What Is DMARC? SPF, DKIM and DMARC Explained, With a 4-Step Setup

DMARC decides what receivers do with mail that forges your domain. How SPF, DKIM and DMARC fit together, a 4-step rollout from p=none to p=reject, the five most common mistakes, and free tools to check and generate the records.

English Implementation & Architecture SummaryBase URL: https://api.callaiapi.com/v1

DMARC decides what receivers do with mail that forges your domain. How SPF, DKIM and DMARC fit together, a 4-step rollout from p=none to p=reject, the five most common mistakes, and free tools to check and generate the records.

Auth Header: Bearer <YOUR_API_KEY>•Billing: TRON USDT from $1 · Pay-as-you-go•Compatibility: 100% OpenAI SDK Drop-in

Anyone can put your domain in an email's From line. DMARC is a DNS record that tells receivers such as Gmail and Outlook what to do with a message that claims to be from your domain but fails authentication: deliver it, send it to spam, or reject it.

When we checked the top 10,000 domains, 41.6% of those that receive mail did not enforce DMARC. For exporters, that is how buyers end up with forged "our bank details have changed" emails. For cold emailers, mail without DMARC is more likely to land in spam.

How SPF, DKIM and DMARC fit together

RecordQuestion it answersWhere it lives
SPFWhich servers may send mail for this domain?TXT on the domain itself
DKIMWas the message signed by the domain owner and left unaltered?TXT under selector._domainkey
DMARCWhat happens when neither SPF nor DKIM matches, and where do reports go?TXT under _dmarc

A message passes DMARC when SPF or DKIM passes and the passing domain matches the visible From domain ("alignment"). SPF alone is often not enough: when a third-party service sends for you, DKIM is usually what aligns.

; SPF: which servers may send for example.com
example.com.         TXT  "v=spf1 include:_spf.google.com ~all"
; DKIM: public key published by your mail provider (selector differs per provider)
google._domainkey    TXT  "v=DKIM1; k=rsa; p=MIIBIjANBg..."
; DMARC: what receivers do when SPF and DKIM do not match, and where to send reports
_dmarc               TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"

A 4-step setup

  • Step 1: list every service that sends as your domain (mailbox provider, marketing, website notifications, CRM), combine them into one SPF record with the SPF generator, and keep DNS lookups at 10 or fewer.
  • Step 2: turn on DKIM in each service and publish its public key in DNS.
  • Step 3: publish DMARC p=none with a rua report address. Delivery is unaffected; you only collect reports.
  • Step 4: after 2-4 weeks of reports showing legitimate mail passes, move to p=quarantine, then p=reject.
站内推荐实用工具

DMARC Record Generator

Pick a policy and a report address and get a _dmarc record to paste into DNS.

Generate DMARC

The five most common mistakes

  • Two SPF records: receivers treat that as an SPF error. Keep one and merge new services into it.
  • More than 10 SPF lookups: nested includes add up quickly, and past 10 SPF fails for every message.
  • Staying at p=none for good: it reports but blocks nothing. In our survey, 21.9% of mail domains sat at this step.
  • No rua address: without reports you cannot tell whether it is safe to move to quarantine.
  • Forgetting domains that send no mail: parked and spare domains can be forged too. Publish v=spf1 -all and p=reject.

Checking your setup

  • MX lookup: confirm your mail provider and inbound servers.
  • SPF checker: expand every include and confirm you are within 10 lookups.
  • DMARC checker: SPF, DKIM, DMARC and MTA-STS in one pass, with a protected / partial / spoofable verdict and fixes.
站内推荐实用工具

DMARC & SPF Checker

See whether a domain can be forged and how to fix it.

Check a domain
站内推荐实用工具

SPF Checker

Expand every include and count DNS lookups against the limit of 10.

Check SPF
站内推荐实用工具

SPF Record Generator

Tick Google Workspace, Microsoft 365, SendGrid and more to build one valid SPF record.

Generate SPF
站内推荐实用工具

MX Lookup

Find a domain's mail servers and provider.

Look up MX