What Is DMARC? SPF, DKIM and DMARC Explained, With a 4-Step Setup
DMARC decides what receivers do with mail that forges your domain. How SPF, DKIM and DMARC fit together, a 4-step rollout from p=none to p=reject, the five most common mistakes, and free tools to check and generate the records.
DMARC decides what receivers do with mail that forges your domain. How SPF, DKIM and DMARC fit together, a 4-step rollout from p=none to p=reject, the five most common mistakes, and free tools to check and generate the records.
Anyone can put your domain in an email's From line. DMARC is a DNS record that tells receivers such as Gmail and Outlook what to do with a message that claims to be from your domain but fails authentication: deliver it, send it to spam, or reject it.
When we checked the top 10,000 domains, 41.6% of those that receive mail did not enforce DMARC. For exporters, that is how buyers end up with forged "our bank details have changed" emails. For cold emailers, mail without DMARC is more likely to land in spam.
How SPF, DKIM and DMARC fit together
| Record | Question it answers | Where it lives |
|---|---|---|
| SPF | Which servers may send mail for this domain? | TXT on the domain itself |
| DKIM | Was the message signed by the domain owner and left unaltered? | TXT under selector._domainkey |
| DMARC | What happens when neither SPF nor DKIM matches, and where do reports go? | TXT under _dmarc |
A message passes DMARC when SPF or DKIM passes and the passing domain matches the visible From domain ("alignment"). SPF alone is often not enough: when a third-party service sends for you, DKIM is usually what aligns.
; SPF: which servers may send for example.com
example.com. TXT "v=spf1 include:_spf.google.com ~all"
; DKIM: public key published by your mail provider (selector differs per provider)
google._domainkey TXT "v=DKIM1; k=rsa; p=MIIBIjANBg..."
; DMARC: what receivers do when SPF and DKIM do not match, and where to send reports
_dmarc TXT "v=DMARC1; p=none; rua=mailto:[email protected]"
A 4-step setup
- Step 1: list every service that sends as your domain (mailbox provider, marketing, website notifications, CRM), combine them into one SPF record with the SPF generator, and keep DNS lookups at 10 or fewer.
- Step 2: turn on DKIM in each service and publish its public key in DNS.
- Step 3: publish DMARC p=none with a rua report address. Delivery is unaffected; you only collect reports.
- Step 4: after 2-4 weeks of reports showing legitimate mail passes, move to p=quarantine, then p=reject.
DMARC Record Generator
Pick a policy and a report address and get a _dmarc record to paste into DNS.
The five most common mistakes
- Two SPF records: receivers treat that as an SPF error. Keep one and merge new services into it.
- More than 10 SPF lookups: nested includes add up quickly, and past 10 SPF fails for every message.
- Staying at p=none for good: it reports but blocks nothing. In our survey, 21.9% of mail domains sat at this step.
- No rua address: without reports you cannot tell whether it is safe to move to quarantine.
- Forgetting domains that send no mail: parked and spare domains can be forged too. Publish v=spf1 -all and p=reject.
Checking your setup
- MX lookup: confirm your mail provider and inbound servers.
- SPF checker: expand every include and confirm you are within 10 lookups.
- DMARC checker: SPF, DKIM, DMARC and MTA-STS in one pass, with a protected / partial / spoofable verdict and fixes.
DMARC & SPF Checker
See whether a domain can be forged and how to fix it.
SPF Checker
Expand every include and count DNS lookups against the limit of 10.
SPF Record Generator
Tick Google Workspace, Microsoft 365, SendGrid and more to build one valid SPF record.
MX Lookup
Find a domain's mail servers and provider.