Back to the blog
spfdkimdmarcdeliverability
New

SPF, DKIM and DMARC in plain language

Three DNS records that together prove your mail really comes from you. Each answers a different question.

SPF: who is allowed to send?

A list of servers permitted to send on behalf of your domain. If another server tries, it does not match.

DKIM: is the message intact?

A digital signature on your mail. The recipient checks that it matches and that nothing was changed in transit.

DMARC: what happens on failure?

You decide: let it through, quarantine it, or refuse it. And you receive reports on what is being sent in your name.

The order of setup

SPF and DKIM first, then DMARC in observation mode. Watch the reports for a few weeks, fix what fails, and only then tighten the policy.

The most common mistake

Going straight to reject. You then block your own legitimate systems — the invoicing software, the shop, the newsletter tool — and only find out afterwards.

#spf dkim dmarc#email authentication#email dns records
Trust Guard Security Scanned
Call us
Send an email