Email Security: SPF, DKIM & DMARC
Email was designed without authentication — anyone can send a message claiming to be from any address. SPF, DKIM, and DMARC are DNS-based protocols that fix this.
SPF (Sender Policy Framework)
A DNS TXT record that lists which servers are allowed to send email for your domain. When a receiving server gets an email from your domain, it checks if the sending server's IP is in your SPF record.
v=spf1 include:_spf.google.com -all — only Google's servers can send for this domain.
DKIM (DomainKeys Identified Mail)
Adds a cryptographic signature to email headers. The sending server signs each email with a private key; the receiving server verifies it using a public key published in DNS. This proves the email wasn't tampered with in transit.
DMARC (Domain-based Message Authentication, Reporting and Conformance)
Ties SPF and DKIM together with a policy. DMARC tells receiving servers what to do when authentication fails:
p=none— monitor only (collect reports, deliver anyway)p=quarantine— send failures to spamp=reject— reject failures entirely
DMARC also provides reporting: receiving servers send XML reports showing who's sending email using your domain.
How They Work Together
- Email arrives claiming to be from your domain
- Receiving server checks SPF: is this IP authorized?
- Receiving server checks DKIM: is the signature valid?
- Receiving server checks DMARC: what's the policy if SPF/DKIM fail?
Why This Matters
- Prevents email spoofing and phishing attacks
- Improves email deliverability (emails less likely to land in spam)
- Required by Google and Yahoo for bulk senders (2024+)
- You can check any domain's email setup using our DNS Lookup tool — query TXT records for SPF, and look for DKIM/DMARC entries