Email Security: SPF, DKIM & DMARC

Email was designed without authentication — anyone can send a message claiming to be from any address. SPF, DKIM, and DMARC are DNS-based protocols that fix this.

SPF (Sender Policy Framework)

A DNS TXT record that lists which servers are allowed to send email for your domain. When a receiving server gets an email from your domain, it checks if the sending server's IP is in your SPF record.

v=spf1 include:_spf.google.com -all — only Google's servers can send for this domain.

DKIM (DomainKeys Identified Mail)

Adds a cryptographic signature to email headers. The sending server signs each email with a private key; the receiving server verifies it using a public key published in DNS. This proves the email wasn't tampered with in transit.

DMARC (Domain-based Message Authentication, Reporting and Conformance)

Ties SPF and DKIM together with a policy. DMARC tells receiving servers what to do when authentication fails:

DMARC also provides reporting: receiving servers send XML reports showing who's sending email using your domain.

How They Work Together

  1. Email arrives claiming to be from your domain
  2. Receiving server checks SPF: is this IP authorized?
  3. Receiving server checks DKIM: is the signature valid?
  4. Receiving server checks DMARC: what's the policy if SPF/DKIM fail?

Why This Matters