What are SPF, DKIM and DMARC?
They are three settings added to your domain that prove an email really came from your business. SPF lists who is allowed to send as you, DKIM adds a tamper-proof signature to each email, and DMARC tells inboxes what to do if an email fails those checks. Without them, your emails are far more likely to land in spam.
Why this suddenly matters
Anyone can put your email address in the "from" line of a message. It takes no skill at all, and it is how most scam emails pretend to come from real businesses. SPF, DKIM and DMARC are how Gmail, Outlook and Yahoo tell the real thing from a fake.
Since February 2024, Google's sender guidelines require every sender to have SPF or DKIM set up, and anyone sending more than 5,000 emails a day to Gmail addresses must have all three. Yahoo introduced matching rules, and Microsoft followed for Outlook in 2025. Small senders are not blocked outright, but mail without authentication is treated with much more suspicion.
The three, one at a time
SPF: the guest list
SPF (Sender Policy Framework) is a list published on your domain of the services allowed to send email on your behalf, such as Microsoft 365, Google Workspace or your website's contact form. An inbox checks the list, and if the sending server is not on it, that is a warning sign.
DKIM: the wax seal
DKIM (DomainKeys Identified Mail) adds a hidden digital signature to every email you send. The receiving inbox checks it against a key published on your domain. If the signature matches, the email genuinely came from an approved sender and was not altered on the way.
DMARC: the instructions
DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the other two together. It tells inboxes what to do with an email that fails: let it through and just report it, send it to spam, or reject it completely. It can also send you reports showing who is sending email using your domain.
Where each one lives
Common mistakes
- Two SPF records. A domain can only have one. Adding a second instead of editing the first breaks both.
- Forgetting a sender. If your website form, booking system or newsletter tool sends as your domain, it needs including too.
- Jumping straight to "reject". Start DMARC on "none", read the reports, fix any gaps, then tighten it.
- Setting it and forgetting it. Change email provider or add a new tool, and the records need updating.
If your emails are already going missing, read our answer to why email goes to spam as well.
The takeaway
- SPF says who can send as you, DKIM signs each email, DMARC says what to do with failures.
- Gmail, Yahoo and Outlook now expect them, and unauthenticated mail is far more likely to hit spam.
- All three are records on your domain, so they need updating whenever your email setup changes.
Want it handled instead of explained?
Everything in this article is included and looked after in every site we build. One monthly plan, no jargon, no surprises.
Start a project