiver verifies the DKIM signature using the public key in DNS.
  4. DMARC aligns the From domain with SPF and/or DKIM results and applies your policy.
  5. Aggregate reports (rua) tell you who is sending as you — good and bad.

Aligned, authenticated mail improves trust. Spoofed mail fails DMARC when policy is enforced.

How do I set them up step by step?

Step 1 — Inventory senders

  1. List every product that sends as your domain.
  2. For each, open the vendor’s “email authentication / SPF / DKIM” docs.
  3. Plan one SPF string that include:s each vendor mechanism without crossing the 10-DNS-lookup limit.

Step 2 — Publish SPF

  1. Create a TXT record on the apex (or the subdomain you send From).
  2. Start with vendor includes; end with -all when you know the inventory, or ~all briefly while discovering.
  3. Ensure there is only one SPF TXT record on that name.
  4. Verify with:
dig +short TXT example.com
# or
nslookup -type=TXT example.com

Step 3 — Enable DKIM at each provider

  1. In Google Workspace / Microsoft 365 / your ESP, generate DKIM keys.
  2. Publish the exact TXT or CNAME records they show (selector names differ).
  3. Turn on signing.
  4. Verify:
dig +short TXT selector._domainkey.example.com

Step 4 — Publish DMARC at p=none

  1. Add TXT at _dmarc.example.com.
  2. Use p=none first so you get reports without blocking mail.
  3. Set rua= to a mailbox or service you monitor.
  4. Verify:
dig +short TXT _dmarc.example.com

Step 5 — Monitor, then enforce

  1. Read weekly DMARC aggregate summaries.
  2. Add missing legitimate senders to SPF/DKIM.
  3. Raise policy: p=quarantine then p=reject.
  4. Keep reporting on after enforcement.

Ravindra Bagale's Tip

💡 Two SPF records confuse receivers — SPF FAIL. Always keep one SPF TXT. And do not jump straight to DMARC p=reject; start with p=none plus reports. Many students forget a marketing tool and then legitimate mail gets rejected. Remember the order!

How do I fix common SPF/DKIM/DMARC problems?

Ghabru naka 😅 — these are the usual ones:

Symptom Likely cause Fix
SPF PermError More than one SPF record or too many lookups Merge to one record; flatten/includes carefully
DKIM fail Wrong DNS value / signing off Re-copy keys; enable signing; wait for TTL
DMARC fail after SPF pass From domain does not align Align From with authenticated domain; tighten carefully
Reports empty Wrong rua or still propagating Confirm TXT; wait; send test mail from each ESP
Suddenly quarantined good mail Jumped to reject too early Temporarily loosen policy; fix senders; re-enforce

Try it at home

If you own a domain, publish DMARC p=none and collect one week of reports. Write:

  1. Legitimate senders found:
  2. Unknown sources found:
  3. Date you plan to move to quarantine:

Got it? SPF = who may send, DKIM = signature, DMARC = policy + reports. One SPF, DKIM on, DMARC from p=none. After reports, quarantine / reject. Less spoof, better deliverability.

Frequently asked questions

What do SPF, DKIM and DMARC do?

SPF lists allowed senders, DKIM signs messages, DMARC sets policy and reporting when checks fail.

Why only one SPF record?

Multiple SPF TXT records on the same name cause evaluation errors. Merge includes into one string.

Why start DMARC at p=none?

So you receive reports and fix legitimate senders before mail is quarantined or rejected.

How do I verify the records?

Use dig or nslookup for TXT on the apex, the DKIM selector name and _dmarc.

Will this stop all phishing?

It reduces domain spoofing and improves trust signals. Compromised real accounts and lookalike domains still need user awareness and MFA.

Which course lessons help?

Cyber DNS record lessons and social-engineering awareness on this site.