All guides
Guide · 7 min read

SPF, DKIM and DMARC, explained.

Three short records in your domain’s DNS decide whether your email reaches the inbox or the spam folder. Here’s what each one does, in plain English.

Anyone can send an email that claims to be from your business. That’s how most phishing works. To fight it, the big email providers check whether a message really came from where it says — and since early 2024, Google and Yahoo have required senders to pass those checks. Email that doesn’t is more likely to be filtered as spam or turned away.

The checks rely on three records you publish in your domain’s DNS (the settings at your domain registrar or host).

SPF: who’s allowed to send

An SPF record is a list of the servers allowed to send email for your domain. If you use Microsoft 365 for your mailbox and a separate service for invoices or newsletters, all of them belong on the list. A typical record looks like this:

v=spf1 include:spf.protection.outlook.com include:sendgrid.net -all

Common mistakes: having two SPF records (only one is allowed), forgetting a service that sends on your behalf, or ending with +all, which allows everyone and defeats the point.

DKIM: a signature on every message

DKIM adds a digital signature to each email you send. The receiving server checks it against a public key in your DNS, which proves the message came from you and wasn’t changed along the way. Your email provider generates the key; you publish the record they give you. Each service that sends for you needs its own DKIM setup.

DMARC: what to do with fakes

DMARC ties the other two together. It tells receivers what to do with email that claims to be from you but fails SPF and DKIM, and where to send reports about it. It has three settings:

  • p=none — just report; deliver everything. A safe place to start.
  • p=quarantine — send failures to spam.
  • p=reject — turn failures away altogether. The strongest protection against people faking your address.
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourbusiness.ca

Many businesses set up DMARC with p=none and never move on. That’s better than nothing for delivery, but fakes of your address still get through. Once the reports show all your real email passing, move to quarantine, then reject.

Blocklists

Even with all three records right, email can bounce if your sending server’s address is on a blocklist such as Spamhaus — often because another customer on a shared server sent spam. If you’re listed, your email provider can usually move you or request removal.

How to check yours

Our Email & DNS report reads all three records, checks the main blocklists, and tells you exactly what to change — or ask for a free report and we’ll look for you.

Is your email set up right?

Tell us your website and we’ll send a free report: what’s working, what isn’t, and what to fix first. Or just call — we’re happy to talk it through.

Call 1-236-425-4400