How to Set Up SPF, DKIM and DMARC for Email
SPF, DKIM and DMARC are DNS-based email authentication controls. SPF lists which servers may send mail for your domain, DKIM cryptographically signs messages, and DMARC tells receivers what to do when checks fail and where to send reports. Publish TXT records carefully, start DMARC at p=none, monitor, then tighten to quarantine or reject.
Friends, mail for your domain lands in spam or others spoof your domain. The fix: SPF + DKIM + DMARC — three DNS TXT records. Today we set them up with a vertical checklist. US-friendly examples (example.com); DNS UI may look like GoDaddy / Route 53 / Cloudflare.
मित्रांनो, तुमच्या डोमेनची टपाल कचरा पेटीत जाते किंवा इतर लोक डोमेन नक्कल करतात. उपाय: SPF + DKIM + DMARC – तीन DNS मजकूर नोंदी. आज आपण रचना उभ्या यादीने करूया. अमेरिकन उदाहरणे (example.com); DNS चे दृश्य GoDaddy / Route 53 / Cloudflare सारखे असू शकते.
मित्रों, आपके डोमेन की डाक कचरा पेटी में जाती है या अन्य लोग डोमेन की नकल करते हैं. उपाय: SPF + DKIM + DMARC – तीन DNS पाठ अभिलेख. आज हम सेटअप ऊर्ध्व सूची से करेंगे. अमेरिकी उदाहरण (example.com); DNS दृश्य GoDaddy / Route 53 / Cloudflare जैसा हो सकता है.
Quick answer
Rollout order:
- Inventory every system that sends mail as
@yourdomain(Google Workspace, Microsoft 365, ESP, servers). - Publish SPF TXT on the apex (one SPF record only).
- Enable DKIM signing at your provider; publish the DKIM CNAMEs/TXT they give you.
- Publish DMARC at
_dmarc.yourdomainwithp=noneand a reporting address. - Read aggregate reports for 1–2 weeks; fix remaining senders.
- Move DMARC policy to
quarantine, thenrejectwhen clean.
Example shapes (replace domains and values with your provider’s):
; SPF (TXT at example.com) — one record only
v=spf1 include:_spf.google.com include:spf.protection.outlook.com -all
; DKIM — follow your provider (selector._domainkey TXT or CNAME)
; DMARC (TXT at _dmarc.example.com)
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s; pct=100
What do I need before this guide?
- Control of DNS for your domain.
- A mailbox that can receive DMARC aggregate reports (or a DMARC report service).
- List of legitimate senders (Workspace, M365, SendGrid, mail server, billing tools, and similar).
- Patience for DNS TTL propagation.
How do SPF, DKIM and DMARC work together?
SPF lists who may send, DKIM signs the message, and DMARC sets the policy and reporting — all as DNS TXT records.
SPF सांगतो कोण पाठवू शकतो, DKIM संदेशावर सही करतो, आणि DMARC धोरण व report ठरवतो — सगळे DNS मजकूर नोंदी म्हणून.
SPF बताता है कौन भेज सकता है, DKIM संदेश पर सही करता है, और DMARC नीति व रिपोर्ट तय करता है — सब DNS पाठ अभिलेख के रूप में.
Vertical flow for one outbound message:
- Your sending service transmits the message.
- The receiver looks up SPF for the envelope domain and checks whether the sending IP is allowed.
- The receiver verifies the DKIM signature using the public key in DNS.
- DMARC aligns the From domain with SPF and/or DKIM results and applies your policy.
- Aggregate reports (
rua) tell you who is sending as you — good and bad.
Aligned, authenticated mail improves trust. Spoofed mail fails DMARC when policy is enforced.
How do I set them up step by step?
Step 1 — Inventory senders
- List every product that sends as your domain.
- For each, open the vendor’s “email authentication / SPF / DKIM” docs.
- Plan one SPF string that
include:s each vendor mechanism without crossing the 10-DNS-lookup limit.
Step 2 — Publish SPF
- Create a TXT record on the apex (or the subdomain you send From).
- Start with vendor includes; end with
-allwhen you know the inventory, or~allbriefly while discovering. - Ensure there is only one SPF TXT record on that name.
- Verify with:
dig +short TXT example.com
# or
nslookup -type=TXT example.com
Step 3 — Enable DKIM at each provider
- In Google Workspace / Microsoft 365 / your ESP, generate DKIM keys.
- Publish the exact TXT or CNAME records they show (selector names differ).
- Turn on signing.
- Verify:
dig +short TXT selector._domainkey.example.com
Step 4 — Publish DMARC at p=none
- Add TXT at
_dmarc.example.com. - Use
p=nonefirst so you get reports without blocking mail. - Set
rua=to a mailbox or service you monitor. - Verify:
dig +short TXT _dmarc.example.com
Step 5 — Monitor, then enforce
- Read weekly DMARC aggregate summaries.
- Add missing legitimate senders to SPF/DKIM.
- Raise policy:
p=quarantinethenp=reject. - Keep reporting on after enforcement.
Ravindra Bagale's Tip
💡 Two SPF records confuse receivers — SPF FAIL. Always keep one SPF TXT. And do not jump straight to DMARC p=reject; start with p=none plus reports. Many students forget a marketing tool and then legitimate mail gets rejected. Remember the order!
Ravindra Bagale's Tip – मराठी
💡 SPF record दोन ठेवले की receivers confuse होतात – SPF FAIL. नेहमी एकच SPF TXT. आणि DMARC सरळ p=reject करू नका; आधी p=none + reports. खूप students marketing tool विसरतात, मग legitimate mail reject. क्रम लक्षात ठेवा!
Ravindra Bagale's Tip – हिंदी
💡 SPF record दो रखोगे तो receivers confuse होते हैं – SPF FAIL. हमेशा एक ही SPF TXT. और DMARC सीधे p=reject मत करो; पहले p=none + reports. बहुत students marketing tool भूल जाते हैं, फिर legitimate mail reject हो जाता है. क्रम याद रखो!
How do I fix common SPF/DKIM/DMARC problems?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| SPF PermError | More than one SPF record or too many lookups | Merge to one record; flatten/includes carefully |
| DKIM fail | Wrong DNS value / signing off | Re-copy keys; enable signing; wait for TTL |
| DMARC fail after SPF pass | From domain does not align | Align From with authenticated domain; tighten carefully |
| Reports empty | Wrong rua or still propagating |
Confirm TXT; wait; send test mail from each ESP |
| Suddenly quarantined good mail | Jumped to reject too early |
Temporarily loosen policy; fix senders; re-enforce |
Try it at home
If you own a domain, publish DMARC p=none and collect one week of reports. Write:
- Legitimate senders found:
- Unknown sources found:
- Date you plan to move to
quarantine:
Learn it properly
Got it? SPF = who may send, DKIM = signature, DMARC = policy + reports. One SPF, DKIM on, DMARC from p=none. After reports, quarantine / reject. Less spoof, better deliverability.
समजलं का? SPF = कोण पाठवू शकतो, DKIM = सही, DMARC = धोरण व report. एक SPF, DKIM सुरू, DMARC p=none पासून. report पाहून quarantine / reject. नक्कल कमी, पोहोच सुधारते.
समझ में आया? SPF = कौन भेज सकता है, DKIM = सही, DMARC = नीति व रिपोर्ट. एक SPF, DKIM चालू, DMARC p=none से शुरू. रिपोर्ट देखकर quarantine / reject. नकल कम, पहुँच बेहतर.
Frequently asked questions
What do SPF, DKIM and DMARC do?
SPF lists allowed senders, DKIM signs messages, DMARC sets policy and reporting when checks fail.
Why only one SPF record?
Multiple SPF TXT records on the same name cause evaluation errors. Merge includes into one string.
Why start DMARC at p=none?
So you receive reports and fix legitimate senders before mail is quarantined or rejected.
How do I verify the records?
Use dig or nslookup for TXT on the apex, the DKIM selector name and _dmarc.
Will this stop all phishing?
It reduces domain spoofing and improves trust signals. Compromised real accounts and lookalike domains still need user awareness and MFA.
Which course lessons help?
Cyber DNS record lessons and social-engineering awareness on this site.