SPF, DKIM and DMARC in plain language
Three DNS records that together prove your mail really comes from you. Each answers a different question.
SPF: who is allowed to send?
A list of servers permitted to send on behalf of your domain. If another server tries, it does not match.
DKIM: is the message intact?
A digital signature on your mail. The recipient checks that it matches and that nothing was changed in transit.
DMARC: what happens on failure?
You decide: let it through, quarantine it, or refuse it. And you receive reports on what is being sent in your name.
The order of setup
SPF and DKIM first, then DMARC in observation mode. Watch the reports for a few weeks, fix what fails, and only then tighten the policy.
The most common mistake
Going straight to reject. You then block your own legitimate systems — the invoicing software, the shop, the newsletter tool — and only find out afterwards.