If your app sends email (password resets, receipts, notifications), three DNS records decide whether it lands in the inbox: SPF, DKIM and DMARC. Since 2024, Gmail and Yahoo require them from bulk senders, and missing records are one of the most common reasons transactional email ends up in spam.
This guide explains each one in plain terms, with real record examples. You can check your own domain as you read with the free domain health checker.
The problem they solve
SMTP was designed without authentication: anyone can put From: billing@yourcompany.com on a message. SPF, DKIM and DMARC let receiving servers check whether a message claiming to be from your domain really is.
- SPF: which servers may send for your domain.
- DKIM: a cryptographic signature proving the message wasn't altered and was sent with your domain's key.
- DMARC: ties both to the visible
From:address, tells receivers what to do when checks fail, and sends you reports.
SPF: who is allowed to send
SPF is a TXT record on your root domain listing authorised senders:
yourcompany.com. TXT "v=spf1 include:_spf.google.com include:sendgrid.net ~all"
Reading it left to right: allow Google Workspace's servers, allow SendGrid's servers, and soft-fail (~all) everything else.
Things that break SPF in practice:
- Two SPF records. A domain may have only one. Two records means a permanent error, and SPF fails for everyone. Merge them.
- More than 10 DNS lookups. Every
include,a,mx,ptr,existsandredirectcosts a lookup, including nested ones inside your providers' records. Over 10, SPF fails. The SPF checker follows every include and shows the real count. +all, which authorises the entire internet to send as you.
SPF alone has a gap: it checks the hidden envelope sender (Return-Path), not the From: header people see. DMARC closes that gap.
Need a record? Use the SPF generator.
DKIM: a signature on every message
Your email provider signs each outgoing message with a private key and adds a header:
DKIM-Signature: v=1; a=rsa-sha256; d=yourcompany.com; s=s1; h=from:to:subject:date; b=...
The receiver reads d= (domain) and s= (selector), fetches the public key from DNS at s1._domainkey.yourcompany.com, and verifies the signature:
s1._domainkey.yourcompany.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOC..."
DKIM survives forwarding better than SPF and proves the content wasn't changed. Tips:
- Use 2048-bit keys; 1024-bit keys are considered weak.
- Every sending service needs its own selector and key. Adding SendGrid means adding SendGrid's DKIM record.
- To find a selector, open a message you sent, view the original, and look for
s=in theDKIM-Signatureheader. Then check it with the DKIM checker.
DMARC: the policy that ties it together
DMARC lives at _dmarc.yourcompany.com:
_dmarc.yourcompany.com. TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@yourcompany.com"
A message passes DMARC if SPF or DKIM passes and the domain it passed for aligns with the visible From: domain. That alignment requirement is what stops spoofing.
The p= tag tells receivers what to do with failures:
| Policy | Effect |
|---|---|
p=none |
Monitor only; failures are still delivered |
p=quarantine |
Failures go to spam |
p=reject |
Failures are blocked |
rua= is where daily aggregate reports go. They list every server that sent mail as your domain and whether it passed, which is how you find the forgotten CRM or invoicing tool that sends as you.
A safe rollout plan
- Publish SPF and DKIM for every service that sends as your domain.
- Add DMARC at
p=nonewith aruaaddress (DMARC generator). - Read the reports for 2 to 4 weeks. Fix each legitimate sender that fails alignment.
- Move to
p=quarantine, optionally withpct=25, then raise it to 100. - Move to
p=rejectonce reports are clean.
p=quarantine or p=reject at 100% is also the requirement for BIMI, which shows your logo next to your emails (BIMI checker).
What Gmail and Yahoo require
For senders of roughly 5,000+ messages a day to Gmail, the 2024 rules require SPF and DKIM, a DMARC record (at least p=none) with alignment, one-click unsubscribe for marketing mail, and a spam complaint rate below 0.3%. Smaller senders still need SPF or DKIM. In practice, set all three up regardless of volume.
Checking other people's domains
Authentication data is also a useful lead signal. A company with DMARC at p=reject, 2048-bit DKIM and Google Workspace or Microsoft 365 is an established business. A domain with no MX and no SPF often isn't. The MailRambo API returns this per address with ?detail=full:
"dns": { "mx": true, "spf": true, "dmarc_policy": "reject", "dkim_selectors": ["google"], "bimi": false, "ptr": true }
Summary
- SPF lists your sending servers. Keep one record and stay under 10 lookups.
- DKIM signs messages. Use 2048-bit keys and one selector per service.
- DMARC enforces alignment with the
From:domain. Start atnone, read reports, finish atreject.
Run the domain health checker to see where your domain stands now.