SPF, DKIM and DMARC are three records added to your domain’s settings. Together they prove your emails really come from you, which keeps them out of spam and stops others faking your address.
SPF: who is allowed to send
SPF lists the services allowed to send email for your domain, such as Google Workspace, Zoho or your email marketing platform. Email providers check it when your message arrives. You should have only one SPF record, with all your senders in it.
DKIM: a digital signature
DKIM adds a signature to each email that proves it was not changed on the way. Each sending service gives you a DKIM record to add, from its settings.
DMARC: what to do with failures
DMARC tells providers what to do when an email fails SPF or DKIM checks, and sends you reports:
- p=none: monitor only. Start here.
- p=quarantine: send failing emails to spam.
- p=reject: block failing emails.
How to set them up
- List every service that sends email for your domain.
- Create your SPF record. Our SPF and DMARC generator builds it.
- Add DKIM records from each service’s settings.
- Add a DMARC record starting with p=none.
- Add them in your domain’s DNS settings at your registrar or host.
- After a few weeks of clean reports, move DMARC to quarantine or reject.
Why it matters now
Major email providers expect businesses sending in bulk to authenticate their domain. Without it, more of your emails land in spam.
Read why emails go to spam.
Want the full picture? This article is part of Email marketing: the complete guide, our in-depth guide with everything in one place.


