Email authentication

Three DNS-backed checks, one goal: receivers can tell whether a message that claims to be from you actually is.

SPF lists sending IPs. DKIM signs content. DMARC demands that at least one of those results aligns with the From domain, then applies a policy. Skipping DMARC is how a domain with perfect SPF still gets impersonated in the visible From header.

A sane order of operations

  1. Get MX right so you still receive mail. MX guide.
  2. Inventory every sender: Workspace, Microsoft 365, billing, CRM, “that form plugin.”
  3. SPF includes for each, one record, watch the 10-lookup cap. SPF.
  4. DKIM for each sender under your domain. DKIM.
  5. DMARC p=none with reports, then quarantine, then reject. DMARC.

Mailbox providers now publish bulk-sender requirements that assume this stack. Treating DNS as optional is how newsletters start landing in spam after a quiet policy change at Gmail or Yahoo.

Run SPF & DMARC and DKIM on production, not just on the domain you remember.