SPF, DKIM and DMARC explained: stop your emails landing in spam
What each email authentication record does, the mistakes that quietly break delivery, a safe way to roll out DMARC, and what Gmail and Yahoo now require from senders.
· 4 min read · By the Spot Downtime team
Your emails land in spam, or don't arrive at all, and nothing is obviously broken. Nine times out of ten, the cause is missing or misconfigured email authentication: SPF, DKIM and DMARC. Since 2024, Gmail and Yahoo require them for anyone sending in bulk, and every major mailbox provider uses them to decide what reaches the inbox.
Here's what each one does, in plain language, and how to set them up without breaking the email you already send.
The short version
| Record | Answers the question | Lives at |
|---|---|---|
| SPF | Which servers may send mail for my domain? | yourdomain.com |
| DKIM | Was this message really signed by my domain, and unchanged? | selector._domainkey.yourdomain.com |
| DMARC | What should receivers do when SPF and DKIM fail, and who gets reports? | _dmarc.yourdomain.com |
All three are TXT records in your DNS. You don't install anything on your servers to publish them.
SPF, DKIM & DMARC checkerCheck all three for any domain in seconds, with plain-English findings and suggested fixes.SPF: the list of allowed senders
SPF (Sender Policy Framework) is a list of the servers and services allowed to send email that claims to be from your domain. A typical record for a company that uses Google Workspace and a newsletter tool:
yourdomain.com. TXT "v=spf1 include:_spf.google.com include:sendgrid.net ~all"include:pulls in a provider's list of servers. Each email service you use tells you its include.~all(soft fail) means “anything else is suspicious”;-all(hard fail) means “anything else isn't us”. Start with~alland tighten once DMARC reports show everything legitimate passes.
The SPF mistakes that break delivery
- Two SPF records. A domain must have exactly one record starting with
v=spf1. With two, SPF fails for every message. Merge them into one. - More than 10 DNS lookups. Each
include,a,mxandredirectcosts a lookup, including the ones nested inside providers' includes. Above 10, SPF returns an error. Remove services you no longer use. - Forgetting a sender. Your CRM, help desk, invoicing tool and website contact form may all send as your domain. Each needs to be in SPF, or better, sign with DKIM.
DKIM: a signature on every message
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message. The sending service signs with a private key; you publish the matching public key in DNS so receivers can check that the message really came from your domain and wasn't changed on the way.
You don't write DKIM records by hand. Each sending service (Google Workspace, Microsoft 365, your newsletter or transactional email provider) gives you a record to add, under a name called a selector:
google._domainkey.yourdomain.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqh..."Turn on DKIM for every service that sends as your domain. DKIM survives forwarding better than SPF, which is why it carries most of the weight in DMARC.
DMARC: the policy and the reports
DMARC ties the other two together. It tells receivers what to do with mail that fails, and asks them to send you reports. A safe first record:
_dmarc.yourdomain.com. TXT "v=DMARC1; p=none; rua=mailto:[email protected]"p=none: deliver as normal, but report. It changes nothing for your mail; it just turns the lights on.p=quarantine: send failing mail to spam.p=reject: refuse failing mail outright. This is what actually stops people from spoofing your domain.rua=: where daily aggregate reports go. They list every server sending as your domain and whether it passed.
What “passing DMARC” means
Rolling it out safely
- List every service that sends email as your domain. Ask finance, sales and support too.
- Publish one SPF record that includes them all, ending in
~all. - Turn on DKIM in every one of those services.
- Publish DMARC with
p=noneand a reporting address. Read the reports for two to four weeks. - Fix every legitimate sender that fails, until the reports show only spoofers failing.
- Move to
p=quarantine, then top=reject. You can phase it in withpct=, e.g.pct=25applies the policy to a quarter of failing mail first.
What Gmail and Yahoo require
Since February 2024, Google and Yahoo require:
- Everyone: SPF or DKIM, valid forward and reverse DNS for sending servers, and a low spam-complaint rate.
- Bulk senders (around 5,000 messages a day to Gmail): SPF and DKIM, a DMARC record (
p=noneis enough), alignment with the From domain, and one-click unsubscribe for marketing mail.
If you send newsletters or product email at any scale, treat all three records as required.
Don't forget the basics
Authentication only matters if mail can be delivered at all. Check that your MX records point at the right mail servers, especially after changing email providers. Mail to a domain with broken MX records simply bounces.
MX lookupSee which mail servers receive email for a domain, in priority order, with their IP addresses.DNS records also change by accident, in a provider migration or a cleanup. A DNS monitor can alert you the moment your MX or TXT records stop matching what they should be, before email quietly stops working.
Keep reading
- Uptime · SLAsWhat 99.9% uptime really means (with a downtime table)99.9% sounds close to perfect, but it allows 43 minutes of downtime a month. Here's what each common uptime target allows, why your real uptime is lower than any one provider's, and how to pick an SLA you can keep.October 2, 2026 · 5 min read
- Cron jobs · HeartbeatsHow to monitor cron jobs and catch the ones that silently stopCron jobs fail without telling anyone. Learn the heartbeat pattern: the job checks in when it finishes, and you get alerted when it doesn't, with examples for crontab, GitHub Actions and Kubernetes.October 2, 2026 · 5 min read