You wrote a great email. You hit send. And it landed… in spam. Or worse, nowhere at all.
Very often the culprit isn’t your copy. It’s three little DNS records with intimidating names: SPF, DKIM and DMARC. They’re how mailbox providers like Gmail, Yahoo and Outlook decide whether an email claiming to be from you really is from you.
Good news: you don’t need to be an engineer to understand them. Let’s decode all three in plain English, with example records you can adapt.
The big idea: proving you are you
Email was designed decades ago with almost no identity checks. Anyone can put any address in the “From” line. Scammers exploit this constantly. Authentication is the fix, and it works like this:
- SPF is the guest list: which servers are allowed to send mail for your domain.
- DKIM is the wax seal: a cryptographic signature proving the message wasn’t tampered with and was authorized by a domain.
- DMARC is the bouncer’s instructions: what to do when a message fails the checks, and where to send reports about it.
All three live in your domain’s DNS as TXT records. You add them wherever you manage your domain (your registrar or DNS host).
SPF: the guest list
SPF (Sender Policy Framework) lists the services allowed to send email using your domain. A typical record looks like this:
Host/Name: @ (your root domain) Type: TXT Value: v=spf1 include:_spf.google.com include:servers.youresp.example ~all
Reading it left to right:
v=spf1says “this is an SPF record.”include:...authorizes a service’s sending servers. You add one for each service that sends as you: your inbox provider, your email marketing platform, your help desk, and so on. Your provider will tell you exactly what to include.~allis “softfail”: anything not on the list is suspicious.-allis “hardfail”: anything not on the list should be rejected. Many senders start with~alland rely on DMARC for enforcement.
Watch out: You can only have one SPF record per domain. If you add a second one for a new tool, both can break. Merge them into a single record with multiple include: entries. Also, SPF has a limit of 10 DNS lookups, so a record stuffed with too many includes can fail. Remove services you no longer use.
SPF’s weak spot
SPF checks the hidden “envelope” sender (the Return-Path, where bounces go), not the visible From address your readers see. And it often breaks when email is forwarded. That’s why it isn’t enough on its own.
DKIM: the wax seal
DKIM (DomainKeys Identified Mail) adds a digital signature to each email. Your sending service signs the message with a private key; the matching public key sits in your DNS. The receiving server checks the signature with the public key. If it matches, the message is authentic and unaltered.
Your email platform generates the record for you. It usually looks something like this:
Host/Name: selector1._domainkey Type: TXT (or CNAME pointing to your provider) Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...
- Selector (
selector1here) is just a label, so one domain can have several DKIM keys, one per service. p=is the public key. You copy and paste it exactly as your provider gives it.
The key thing: make sure your email platform signs with your domain, not just its own. Most platforms call this “domain authentication” or “custom domain setup.” Do it.
DMARC: the bouncer’s instructions
DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM to the From address people actually see, tells receivers what to do with failures, and sends you reports.
A starter DMARC record:
Host/Name: _dmarc Type: TXT Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
v=DMARC1identifies the record.p=is your policy:none(monitor only),quarantine(treat failures as suspicious, usually spam folder), orreject(block failures outright).rua=is where daily aggregate reports get sent. These show every source sending mail as your domain, legitimate or not.
Optional tags you’ll see: pct= (apply the policy to a percentage of failing mail), sp= (policy for subdomains), and adkim=/aspf= (strict or relaxed alignment).
Pro tip: Raw DMARC reports are XML files that are painful to read. Point your rua address at a DMARC reporting service, or a dedicated mailbox you process with a report tool, so you get readable summaries instead of a pile of attachments.
Alignment: the part everyone skips
Here’s the concept that trips most people up. For DMARC to pass, it’s not enough for SPF or DKIM to pass. At least one of them has to pass and align with the domain in your visible From address.
- SPF alignment: the Return-Path domain matches your From domain.
- DKIM alignment: the signing domain (the
d=value in the DKIM signature) matches your From domain.
“Relaxed” alignment (the default) lets subdomains count, so mail.yourdomain.com aligns with yourdomain.com. “Strict” requires an exact match.
Example: You send from hello@yourdomain.com through a marketing platform that hasn’t been set up with your domain. SPF passes for the platform’s own domain, and DKIM is signed by the platform’s domain. Both “pass,” but neither aligns with yourdomain.com. Result: DMARC fails. Setting up custom domain authentication in your platform fixes this, because DKIM then signs with d=yourdomain.com.
The safe rollout: none → quarantine → reject
Never jump straight to p=reject. If you’ve forgotten a legitimate sender (your invoicing app, your help desk), you’ll block your own mail. Roll out in stages:
- Stage 1, monitor (
p=none): Publish the record and read your reports for a few weeks. Find every service sending as you. Fix SPF and DKIM for each legitimate one. - Stage 2, quarantine (
p=quarantine): Once legitimate mail consistently passes, move to quarantine. You can ease in withpct=on a portion of failing mail first. Keep watching reports. - Stage 3, reject (
p=reject): When you’re confident, reject failures. Now spoofers can’t easily impersonate your domain, which protects your reputation and your readers.
Stage 1: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com Stage 2: v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@yourdomain.com Stage 3: v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com
Want the records generated for you? Use our DMARC & SPF Builder.
The Gmail and Yahoo bulk sender rules
In 2024, Gmail and Yahoo introduced stricter requirements for bulk senders (Google defines this as sending roughly 5,000 or more messages a day to Gmail addresses). If you run a newsletter, treat these as the baseline even if you’re smaller:
- Authenticate with both SPF and DKIM
- Publish a DMARC record (a
p=nonepolicy satisfies the minimum) - Your From domain aligns with SPF or DKIM
- Marketing emails support one-click unsubscribe (the List-Unsubscribe and List-Unsubscribe-Post headers), and unsubscribes are honored promptly, within two days
- Keep your spam complaint rate under 0.3%, and ideally under 0.1%
- Don’t send from a free webmail address like a gmail.com From address through a bulk tool
Most reputable email platforms handle the unsubscribe headers for you. Your job is the DNS setup, sending to people who actually want your mail, and keeping complaints low.
Profit move: Deliverability is revenue. If a chunk of your list never sees your emails, every campaign earns less than it should. Authenticating properly and cleaning out inactive subscribers is often the highest-ROI hour you’ll spend all quarter.
Quick troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| SPF “permerror” | Two SPF records, or more than 10 lookups | Merge into one record; remove unused includes |
| DKIM passes, DMARC fails | DKIM signed by the platform’s domain, not yours | Complete custom domain authentication in your platform |
| Unknown senders in reports | A forgotten tool or someone spoofing you | Authorize the legit tool; ignore or block the spoofer via policy |
| Mail to spam despite passing | Reputation or engagement issues | Send to engaged subscribers, reduce complaints, improve content |
Authentication gets you through the door. Reputation keeps you in the room. Run important campaigns through the Spam Word Checker too.
This article is general information, not legal or professional IT advice. Always follow your email provider’s specific setup instructions.
Key takeaways
- SPF lists who may send for you, DKIM signs your mail, DMARC sets the policy and sends reports.
- Only one SPF record per domain, and watch the 10-lookup limit.
- DMARC needs SPF or DKIM to pass and align with your visible From domain.
- Roll out DMARC gradually: none, then quarantine, then reject.
- Gmail and Yahoo expect authentication, one-click unsubscribe, and complaints under 0.3% (aim for under 0.1%).
Generate your records in minutes with the DMARC & SPF Builder, then go deeper on inbox placement in the free 7-Day Email Profit Bootcamp.
Join the Profit Inbox Insiders
Weekly email marketing plays, free tools and templates. Plus the free 7-Day Email Profit Bootcamp.
