Guides · updated 2026-09-06
SPF, DKIM, and DMARC Setup Guide
SPF, DKIM, and DMARC are the three DNS records that prove a message really came from your domain. Since 2024, Gmail, Yahoo, and Microsoft require all three from bulk senders. Miss any one and your mail gets throttled, filed as spam, or rejected outright.
SPF — who may send for your domain
SPF is a TXT record that lists the servers allowed to send for your domain. For example:
v=spf1 include:_spf.yourprovider.com -all
- List every service that sends on your behalf — your ESP, CRM, and mail host.
- End with
-all(hard fail) or~all(soft fail). Never+all. - Stay under 10 DNS lookups. Go over and SPF simply breaks.
DKIM — a cryptographic signature
DKIM signs each message with a private key. The matching public key sits in DNS at
selector._domainkey.yourdomain. Your ESP or mail server generates the key pair and
hands you the record to publish. Once it is live, confirm the selector actually resolves —
this is where setups quietly fail.
DMARC — policy and reporting
DMARC tells receivers what to do when SPF or DKIM fails, and where to send the reports.
Publish a TXT record at _dmarc.yourdomain:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain; adkim=s; aspf=s
- Start at
p=noneand just watch. Move top=quarantine, thenp=reject, only once your legitimate mail is passing cleanly. ruacollects the aggregate reports that show you who is sending as your domain.adkim=s; aspf=sdemand strict alignment.
Verify and keep it healthy
After publishing, check that all three pass — the free checker shows SPF, DKIM, and DMARC status for a domain in one view. Records get edited, providers change, policies drift. So watch them: Deliveradar tells you if SPF/DKIM/DMARC or your blacklist status slips. Start monitoring free.
Check your reputation now
Free check of your IP or domain across blacklists, SSL and SPF/DMARC — or set up automatic monitoring with instant alerts.