Email · Email & certs
Email deliverability: SPF, DKIM, and DMARC in plain English
If you send email from your own domain (not Gmail or Outlook), three DNS records control whether your messages reach the inbox: an SPF records that authorizes senders, a DKIM record that cryptographically signs them, and a CNAME that publishers expect. A missing or misconfigured record sends your email to spam.
TL;DR
Three DNS records decide whether your email lands in the inbox or the spam folder. SPF says who can send. DKIM signs the message. DMARC says what to do if it fails. Here is how to set them up.
SPF: who can send mail for your domain
An SPF record is a TXT record starting with "v=spf1" that lists the IPs and hostnames authorized to send mail for your domain. Example: "v=spf1 include:_spf.google.com ~all" authorizes Google's mail servers. "~all" is a softfail (mark as spam but accept), "-all" is a hardfail (reject). Anything not in the list gets failed. SPF checks the envelope sender, not the From: header.
DKIM: cryptographically sign each message
DKIM signs each outgoing message with a private key. The receiving server fetches the public key from a DNS TXT record at selector._domainkey.example.com and verifies the signature. If it matches, the message is authentic. DKIM catches spoofed messages and forwarded-forgeries that SPF misses.
DMARC: what to do with failures
A DMARC record tells receiving servers what to do when a message fails both SPF and DKIM alignment. "v=DMARC1; p=none" means monitor only. "p=quarantine" means send to spam. "p=reject" means reject. You should start with p=none, monitor for a month, then move to quarantine, then reject. DMARC also sends reports to an email address you specify, so you can see who is sending mail using your domain.
Why all three are needed
SPF alone fails when email is forwarded (the forwarder is not in your SPF list). DKIM alone fails when the message is modified in transit (a signature mismatch). DMARC ties them together by requiring either SPF or DKIM to pass alignment. Without all three, you have partial protection. With all three, you have a high-confidence signal that the message is really from you.
Try it →
Run the Email deliverability tool on sitetrace.it.com — paste a value and get an instant answer.
Open Email deliverability