New: The free 7-Day Email Profit BootcampStart free →
Skip to content
Deliverability Intermediate

Deliverability Decoded: SPF, DKIM and DMARC in Plain English

Three DNS records decide whether your emails reach the inbox. Here's what SPF, DKIM and DMARC do, in plain English.

admin August 28, 2026 7 min read
Deliverability Decoded: SPF, DKIM and DMARC in Plain English

You wrote a great email. You hit send. And it landed… in spam. Or worse, nowhere at all.

Very often the culprit isn’t your copy. It’s three little DNS records with intimidating names: SPF, DKIM and DMARC. They’re how mailbox providers like Gmail, Yahoo and Outlook decide whether an email claiming to be from you really is from you.

Good news: you don’t need to be an engineer to understand them. Let’s decode all three in plain English, with example records you can adapt.

The big idea: proving you are you

Email was designed decades ago with almost no identity checks. Anyone can put any address in the “From” line. Scammers exploit this constantly. Authentication is the fix, and it works like this:

  • SPF is the guest list: which servers are allowed to send mail for your domain.
  • DKIM is the wax seal: a cryptographic signature proving the message wasn’t tampered with and was authorized by a domain.
  • DMARC is the bouncer’s instructions: what to do when a message fails the checks, and where to send reports about it.

All three live in your domain’s DNS as TXT records. You add them wherever you manage your domain (your registrar or DNS host).

SPF: the guest list

SPF (Sender Policy Framework) lists the services allowed to send email using your domain. A typical record looks like this:

Host/Name:  @   (your root domain)
Type:       TXT
Value:      v=spf1 include:_spf.google.com include:servers.youresp.example ~all

Reading it left to right:

  • v=spf1 says “this is an SPF record.”
  • include:... authorizes a service’s sending servers. You add one for each service that sends as you: your inbox provider, your email marketing platform, your help desk, and so on. Your provider will tell you exactly what to include.
  • ~all is “softfail”: anything not on the list is suspicious. -all is “hardfail”: anything not on the list should be rejected. Many senders start with ~all and rely on DMARC for enforcement.

Watch out: You can only have one SPF record per domain. If you add a second one for a new tool, both can break. Merge them into a single record with multiple include: entries. Also, SPF has a limit of 10 DNS lookups, so a record stuffed with too many includes can fail. Remove services you no longer use.

SPF’s weak spot

SPF checks the hidden “envelope” sender (the Return-Path, where bounces go), not the visible From address your readers see. And it often breaks when email is forwarded. That’s why it isn’t enough on its own.

DKIM: the wax seal

DKIM (DomainKeys Identified Mail) adds a digital signature to each email. Your sending service signs the message with a private key; the matching public key sits in your DNS. The receiving server checks the signature with the public key. If it matches, the message is authentic and unaltered.

Your email platform generates the record for you. It usually looks something like this:

Host/Name:  selector1._domainkey
Type:       TXT (or CNAME pointing to your provider)
Value:      v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...
  • Selector (selector1 here) is just a label, so one domain can have several DKIM keys, one per service.
  • p= is the public key. You copy and paste it exactly as your provider gives it.

The key thing: make sure your email platform signs with your domain, not just its own. Most platforms call this “domain authentication” or “custom domain setup.” Do it.

DMARC: the bouncer’s instructions

DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM to the From address people actually see, tells receivers what to do with failures, and sends you reports.

A starter DMARC record:

Host/Name:  _dmarc
Type:       TXT
Value:      v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
  • v=DMARC1 identifies the record.
  • p= is your policy: none (monitor only), quarantine (treat failures as suspicious, usually spam folder), or reject (block failures outright).
  • rua= is where daily aggregate reports get sent. These show every source sending mail as your domain, legitimate or not.

Optional tags you’ll see: pct= (apply the policy to a percentage of failing mail), sp= (policy for subdomains), and adkim=/aspf= (strict or relaxed alignment).

Pro tip: Raw DMARC reports are XML files that are painful to read. Point your rua address at a DMARC reporting service, or a dedicated mailbox you process with a report tool, so you get readable summaries instead of a pile of attachments.

Alignment: the part everyone skips

Here’s the concept that trips most people up. For DMARC to pass, it’s not enough for SPF or DKIM to pass. At least one of them has to pass and align with the domain in your visible From address.

  • SPF alignment: the Return-Path domain matches your From domain.
  • DKIM alignment: the signing domain (the d= value in the DKIM signature) matches your From domain.

“Relaxed” alignment (the default) lets subdomains count, so mail.yourdomain.com aligns with yourdomain.com. “Strict” requires an exact match.

Example: You send from hello@yourdomain.com through a marketing platform that hasn’t been set up with your domain. SPF passes for the platform’s own domain, and DKIM is signed by the platform’s domain. Both “pass,” but neither aligns with yourdomain.com. Result: DMARC fails. Setting up custom domain authentication in your platform fixes this, because DKIM then signs with d=yourdomain.com.

The safe rollout: none → quarantine → reject

Never jump straight to p=reject. If you’ve forgotten a legitimate sender (your invoicing app, your help desk), you’ll block your own mail. Roll out in stages:

  1. Stage 1, monitor (p=none): Publish the record and read your reports for a few weeks. Find every service sending as you. Fix SPF and DKIM for each legitimate one.
  2. Stage 2, quarantine (p=quarantine): Once legitimate mail consistently passes, move to quarantine. You can ease in with pct= on a portion of failing mail first. Keep watching reports.
  3. Stage 3, reject (p=reject): When you’re confident, reject failures. Now spoofers can’t easily impersonate your domain, which protects your reputation and your readers.
Stage 1: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
Stage 2: v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@yourdomain.com
Stage 3: v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com

Want the records generated for you? Use our DMARC & SPF Builder.

The Gmail and Yahoo bulk sender rules

In 2024, Gmail and Yahoo introduced stricter requirements for bulk senders (Google defines this as sending roughly 5,000 or more messages a day to Gmail addresses). If you run a newsletter, treat these as the baseline even if you’re smaller:

  • Authenticate with both SPF and DKIM
  • Publish a DMARC record (a p=none policy satisfies the minimum)
  • Your From domain aligns with SPF or DKIM
  • Marketing emails support one-click unsubscribe (the List-Unsubscribe and List-Unsubscribe-Post headers), and unsubscribes are honored promptly, within two days
  • Keep your spam complaint rate under 0.3%, and ideally under 0.1%
  • Don’t send from a free webmail address like a gmail.com From address through a bulk tool

Most reputable email platforms handle the unsubscribe headers for you. Your job is the DNS setup, sending to people who actually want your mail, and keeping complaints low.

Profit move: Deliverability is revenue. If a chunk of your list never sees your emails, every campaign earns less than it should. Authenticating properly and cleaning out inactive subscribers is often the highest-ROI hour you’ll spend all quarter.

Quick troubleshooting

Symptom Likely cause Fix
SPF “permerror” Two SPF records, or more than 10 lookups Merge into one record; remove unused includes
DKIM passes, DMARC fails DKIM signed by the platform’s domain, not yours Complete custom domain authentication in your platform
Unknown senders in reports A forgotten tool or someone spoofing you Authorize the legit tool; ignore or block the spoofer via policy
Mail to spam despite passing Reputation or engagement issues Send to engaged subscribers, reduce complaints, improve content

Authentication gets you through the door. Reputation keeps you in the room. Run important campaigns through the Spam Word Checker too.

This article is general information, not legal or professional IT advice. Always follow your email provider’s specific setup instructions.

Key takeaways

  • SPF lists who may send for you, DKIM signs your mail, DMARC sets the policy and sends reports.
  • Only one SPF record per domain, and watch the 10-lookup limit.
  • DMARC needs SPF or DKIM to pass and align with your visible From domain.
  • Roll out DMARC gradually: none, then quarantine, then reject.
  • Gmail and Yahoo expect authentication, one-click unsubscribe, and complaints under 0.3% (aim for under 0.1%).

Generate your records in minutes with the DMARC & SPF Builder, then go deeper on inbox placement in the free 7-Day Email Profit Bootcamp.

Join the Profit Inbox Insiders

Weekly email marketing plays, free tools and templates. Plus the free 7-Day Email Profit Bootcamp.

Join the conversation

Your email address will not be published. Required fields are marked *

Free every week

One email a week. More money from every email you send.

Join the Profit Inbox Insiders and get the free Starter Kit: 50 subject line formulas, a deliverability checklist and 30 email secrets.