SMTP Relay Webmail Hosting Web Hosting (cPanel) DDoS-Protected Hosting Reseller Hosting (WHM) WordPress Hosting Windows VPS / RDP Linux VPS (KVM) Dedicated Servers SSL Certificates Managed DNS Cloud Backup Domains Pay with Crypto Blog About Contact Client Login Get Started
Home/Blog/Deliverability
deliverability

SPF, DKIM and DMARC Explained: The Complete Guide

Email authentication in plain English. What SPF, DKIM and DMARC do, how they work together, and the exact records to publish.

2026-03-04 · 9 min read
Diagram of the email authentication flow: sender, SPF check, DKIM signature check, DMARC alignment and policy, then inbox, quarantine or reject
How a receiving mail server applies SPF, DKIM and DMARC before deciding inbox, quarantine or reject.

Three acronyms decide whether mailbox providers trust your email: SPF, DKIM and DMARC. Get them right and you clear the first hurdle to the inbox. Get them wrong and even perfectly legitimate mail gets filtered. Here is how each one works, without the jargon.

SPF — who is allowed to send

Sender Policy Framework is a DNS record that lists the servers permitted to send mail for your domain. When a receiving server gets your message, it checks whether the sending server is on that list.

v=spf1 include:_spf.mmsmtp.com include:_spf.google.com ~all

The ~all at the end means "anything not listed should be treated with suspicion." Keep your SPF record to a single line and under ten DNS lookups, or it silently breaks.

DKIM — proof the message wasn't tampered with

DomainKeys Identified Mail adds a cryptographic signature to every message. The receiving server fetches your public key from DNS and verifies the signature. If the body or key headers were changed in transit, the check fails.

selector._domainkey.yourdomain.com  TXT  "v=DKIM1; k=rsa; p=MIGfMA0GCSq..."

DMARC — tying it together

DMARC is the policy layer. It tells receivers what to do when SPF or DKIM fails, and — crucially — it sends you reports showing who is sending mail as your domain.

_dmarc.yourdomain.com  TXT  "v=DMARC1; p=quarantine; rua=mailto:[email protected]; adkim=s; aspf=s"

Start with p=none to monitor, read the reports for a couple of weeks, then move to quarantine and eventually reject once you are confident every legitimate source is aligned.

Alignment is the catch. DMARC doesn't just require SPF or DKIM to pass — it requires the domain they authenticate to match your visible From address. This is where most setups quietly fail.

The order to do this in

  1. Publish SPF listing every service that sends for you.
  2. Enable DKIM signing and publish the public key.
  3. Publish DMARC at p=none and collect reports.
  4. Fix any unaligned sources, then tighten to quarantine, then reject.

When you order an SMTP relay from us, we configure SPF, DKIM and DMARC for your sending domain as part of setup — so you clear this hurdle on day one. For a deeper look at what happens after authentication, read why emails land in spam.

keep reading

Related articles

Put this into practice

Spin up an SMTP relay or hosting in minutes and pay with crypto.